Vulnerability Disclosure Program (VDP)
VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.
canva
18
In Scope
0
Out of Scope
In-Scope Assets (18)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| *.canva-apps.cn | URL | No | ||
| *.canva-apps.com | URL | No | ||
| *.canva.cn | URL | No | ||
| *.canva.com | URL | No | ||
| 3rd-Party Provider Vulnerability | OTHER | No | - | |
| Apps SDK Sandboxing | OTHER | No | - | |
| Canva (Android) | ANDROID | No | - | |
| Canva (Chrome Extension) | OTHER | No | - | |
| Canva (iOS) | IOS | No | - | |
| Canva Desktop (macOS / Windows) | OTHER | No | - | |
| Leaked Credentials and Secrets (Canva Employee/Contractor) | OTHER | No | - | |
| Leaked Credentials and Secrets (Canva User) | OTHER | No | - | |
| https://*.canva.tech | URL | No | ||
| https://api.canva.com | URL | No | ||
| https://www.canva.com | URL | No | ||
| https://www.canva.com/developers/ | URL | No | ||
| https://www.canva.com/en_au/help/chatgpt-templates/ | URL | No | ||
| https://www.canva.com/integrations/slack/ | URL | No |