Vulnerability Disclosure Program (VDP)
VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.
/engagements/xero-vdp-pro
13
In Scope
0
Out of Scope
In-Scope Assets (13)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| *.api.xero.com | URL | No | ||
| https://apps.xero.com | URL | No | ||
| https://bankaccounts.xero.com | URL | No | ||
| https://central.xero.com | URL | No | ||
| https://fixedassets.xero.com | URL | No | ||
| https://go.xero.com | URL | No | ||
| https://identity.xero.com | URL | No | ||
| https://login.xero.com | URL | No | ||
| https://my.xero.com | URL | No | ||
| https://payroll.xero.com | URL | No | ||
| https://reporting.xero.com | URL | No | ||
| https://www.xero.com/{region}/advisors | URL | No | ||
| https://xero.com | URL | No |