Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

tesco

HackerOneView on HackerOne
RawAI Enhanced
24
In Scope
3
Out of Scope
In-Scope Assets (24)
AssetCategoryBountyQuick Links
*.itesco.cz/*WILDCARDNo
*.itesco.sk/*WILDCARDNo
*.ourtesco.com/*WILDCARDNo
*.tesco-europe.com/*WILDCARDNo
*.tesco.com/*WILDCARDNo
*.tesco.hu/*WILDCARDNo
*.tesco.ie/*WILDCARDNo
*.tesco.org/*WILDCARDNo
*.tesco.sk/*WILDCARDNo
*.tescocloud.com/*WILDCARDNo
*.tescoplc.com/*WILDCARDNo
389581236IOSNo-
857834425IOSNo-
API AssetsOTHERNo-
Cloud AssetsOTHERNo-
Domain, Subdomain & Zone TakeoversOTHERNo-
Exposed Sensitive DocumentsOTHERNo-
Leaked & Default CredentialsOTHERNo-
Medium, High and Critical Severity Issue on Out-Of-Scope AssetsOTHERNo-
Third-Party Managed AssetsOTHERNo-
com.tesco.grocery.viewANDROIDNo
https://www.booker.co.uk/*WILDCARDNo
https://www.onestop.co.uk/*WILDCARDNo
https://www.tescomobile.com/*WILDCARDNo
Out-of-Scope Assets (3)
AssetCategoryBounty
Dunnhumby (Non-Critical)OTHERNo
Tesco BankOTHERNo
com.tescobank.mobileANDROIDNo
Scope Changes (81)
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedmedium, high and critical severity issue on out-of-scope assetsOTHEROut of Scope19:14
Addedcloud assetsOTHERIn Scope19:14
Addedapi assetsOTHERIn Scope19:14
Addeddunnhumby (non-critical)OTHEROut of Scope19:14
Added*.tescocloud.com/*WILDCARDIn Scope19:14
Added*.ourtesco.com/*WILDCARDIn Scope19:14
Added*.itesco.cz/*WILDCARDIn Scope19:14
Addedleaked & default credentialsOTHERIn Scope19:14
Addedhttps://www.tescomobile.com/*WILDCARDIn Scope19:14
Addedcom.tesco.grocery.viewANDROIDIn Scope19:14
Addedhttps://www.booker.co.uk/*WILDCARDIn Scope19:14
Addedexposed sensitive documentsOTHERIn Scope19:14
Added857834425IOSIn Scope19:14
Added389581236IOSIn Scope19:14
Added*.tesco.sk/*WILDCARDIn Scope19:14
Addedcom.tescobank.mobileANDROIDOut of Scope19:14
Added*.tesco.hu/*WILDCARDIn Scope19:14
Added*.tesco.com/*WILDCARDIn Scope19:14
Added*.tesco-europe.com/*WILDCARDIn Scope19:14
Addedhttps://www.onestop.co.uk/*WILDCARDIn Scope19:14
Added*.itesco.sk/*WILDCARDIn Scope19:14
Addedthird-party managed assetsOTHERIn Scope19:14
Addeddomain, subdomain & zone takeoversOTHERIn Scope19:14
Added*.tesco.ie/*WILDCARDIn Scope19:14
Addedtesco bankOTHEROut of Scope19:14
Added*.tescoplc.com/*WILDCARDIn Scope19:14
Added*.tesco.org/*WILDCARDIn Scope19:14
Feb 22, 2026
ChangeAssetCategoryScopeTime
Added857834425IOSIn Scope00:44
Addedcom.tesco.grocery.viewANDROIDIn Scope00:44
Added*.itesco.cz/*WILDCARDIn Scope00:44
Addedapi assetsOTHERIn Scope00:44
Addedmedium, high and critical severity issue on out-of-scope assetsOTHEROut of Scope00:44
Addedhttps://www.onestop.co.uk/*WILDCARDIn Scope00:44
Added*.ourtesco.com/*WILDCARDIn Scope00:44
Added*.tesco-europe.com/*WILDCARDIn Scope00:44
Added*.tesco.com/*WILDCARDIn Scope00:44
Addedleaked & default credentialsOTHERIn Scope00:44
Addedthird-party managed assetsOTHERIn Scope00:44
Added*.itesco.sk/*WILDCARDIn Scope00:44
Added*.tesco.hu/*WILDCARDIn Scope00:44
Added*.tesco.ie/*WILDCARDIn Scope00:44
Addedhttps://www.tescomobile.com/*WILDCARDIn Scope00:44
Addedtesco bankOTHEROut of Scope00:44
Addedcom.tescobank.mobileANDROIDOut of Scope00:44
Added*.tesco.sk/*WILDCARDIn Scope00:44
Added389581236IOSIn Scope00:44
Addedcloud assetsOTHERIn Scope00:44
Addeddomain, subdomain & zone takeoversOTHERIn Scope00:44
Addedexposed sensitive documentsOTHERIn Scope00:44
Addedhttps://www.booker.co.uk/*WILDCARDIn Scope00:44
Added*.tescocloud.com/*WILDCARDIn Scope00:44
Added*.tesco.org/*WILDCARDIn Scope00:44
Added*.tescoplc.com/*WILDCARDIn Scope00:44
Addeddunnhumby (non-critical)OTHEROut of Scope00:44
Feb 21, 2026
ChangeAssetCategoryScopeTime
Added*.tesco.sk/*WILDCARDIn Scope19:12
Addedcom.tescobank.mobileANDROIDOut of Scope19:12
Addedtesco bankOTHEROut of Scope19:12
Addeddunnhumby (non-critical)OTHEROut of Scope19:12
Added*.tescoplc.com/*WILDCARDIn Scope19:12
Addedhttps://www.tescomobile.com/*WILDCARDIn Scope19:12
Added*.tescocloud.com/*WILDCARDIn Scope19:12
Added*.tesco.org/*WILDCARDIn Scope19:12
Added*.tesco.ie/*WILDCARDIn Scope19:12
Added*.tesco.hu/*WILDCARDIn Scope19:12
Added*.tesco.com/*WILDCARDIn Scope19:12
Added*.tesco-europe.com/*WILDCARDIn Scope19:12
Added*.ourtesco.com/*WILDCARDIn Scope19:12
Addedhttps://www.onestop.co.uk/*WILDCARDIn Scope19:12
Added*.itesco.sk/*WILDCARDIn Scope19:12
Added*.itesco.cz/*WILDCARDIn Scope19:12
Addedcom.tesco.grocery.viewANDROIDIn Scope19:12
Addedhttps://www.booker.co.uk/*WILDCARDIn Scope19:12
Addedthird-party managed assetsOTHERIn Scope19:12
Addedmedium, high and critical severity issue on out-of-scope assetsOTHERIn Scope19:12
Addedleaked & default credentialsOTHERIn Scope19:12
Addedexposed sensitive documentsOTHERIn Scope19:12
Addeddomain, subdomain & zone takeoversOTHERIn Scope19:12
Addedcloud assetsOTHERIn Scope19:12
Addedapi assetsOTHERIn Scope19:12
Added857834425IOSIn Scope19:12
Added389581236IOSIn Scope19:12