Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

vendasta

HackerOneView on HackerOne
RawAI Enhanced
11
In Scope
6
Out of Scope
In-Scope Assets (11)
Out-of-Scope Assets (6)
AssetCategoryBounty
Spamming of forms and APIs with automated vulnerability scanners are strictly out of scopeOTHERNo
help.yesware.comURLNo
roadmap.vendasta.comURLNo
t.yesware.comURLNo
www.vendasta.comURLNo
www.yesware.comURLNo
Scope Changes (51)
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedhelp.yesware.comURLOut of Scope19:12
Addedyour-domain.pdqs.mobiURLIn Scope19:12
Addedtask-manager.bizURLIn Scope19:12
Added*.apigateway.coWILDCARDIn Scope19:12
Addedcustomervoice.bizURLIn Scope19:12
Addedyour-domain.snapshotreport.bizURLIn Scope19:12
Addedspamming of forms and apis with automated vulnerability scanners are strictly out of scopeOTHEROut of Scope19:12
Addedt.yesware.comURLOut of Scope19:12
Added*.yesware.comWILDCARDIn Scope19:12
Addedwww.yesware.comURLOut of Scope19:12
Addedwww.vendasta.comURLOut of Scope19:12
Addedroadmap.vendasta.comURLOut of Scope19:12
Added*.vendasta-internal.comWILDCARDIn Scope19:12
Addedyour-domain.socialsmbs.comURLIn Scope19:12
Addedyour-domain.steprep.comURLIn Scope19:12
Addedyour-domain.smblogin.comURLIn Scope19:12
Addedpartners.vendasta.comURLIn Scope19:12
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedcustomervoice.bizURLIn Scope00:42
Addedyour-domain.steprep.comURLIn Scope00:42
Addedtask-manager.bizURLIn Scope00:42
Addedwww.yesware.comURLOut of Scope00:42
Added*.vendasta-internal.comWILDCARDIn Scope00:42
Addedroadmap.vendasta.comURLOut of Scope00:42
Addedwww.vendasta.comURLOut of Scope00:42
Added*.yesware.comWILDCARDIn Scope00:42
Added*.apigateway.coWILDCARDIn Scope00:42
Addedyour-domain.snapshotreport.bizURLIn Scope00:42
Addedhelp.yesware.comURLOut of Scope00:42
Addedyour-domain.socialsmbs.comURLIn Scope00:42
Addedyour-domain.smblogin.comURLIn Scope00:42
Addedyour-domain.pdqs.mobiURLIn Scope00:42
Addedpartners.vendasta.comURLIn Scope00:42
Addedspamming of forms and apis with automated vulnerability scanners are strictly out of scopeOTHEROut of Scope00:42
Addedt.yesware.comURLOut of Scope00:42
Feb 21, 2026
ChangeAssetCategoryScopeTime
Added*.yesware.comWILDCARDIn Scope19:12
Added*.apigateway.coWILDCARDIn Scope19:12
Added*.vendasta-internal.comWILDCARDIn Scope19:12
Addedcustomervoice.bizURLIn Scope19:12
Addedyour-domain.socialsmbs.comURLIn Scope19:12
Addedyour-domain.steprep.comURLIn Scope19:12
Addedyour-domain.smblogin.comURLIn Scope19:12
Addedyour-domain.pdqs.mobiURLIn Scope19:12
Addedyour-domain.snapshotreport.bizURLIn Scope19:12
Addedpartners.vendasta.comURLIn Scope19:12
Addedtask-manager.bizURLIn Scope19:12
Addedwww.yesware.comURLOut of Scope19:12
Addedhelp.yesware.comURLOut of Scope19:12
Addedroadmap.vendasta.comURLOut of Scope19:12
Addedspamming of forms and apis with automated vulnerability scanners are strictly out of scopeOTHEROut of Scope19:12
Addedwww.vendasta.comURLOut of Scope19:12
Addedt.yesware.comURLOut of Scope19:12