Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

moovit-mbb-og

BugcrowdView on Bugcrowd
RawAI Enhanced
4
In Scope
3
Out of Scope

In-Scope Assets (4)

AssetCategoryBountyQuick Links
All In Scope TargetsOTHERNo-
https://apps.apple.com/us/app/moovit-all-transit-options/id498477945IOSNo-
https://play.google.com/store/apps/details?id=com.tranzmate&hl=en_USANDROIDNo
https://support.moovitapp.com/hc/en-us/articles/11389054527122-WayFinder-Augmented-Reality-helper-to-find-your-stop-iPhone-onlyIOSNo-
Out-of-Scope Assets (3)
AssetCategoryBounty
Any WebView sources or web application rendered within the mobile applicationsOTHERNo
Every Web App is Out Of Scope.URLNo
Every app not related to the Moovit mobile application.OTHERNo