doctolib-public-bug-bounty-program

YesWeHackView on YesWeHack
RawAI Enhanced
9
In Scope
27
Out of Scope
In-Scope Assets (9)
AssetCategoryBountyQuick Links
*.doctolib.(fr|de|it|com|net)URLYes
*.siilo.comOTHERYes-
Special scenarios (see description)URLYes-
http://play.google.com/store/apps/details?id=fr.doctolib.wwwANDROIDYes
https://apps.apple.com/fr/app/doctolib/id925339063IOSYes-
https://apps.apple.com/ie/app/doctolib-siilo/id1083002150IOSYes-
https://play.google.com/store/apps/details?id=com.siilo.android&hl=enANDROIDYes
pro.doctolib.(fr|de|it) (see "Free features for healthcare professionals"))URLYes-
www.doctolib.(fr|de|it)URLYes
Out-of-Scope Assets (27)
AssetCategoryBounty
Any *.sslip.io, *.nip.io, AWS ELB / load-balancer hostname, or raw IPv4 / IPv6 addressOTHERYes
Craft CMS on www.siilo.com, plus siilo.com marketing / staging sub-domains (l.siilo.com, l-dev.siilo.com, web.siilo.com, web-dev.siilo.com, www-admin.siilo.com, mjt-dev.siilo.com, att-dev-nl.siilo.com, sandbox-nl.siilo.com, connect.siilo.com, prod-nl-web.siilo.com)OTHERYes
Look-alike, typo-squatting or expired domains not owned by Doctolib (e.g. www.dioctolib.de, doctolib.fr.evil.com, doctodketest.tk, doctolib-poc.partner-experience.com)OTHERYes
Note: should you discover a critical issue within an asset that falls outside the program's scope, we would appreciate it and may choose to offer a reward at our discretion.OTHERYes
Public GitHub repositories we do not own (such as student projects doing)OTHERYes
There is no IDOR on /api/security/tanker_groups via subject_idOTHERYes
Third-party assets linked from our products (e.g. login.decathlon.net, wallet.esw.esante.gouv.fr, preprod.alaxione.fr, hooks.zapier.com, cron.signitic.app, job-boards.greenhouse.io, docto.digitalstack.it, and any hospital-specific or customer-specific host)OTHERYes
api.tanker.io (Accessing the tanker private key is normal functioning of the Tanker protocol)OTHERYes
billing-client-logs.billing.doctolib.fr | api-external.datascience.doctolibdata.comOTHERYes
community.doctolib.com | .fr | .de | .itOTHERYes
developers.doctolib.comOTHERYes
dmp.doctolib.fr | dmp-prd-aws-*.doctolib.frOTHERYes
doctocommit.doctolib.frOTHERYes
doctolib-ps-ehr-downloads.s3.amazonaws.comOTHERYes
doctolib.atlassian.net and any *.atlassian.net pathOTHERYes
doctolib.zendesk.com | siilo.zendesk.comOTHERYes
exceptions.doctolib.fr | .deOTHERYes
fb.doctolib.com | fb-dev.doctolib.frOTHERYes
fm.doctolib.fr | fm.doctolib.it | voip.doctolib.de and other decommissioned / dangling Doctolib sub-domainsOTHERYes
info.doctolib.com | .fr | .de | .itOTHERYes
media.doctolib.comOTHERYes
partners.doctolib.fr | partnerportal.doctolib.com | partnerprogram.doctolib.comOTHERYes
pro-app.doctolib.comOTHERYes
share.doctolib.netOTHERYes
status.doctolib.com | .fr | .itOTHERYes
store.doctolib.comOTHERYes
vettore.it and any related Vettore assetsOTHERYes
Scope Changes (170)
Apr 29, 2026
ChangeAssetCategoryScopeTime
Addedthere is no idor on /api/security/tanker_groups via subject_idOTHEROut of Scope09:26
