Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

openmage

HackerOneView on HackerOne
RawAI Enhanced
3
In Scope
1
Out of Scope
In-Scope Assets (3)
Out-of-Scope Assets (1)
AssetCategoryBounty
www.openmage.orgURLNo
Scope Changes (12)
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedhttps://github.com/OpenMage/magento-ltsCODEIn Scope19:12
Addeddemo.openmage.orgURLIn Scope19:12
Addeddemo-admin.openmage.comURLIn Scope19:12
Addedwww.openmage.orgURLOut of Scope19:12
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedhttps://github.com/OpenMage/magento-ltsCODEIn Scope00:42
Addeddemo.openmage.orgURLIn Scope00:42
Addeddemo-admin.openmage.comURLIn Scope00:42
Addedwww.openmage.orgURLOut of Scope00:42
Feb 21, 2026
ChangeAssetCategoryScopeTime
Addedhttps://github.com/OpenMage/magento-ltsCODEIn Scope19:12
Addeddemo.openmage.orgURLIn Scope19:12
Addeddemo-admin.openmage.comURLIn Scope19:12
Addedwww.openmage.orgURLOut of Scope19:12