bug-bounty-sncf-connect-1

YesWeHackView on YesWeHack
RawAI Enhanced
4
In Scope
15
Out of Scope
In-Scope Assets (4)
Out-of-Scope Assets (15)
AssetCategoryBounty
- hiflow.sncf-connect.comOTHERYes
- office-web-sncf-a.sips-services.comOTHERYes
- ouigo.comOTHERYes
- sncf-voyageurs.comOTHERYes
- ter.sncf.comOTHERYes
- tgvinoui.sncfOTHERYes
- www.garesetconnexions.sncfOTHERYes
- www.groupe-sncf.comOTHERYes
- www.malocationavis.sncf-connect.comOTHERYes
- www.maxjeune-tgvinoui.sncfOTHERYes
- www.sncf-connect-tech.frOTHERYes
- www.sncf-voyageurs.comOTHERYes
- www.sncf.comOTHERYes
The SNCF Connect mobile applications (Android and Apple) are out of scope even if the web services they use are in scope (accessible through paths beginning by 'https://www.sncf-connect.com/bff').OTHERYes
The scope of the Bug Bounty program is defined in the preceding section. To remove any potential ambiguity regarding this scope, the following non‑exhaustive examples illustrate domains that are not included in the program:OTHERYes
Scope Changes (86)
Feb 25, 2026
ChangeAssetCategoryScopeTime
Added- office-web-sncf-a.sips-services.comURLOut of Scope19:08
Added- www.sncf.comURLOut of Scope19:08
Added- hiflow.sncf-connect.comURLOut of Scope19:08
Addedhttps://sncf-connect.comURLIn Scope19:08
Addedhttps//monidentifiant.sncfURLIn Scope19:08
Addedhttps://www.sncf-connect.com/bffURLIn Scope19:08
Added- www.malocationavis.sncf-connect.comURLOut of Scope19:08
Addedthe sncf connect mobile applications (android and apple) are out of scope even if the web services they use are in scope (accessible through paths beginning by 'https://www.sncf-connect.com/bff')OTHEROut of Scope19:08
Added- sncf-voyageurs.comURLOut of Scope19:08
Added- tgvinoui.sncfURLOut of Scope19:08
Added- ter.sncf.comURLOut of Scope19:08
Added- ouigo.comURLOut of Scope19:08
Added- www.maxjeune-tgvinoui.sncfURLOut of Scope19:08
Addedhttps://www.sncf-connect.comURLIn Scope19:08
Addedthe scope of the bug bounty program is defined in the preceding section. to remove any potential ambiguity regarding this scope, the following non‑exhaustive examples illustrate domains that are not included in the program:OTHEROut of Scope19:08
Added- www.groupe-sncf.comURLOut of Scope19:08
Added- www.garesetconnexions.sncfURLOut of Scope19:08
Added- www.sncf-voyageurs.comURLOut of Scope19:08
Added- www.sncf-connect-tech.frURLOut of Scope19:08
Feb 23, 2026
ChangeAssetCategoryScopeTime
Added- hiflow.sncf-connect.comURLOut of Scope09:43
Added- office-web-sncf-a.sips-services.comURLOut of Scope09:43
Added- www.sncf.comURLOut of Scope09:43
Added- www.groupe-sncf.comURLOut of Scope09:43
Added- tgvinoui.sncfURLOut of Scope09:43
Added- www.malocationavis.sncf-connect.comURLOut of Scope09:43
Added- www.garesetconnexions.sncfURLOut of Scope09:43
Added- ouigo.comURLOut of Scope09:43
Added- sncf-voyageurs.comURLOut of Scope09:43
Added- www.sncf-voyageurs.comURLOut of Scope09:43
Added- ter.sncf.comURLOut of Scope09:43
Added- www.maxjeune-tgvinoui.sncfURLOut of Scope09:43
Addedthe scope of the bug bounty program is defined in the preceding section. to remove any potential ambiguity regarding this scope, the following non‑exhaustive examples illustrate domains that are not included in the program:OTHEROut of Scope09:43
Added- www.sncf-connect-tech.frOTHEROut of Scope09:43
Added- office-web-sncf-a.sips-services.comOTHEROut of Scope09:43
Added- www.sncf.comOTHEROut of Scope09:43
Added- www.groupe-sncf.comOTHEROut of Scope09:43
Added- www.garesetconnexions.sncfOTHEROut of Scope09:43
Added- sncf-voyageurs.comOTHEROut of Scope09:43
Added- www.sncf-voyageurs.comOTHEROut of Scope09:43
Added- tgvinoui.sncfOTHEROut of Scope09:43