Addedthere is no idor on /api/security/tanker_groups via subject_idOTHEROut of Scope09:26
Apr 22, 2026
ChangeAssetCategoryScopeTime
Addedstatus.doctolib.com | .fr | .itOTHEROut of Scope15:21
Addedmedia.doctolib.comOTHEROut of Scope15:21
Addedfb.doctolib.com | fb-dev.doctolib.frOTHEROut of Scope15:21
Addedpro-app.doctolib.comOTHEROut of Scope15:21
Addeddevelopers.doctolib.comOTHEROut of Scope15:21
Addedpartners.doctolib.fr | partnerportal.doctolib.com | partnerprogram.doctolib.comOTHEROut of Scope15:21
Addeddmp.doctolib.fr | dmp-prd-aws-*.doctolib.frOTHEROut of Scope15:21
Addedfm.doctolib.fr | fm.doctolib.it | voip.doctolib.de and other decommissioned / dangling doctolib sub-domainsOTHEROut of Scope15:21
Addeddoctolib.atlassian.net and any *.atlassian.net pathOTHEROut of Scope15:21
Addeddoctolib.zendesk.com | siilo.zendesk.comOTHEROut of Scope15:21
Addedapi.tanker.io (accessing the tanker private key is normal functioning of the tanker protocol)OTHEROut of Scope15:21
Addedexceptions.doctolib.fr | .deOTHEROut of Scope15:21
Addedbilling-client-logs.billing.doctolib.fr | api-external.datascience.doctolibdata.comOTHEROut of Scope15:21
Addeddoctolib-ps-ehr-downloads.s3.amazonaws.comOTHEROut of Scope15:21
Addedvettore.it and any related vettore assetsOTHEROut of Scope15:21
Addedcraft cms on www.siilo.com, plus siilo.com marketing / staging sub-domains (l.siilo.com, l-dev.siilo.com, web.siilo.com, web-dev.siilo.com, www-admin.siilo.com, mjt-dev.siilo.com, att-dev-nl.siilo.com, sandbox-nl.siilo.com, connect.siilo.com, prod-nl-web.siilo.com)OTHEROut of Scope15:21
Addedthird-party assets linked from our products (e.g. login.decathlon.net, wallet.esw.esante.gouv.fr, preprod.alaxione.fr, hooks.zapier.com, cron.signitic.app, job-boards.greenhouse.io, docto.digitalstack.it, and any hospital-specific or customer-specific host)OTHEROut of Scope15:21
Addedany *.sslip.io, *.nip.io, aws elb / load-balancer hostname, or raw ipv4 / ipv6 addressOTHEROut of Scope15:21
Addedlook-alike, typo-squatting or expired domains not owned by doctolib (e.g. www.dioctolib.de, doctolib.fr.evil.com, doctodketest.tk, doctolib-poc.partner-experience.com)OTHEROut of Scope15:21
Addedpublic github repositories we do not own (such as student projects doing)OTHEROut of Scope15:21
Removedcommunity.doctolib.com|.fr|.de|.itOTHEROut of Scope15:21
Removeddoctolib.zendesk.comOTHEROut of Scope15:21
Removedvettore.it (and any related vettore assets)OTHEROut of Scope15:21
Removeddoctolib.atlassian.netOTHEROut of Scope15:21
Removedcraft cms on www.siilo.comOTHEROut of Scope15:21
Addedpro-app.doctolib.comOTHEROut of Scope15:21
Addeddevelopers.doctolib.comOTHEROut of Scope15:21
Addedapi.tanker.io (accessing the tanker private key is normal functioning of the tanker protocol)OTHEROut of Scope15:21
Addedcommunity.doctolib.com | .fr | .de | .itOTHEROut of Scope15:21
Addedany *.sslip.io, *.nip.io, aws elb / load-balancer hostname, or raw ipv4 / ipv6 addressWILDCARDOut of Scope15:21
Addedany *.sslip.io, *.nip.io, aws elb / load-balancer hostname, or raw ipv4 / ipv6 addressWILDCARDOut of Scope15:21
