Vulnerability Disclosure Program (VDP)
VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.
upwork
12
In Scope
14
Out of Scope
In-Scope Assets (12)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| Direct Contracts | URL | No | - | |
| Upwork - Android Application | ANDROID | No | - | |
| Upwork - Marketplace Portal | URL | No | - | |
| Upwork - Messages | URL | No | - | |
| Upwork - Mobile Application Android | ANDROID | No | - | |
| Upwork - Mobile Application IOS | IOS | No | - | |
| Upwork - api.upwork.com/graphql | URL | No | - | |
| Upwork - iOS Application | IOS | No | - | |
| Upwork Dash Messenger Desktop Version (www.upwork.com/downloads) | HARDWARE | No | - | |
| api.upwork.com/graphql | URL | No | ||
| https://www.upwork.com | URL | No | ||
| www.upwork.com/api | URL | No |
Out-of-Scope Assets (14)
| Asset | Category | Bounty | |
|---|---|---|---|
| Any Third-party Services | OTHER | No | |
| Any subdomain/domain/property not listed in the 'in scope' section, is out of scope. | OTHER | No | |
| Social media hijacking | OTHER | No | |
| careers.upwork.com | OTHER | No | |
| community.stage.upwork.com | OTHER | No | |
| community.upwork.com | OTHER | No | |
| e.upwork.com | OTHER | No | |
| pardot.upwork.com | OTHER | No | |
| signature.upwork.com | OTHER | No | |
| stage.upwork.com | OTHER | No | |
| status.upwork.com | OTHER | No | |
| support.upwork.com | OTHER | No | |
| tip.upwork.com | URL | No | |
| tip.upwork.com | OTHER | No |