Added- ter.sncf.comOTHEROut of Scope09:43
Added- ouigo.comOTHEROut of Scope09:43
Added- www.maxjeune-tgvinoui.sncfOTHEROut of Scope09:43
Added- www.malocationavis.sncf-connect.comOTHEROut of Scope09:43
Added- hiflow.sncf-connect.comOTHEROut of Scope09:43
Removedplease note sncf-connect.com doesn't own the sncf.com domainsOTHEROut of Scope09:43
Removed- https://www.sncf.comOTHEROut of Scope09:43
Removed- https://www.malocationavis.sncf-connect.comOTHEROut of Scope09:43
Removed- https://www.maxjeune-tgvinoui.sncfOTHEROut of Scope09:43
Removedanything that is not listed as part of the scope, example :OTHEROut of Scope09:43
Removed- https://tgvinoui.sncfOTHEROut of Scope09:43
Removed- https://www.sncf-voyageurs.comOTHEROut of Scope09:43
Addedthe scope of the bug bounty program is defined in the preceding section. to remove any potential ambiguity regarding this scope, the following non‑exhaustive examples illustrate domains that are not included in the program:OTHEROut of Scope09:43
Added- www.sncf-connect-tech.frURLOut of Scope09:43
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedanything that is not listed as part of the scope, example :OTHEROut of Scope00:52
Added- https://www.malocationavis.sncf-connect.comURLOut of Scope00:52
Addedhttps//monidentifiant.sncfURLIn Scope00:52
Addedplease note sncf-connect.com doesn't own the sncf.com domainsOTHEROut of Scope00:52
Added- https://www.sncf.comURLOut of Scope00:52
Addedthe sncf connect mobile applications (android and apple) are out of scope even if the web services they use are in scope (accessible through paths beginning by 'https://www.sncf-connect.com/bff')OTHEROut of Scope00:52
Addedhttps://www.sncf-connect.comURLIn Scope00:52
Addedhttps://sncf-connect.comURLIn Scope00:52
Addedhttps://www.sncf-connect.com/bffURLIn Scope00:52
Added- https://tgvinoui.sncfURLOut of Scope00:52
Added- https://www.sncf-voyageurs.comURLOut of Scope00:52
Added- https://www.maxjeune-tgvinoui.sncfURLOut of Scope00:52
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removedthe sncf connect mobile applications (android and apple) are out of scope even if the web services they use are in scope (accessible through paths beginning by 'https://www.sncf-connect.com/bff')OTHEROut of Scope21:40
Removedhttps://www.sncf-connect.com/bffURLIn Scope21:40
Removedplease note sncf-connect.com doesn't own the sncf.com domainsOTHEROut of Scope21:40
Removedanything that is not listed as part of the scope, example :OTHEROut of Scope21:40
Removed- https://www.sncf.comOTHEROut of Scope21:40
Removed- https://tgvinoui.sncfOTHEROut of Scope21:40
Removed- https://www.sncf-voyageurs.comOTHEROut of Scope21:40
Removed- https://www.maxjeune-tgvinoui.sncfOTHEROut of Scope21:40
Removed- https://www.malocationavis.sncf-connect.comOTHEROut of Scope21:40
Removedhttps://www.sncf-connect.comURLIn Scope21:40
Removedhttps://sncf-connect.comURLIn Scope21:40
Removedhttps//monidentifiant.sncfURLIn Scope21:40
Addedanything that is not listed as part of the scope, example :OTHEROut of Scope00:33
Added- https://www.sncf.comOTHEROut of Scope00:33
Added- https://tgvinoui.sncfOTHEROut of Scope00:33
Added- https://www.sncf-voyageurs.comOTHEROut of Scope00:33
Added- https://www.maxjeune-tgvinoui.sncfOTHEROut of Scope00:33
Added- https://www.malocationavis.sncf-connect.comOTHEROut of Scope00:33
Addedthe sncf connect mobile applications (android and apple) are out of scope even if the web services they use are in scope (accessible through paths beginning by 'https://www.sncf-connect.com/bff')OTHEROut of Scope00:33
Addedplease note sncf-connect.com doesn't own the sncf.com domainsOTHEROut of Scope00:33