Addedany *.sslip.io, *.nip.io, aws elb / load-balancer hostname, or raw ipv4 / ipv6 addressWILDCARDOut of Scope15:21
Addedany *.sslip.io, *.nip.io, aws elb / load-balancer hostname, or raw ipv4 / ipv6 addressWILDCARDOut of Scope15:21
Addeddoctolib.atlassian.net and any *.atlassian.net pathOTHEROut of Scope15:21
Addeddoctolib.atlassian.net and any *.atlassian.net pathOTHEROut of Scope15:21
Addedinfo.doctolib.com | .fr | .de | .itOTHEROut of Scope15:21
Addedinfo.doctolib.com | .fr | .de | .itOTHEROut of Scope15:21
Addedinfo.doctolib.com | .fr | .de | .itOTHEROut of Scope15:21
Addedinfo.doctolib.com | .fr | .de | .itOTHEROut of Scope15:21
Addedfm.doctolib.fr | fm.doctolib.it | voip.doctolib.de and other decommissioned / dangling doctolib sub-domainsOTHEROut of Scope15:21
Addedfm.doctolib.fr | fm.doctolib.it | voip.doctolib.de and other decommissioned / dangling doctolib sub-domainsOTHEROut of Scope15:21
Addedfm.doctolib.fr | fm.doctolib.it | voip.doctolib.de and other decommissioned / dangling doctolib sub-domainsOTHEROut of Scope15:21
Addedfm.doctolib.fr | fm.doctolib.it | voip.doctolib.de and other decommissioned / dangling doctolib sub-domainsOTHEROut of Scope15:21
Addeddoctolib.zendesk.com | siilo.zendesk.comOTHEROut of Scope15:21
Addeddoctolib.zendesk.com | siilo.zendesk.comOTHEROut of Scope15:21
Addedexceptions.doctolib.fr | .deOTHEROut of Scope15:21
Addedexceptions.doctolib.fr | .deOTHEROut of Scope15:21
Addeddoctolib-ps-ehr-downloads.s3.amazonaws.comOTHEROut of Scope15:21
Addedvettore.it and any related vettore assetsOTHEROut of Scope15:21
Addedvettore.it and any related vettore assetsOTHEROut of Scope15:21
Addedstatus.doctolib.com | .fr | .itOTHEROut of Scope15:21
Addedstatus.doctolib.com | .fr | .itOTHEROut of Scope15:21
Addedstatus.doctolib.com | .fr | .itOTHEROut of Scope15:21
Addedlook-alike, typo-squatting or expired domains not owned by doctolib (e.g. www.dioctolib.de, doctolib.fr.evil.com, doctodketest.tk, doctolib-poc.partner-experience.com)OTHEROut of Scope15:21
Addedpublic github repositories we do not own (such as student projects doing)OTHEROut of Scope15:21
Addedpartners.doctolib.fr | partnerportal.doctolib.com | partnerprogram.doctolib.comOTHEROut of Scope15:21
Addedpartners.doctolib.fr | partnerportal.doctolib.com | partnerprogram.doctolib.comOTHEROut of Scope15:21
Addedpartners.doctolib.fr | partnerportal.doctolib.com | partnerprogram.doctolib.comOTHEROut of Scope15:21
Addedbilling-client-logs.billing.doctolib.fr | api-external.datascience.doctolibdata.comOTHEROut of Scope15:21
Addedbilling-client-logs.billing.doctolib.fr | api-external.datascience.doctolibdata.comOTHEROut of Scope15:21
Addedcommunity.doctolib.com | .fr | .de | .itOTHEROut of Scope15:21
Addedcommunity.doctolib.com | .fr | .de | .itOTHEROut of Scope15:21
Addedcommunity.doctolib.com | .fr | .de | .itOTHEROut of Scope15:21
Addedcommunity.doctolib.com | .fr | .de | .itOTHEROut of Scope15:21
Addedfb.doctolib.com | fb-dev.doctolib.frOTHEROut of Scope15:21
Addedfb.doctolib.com | fb-dev.doctolib.frOTHEROut of Scope15:21
