Vulnerability Disclosure Program (VDP)
VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.
ynab
3
In Scope
5
Out of Scope
In-Scope Assets (3)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| http://staging-api.ynab.com | URL | No | ||
| staging-app.bany.dev | URL | No | ||
| www.ynab.com | OTHER | No | - |
Out-of-Scope Assets (5)
| Asset | Category | Bounty | |
|---|---|---|---|
| Any previous version of the desktop apps: YNAB 4, YNAB 3, YNAB Pro, YNAB Basic (Spreadsheet) | OTHER | No | |
| https://app.ynab.com/ | URL | No | |
| https://develop-app.ynab.com | URL | No | |
| https://learn.ynab.com/ | URL | No | |
| https://support.ynab.com | URL | No |