Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

owaspjavasanitizer

BugcrowdView on Bugcrowd
RawAI Enhanced
1
In Scope
0
Out of Scope
In-Scope Assets (1)
AssetCategoryBountyQuick Links
https://github.com/OWASP/OWASPBugBounty/tree/master/JavaHTMLSanitizer/war-filesOTHERNo-
Scope Changes (5)
Mar 5, 2026
ChangeAssetCategoryScopeTime
Addedhttps://github.com/OWASP/OWASPBugBounty/tree/master/JavaHTMLSanitizer/war-filesOTHERIn Scope22:37
Addedhttps://github.com/OWASP/OWASPBugBounty/tree/master/JavaHTMLSanitizer/war-filesOTHERIn Scope22:37
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedhttps://github.com/OWASP/OWASPBugBounty/tree/master/JavaHTMLSanitizer/war-filesURLIn Scope19:20
Addedhttps://github.com/OWASP/OWASPBugBounty/tree/master/JavaHTMLSanitizer/war-filesOTHERIn Scope17:19
Addedhttps://github.com/OWASP/OWASPBugBounty/tree/master/JavaHTMLSanitizer/war-filesOTHERIn Scope17:19