Addedmedia.doctolib.comOTHEROut of Scope15:21
Addeddmp.doctolib.fr | dmp-prd-aws-*.doctolib.frOTHEROut of Scope15:21
Addeddmp.doctolib.fr | dmp-prd-aws-*.doctolib.frOTHEROut of Scope15:21
Addedcraft cms on www.siilo.com, plus siilo.com marketing / staging sub-domains (l.siilo.com, l-dev.siilo.com, web.siilo.com, web-dev.siilo.com, www-admin.siilo.com, mjt-dev.siilo.com, att-dev-nl.siilo.com, sandbox-nl.siilo.com, connect.siilo.com, prod-nl-web.siilo.com)OTHEROut of Scope15:21
Addedcraft cms on www.siilo.com, plus siilo.com marketing / staging sub-domains (l.siilo.com, l-dev.siilo.com, web.siilo.com, web-dev.siilo.com, www-admin.siilo.com, mjt-dev.siilo.com, att-dev-nl.siilo.com, sandbox-nl.siilo.com, connect.siilo.com, prod-nl-web.siilo.com)OTHEROut of Scope15:21
Addedcraft cms on www.siilo.com, plus siilo.com marketing / staging sub-domains (l.siilo.com, l-dev.siilo.com, web.siilo.com, web-dev.siilo.com, www-admin.siilo.com, mjt-dev.siilo.com, att-dev-nl.siilo.com, sandbox-nl.siilo.com, connect.siilo.com, prod-nl-web.siilo.com)OTHEROut of Scope15:21
Addedcraft cms on www.siilo.com, plus siilo.com marketing / staging sub-domains (l.siilo.com, l-dev.siilo.com, web.siilo.com, web-dev.siilo.com, www-admin.siilo.com, mjt-dev.siilo.com, att-dev-nl.siilo.com, sandbox-nl.siilo.com, connect.siilo.com, prod-nl-web.siilo.com)OTHEROut of Scope15:21
Addedcraft cms on www.siilo.com, plus siilo.com marketing / staging sub-domains (l.siilo.com, l-dev.siilo.com, web.siilo.com, web-dev.siilo.com, www-admin.siilo.com, mjt-dev.siilo.com, att-dev-nl.siilo.com, sandbox-nl.siilo.com, connect.siilo.com, prod-nl-web.siilo.com)OTHEROut of Scope15:21
Addedcraft cms on www.siilo.com, plus siilo.com marketing / staging sub-domains (l.siilo.com, l-dev.siilo.com, web.siilo.com, web-dev.siilo.com, www-admin.siilo.com, mjt-dev.siilo.com, att-dev-nl.siilo.com, sandbox-nl.siilo.com, connect.siilo.com, prod-nl-web.siilo.com)OTHEROut of Scope15:21
Addedcraft cms on www.siilo.com, plus siilo.com marketing / staging sub-domains (l.siilo.com, l-dev.siilo.com, web.siilo.com, web-dev.siilo.com, www-admin.siilo.com, mjt-dev.siilo.com, att-dev-nl.siilo.com, sandbox-nl.siilo.com, connect.siilo.com, prod-nl-web.siilo.com)OTHEROut of Scope15:21
Addedcraft cms on www.siilo.com, plus siilo.com marketing / staging sub-domains (l.siilo.com, l-dev.siilo.com, web.siilo.com, web-dev.siilo.com, www-admin.siilo.com, mjt-dev.siilo.com, att-dev-nl.siilo.com, sandbox-nl.siilo.com, connect.siilo.com, prod-nl-web.siilo.com)OTHEROut of Scope15:21
Addedcraft cms on www.siilo.com, plus siilo.com marketing / staging sub-domains (l.siilo.com, l-dev.siilo.com, web.siilo.com, web-dev.siilo.com, www-admin.siilo.com, mjt-dev.siilo.com, att-dev-nl.siilo.com, sandbox-nl.siilo.com, connect.siilo.com, prod-nl-web.siilo.com)OTHEROut of Scope15:21
Addedcraft cms on www.siilo.com, plus siilo.com marketing / staging sub-domains (l.siilo.com, l-dev.siilo.com, web.siilo.com, web-dev.siilo.com, www-admin.siilo.com, mjt-dev.siilo.com, att-dev-nl.siilo.com, sandbox-nl.siilo.com, connect.siilo.com, prod-nl-web.siilo.com)OTHEROut of Scope15:21
