Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

concretecms

HackerOneView on HackerOne
RawAI Enhanced
1
In Scope
3
Out of Scope
In-Scope Assets (1)
AssetCategoryBountyQuick Links
https://github.com/concrete5/concrete5CODENo-
Out-of-Scope Assets (3)
AssetCategoryBounty
*.concrete5.orgWILDCARDNo
*.concretecms.comWILDCARDNo
*.concretecms.orgWILDCARDNo
Scope Changes (21)
Mar 27, 2026
ChangeAssetCategoryScopeTime
Added*.concretecms.comWILDCARDOut of Scope09:21
Addedhttps://github.com/concrete5/concrete5CODEIn Scope09:21
Added*.concrete5.orgWILDCARDOut of Scope09:21
Added*.concretecms.orgWILDCARDOut of Scope09:21
Added*.concretecms.comWILDCARDOut of Scope09:21
Addedhttps://github.com/concrete5/concrete5CODEIn Scope09:21
Added*.concrete5.orgWILDCARDOut of Scope09:21
Added*.concretecms.orgWILDCARDOut of Scope09:21
Mar 25, 2026
ChangeAssetCategoryScopeTime
Program Removed15:40
Feb 25, 2026
ChangeAssetCategoryScopeTime
Added*.concrete5.orgWILDCARDOut of Scope19:08
Added*.concretecms.orgWILDCARDOut of Scope19:08
Added*.concretecms.comWILDCARDOut of Scope19:08
Addedhttps://github.com/concrete5/concrete5CODEIn Scope19:08
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedhttps://github.com/concrete5/concrete5CODEIn Scope00:40
Added*.concrete5.orgWILDCARDOut of Scope00:40
Added*.concretecms.orgWILDCARDOut of Scope00:40
Added*.concretecms.comWILDCARDOut of Scope00:40
Feb 21, 2026
ChangeAssetCategoryScopeTime
Addedhttps://github.com/concrete5/concrete5CODEIn Scope19:11
Added*.concrete5.orgWILDCARDOut of Scope19:11
Added*.concretecms.orgWILDCARDOut of Scope19:11
Added*.concretecms.comWILDCARDOut of Scope19:11