Vulnerability Disclosure Program (VDP)
VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.
/engagements/plusgrade-vdp-pro
5
In Scope
2
Out of Scope
In-Scope Assets (5)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| *.points.com | URL | No | ||
| *.upgrd.co | URL | No | ||
| Additional scope included under resources tab | URL | No | - | |
| https://www.plusgrade.com/ | URL | No | ||
| https://www.upstay.tech | URL | No |
Out-of-Scope Assets (2)
| Asset | Category | Bounty | |
|---|---|---|---|
| Anything not explicitly listed as in-scope | URL | No | |
| Partner Website & Applications | URL | No |