Addedcraft cms on www.siilo.com, plus siilo.com marketing / staging sub-domains (l.siilo.com, l-dev.siilo.com, web.siilo.com, web-dev.siilo.com, www-admin.siilo.com, mjt-dev.siilo.com, att-dev-nl.siilo.com, sandbox-nl.siilo.com, connect.siilo.com, prod-nl-web.siilo.com)OTHEROut of Scope15:21
Addedcraft cms on www.siilo.com, plus siilo.com marketing / staging sub-domains (l.siilo.com, l-dev.siilo.com, web.siilo.com, web-dev.siilo.com, www-admin.siilo.com, mjt-dev.siilo.com, att-dev-nl.siilo.com, sandbox-nl.siilo.com, connect.siilo.com, prod-nl-web.siilo.com)OTHEROut of Scope15:21
Addedthird-party assets linked from our products (e.g. login.decathlon.net, wallet.esw.esante.gouv.fr, preprod.alaxione.fr, hooks.zapier.com, cron.signitic.app, job-boards.greenhouse.io, docto.digitalstack.it, and any hospital-specific or customer-specific host)OTHEROut of Scope15:21
Addedinfo.doctolib.com | .fr | .de | .itOTHEROut of Scope15:21
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedvettore.it (and any related vettore assets)URLOut of Scope19:08
Addedpro.doctolib.(fr|de|it) (see "free features for healthcare professionals"))URLIn Scope19:08
Added*.doctolib.(fr|de|it|com|net)WILDCARDIn Scope19:08
Added*.doctolib.(fr|de|it|com|net)WILDCARDIn Scope19:08
Added*.doctolib.(fr|de|it|com|net)WILDCARDIn Scope19:08
Added*.doctolib.(fr|de|it|com|net)WILDCARDIn Scope19:08
Added*.doctolib.(fr|de|it|com|net)WILDCARDIn Scope19:08
Addedhttp://play.google.com/store/apps/details?id=fr.doctolib.wwwANDROIDIn Scope19:08
Added*.siilo.comWILDCARDIn Scope19:08
Addedhttps://apps.apple.com/ie/app/doctolib-siilo/id1083002150IOSIn Scope19:08
Addedhttps://play.google.com/store/apps/details?id=com.siilo.android&hl=enANDROIDIn Scope19:08
Addedstore.doctolib.comURLOut of Scope19:08
Addedshare.doctolib.netURLOut of Scope19:08
Addedwww.doctolib.(fr|de|it)URLIn Scope19:08
Addedwww.doctolib.(fr|de|it)URLIn Scope19:08
Addedwww.doctolib.(fr|de|it)URLIn Scope19:08
Addednote: should you discover a critical issue within an asset that falls outside the program's scope, we would appreciate it and may choose to offer a reward at our discretionOTHEROut of Scope19:08
Addeddoctocommit.doctolib.frURLOut of Scope19:08
Addeddoctolib.zendesk.comURLOut of Scope19:08
Addedhttps://apps.apple.com/fr/app/doctolib/id925339063IOSIn Scope19:08
Addedspecial scenarios (see description)URLIn Scope19:08
Addedcommunity.doctolib.com|.fr|.de|.itURLOut of Scope19:08
Addedcommunity.doctolib.com|.fr|.de|.itURLOut of Scope19:08
Addedcommunity.doctolib.com|.fr|.de|.itURLOut of Scope19:08
Addedcommunity.doctolib.com|.fr|.de|.itURLOut of Scope19:08
Addeddoctolib.atlassian.netURLOut of Scope19:08
Addedcraft cms on www.siilo.comOTHEROut of Scope19:08
Addedpro.doctolib.(fr|de|it) (see "free features for healthcare professionals"))URLIn Scope19:08
Addedpro.doctolib.(fr|de|it) (see "free features for healthcare professionals"))URLIn Scope19:08
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedhttp://play.google.com/store/apps/details?id=fr.doctolib.wwwANDROIDIn Scope00:51
Added*.doctolib.(fr|de|it|com|net)WILDCARDIn Scope00:51
Added*.doctolib.(fr|de|it|com|net)WILDCARDIn Scope00:51
Addedwww.doctolib.(fr|de|it)URLIn Scope00:51
Addedwww.doctolib.(fr|de|it)URLIn Scope00:51
Addedwww.doctolib.(fr|de|it)URLIn Scope00:51
Addeddoctolib.atlassian.netURLOut of Scope00:51
Addeddoctolib.zendesk.comURLOut of Scope00:51
Addedcraft cms on www.siilo.comURLOut of Scope00:51
Addedhttps://apps.apple.com/fr/app/doctolib/id925339063IOSIn Scope00:51
Addedhttps://apps.apple.com/ie/app/doctolib-siilo/id1083002150IOSIn Scope00:51
Addednote: should you discover a critical issue within an asset that falls outside the program's scope, we would appreciate it and may choose to offer a reward at our discretionOTHEROut of Scope00:51
Addedcommunity.doctolib.com|.fr|.de|.itURLOut of Scope00:51
Addedcommunity.doctolib.com|.fr|.de|.itURLOut of Scope00:51
Addedcommunity.doctolib.com|.fr|.de|.itURLOut of Scope00:51
Addedcommunity.doctolib.com|.fr|.de|.itURLOut of Scope00:51
Addeddoctocommit.doctolib.frURLOut of Scope00:51
Addedstore.doctolib.comURLOut of Scope00:51
Addedshare.doctolib.netURLOut of Scope00:51
Addedpro.doctolib.(fr|de|it) (see "free features for healthcare professionals"))URLIn Scope00:51
Addedpro.doctolib.(fr|de|it) (see "free features for healthcare professionals"))URLIn Scope00:51
Addedpro.doctolib.(fr|de|it) (see "free features for healthcare professionals"))URLIn Scope00:51
Added*.siilo.comWILDCARDIn Scope00:51
Addedhttps://play.google.com/store/apps/details?id=com.siilo.android&hl=enANDROIDIn Scope00:51
Addedvettore.it (and any related vettore assets)URLOut of Scope00:51
Addedspecial scenarios (see description)URLIn Scope00:51
Added*.doctolib.(fr|de|it|com|net)WILDCARDIn Scope00:51
Added*.doctolib.(fr|de|it|com|net)WILDCARDIn Scope00:51
Added*.doctolib.(fr|de|it|com|net)WILDCARDIn Scope00:51
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removedpro.doctolib.(fr|de|it) (see "free features for healthcare professionals"))URLIn Scope21:40
Removedspecial scenarios (see description)URLIn Scope21:40
Removed*.doctolib.(fr|de|it|com|net)URLIn Scope21:40
Removedhttps://apps.apple.com/fr/app/doctolib/id925339063IOSIn Scope21:40
Removedhttp://play.google.com/store/apps/details?id=fr.doctolib.wwwANDROIDIn Scope21:40
Removed*.siilo.comOTHERIn Scope21:40
Removedhttps://apps.apple.com/ie/app/doctolib-siilo/id1083002150IOSIn Scope21:40
Removedhttps://play.google.com/store/apps/details?id=com.siilo.android&hl=enANDROIDIn Scope21:40
Removednote: should you discover a critical issue within an asset that falls outside the program's scope, we would appreciate it and may choose to offer a reward at our discretionOTHEROut of Scope21:40
Removedcommunity.doctolib.com|.fr|.de|.itOTHEROut of Scope21:40
Removeddoctocommit.doctolib.frOTHEROut of Scope21:40
Removeddoctolib.atlassian.netOTHEROut of Scope21:40
Removeddoctolib.zendesk.comOTHEROut of Scope21:40
Removedstore.doctolib.comOTHEROut of Scope21:40
Removedshare.doctolib.netOTHEROut of Scope21:40
Removedvettore.it (and any related vettore assets)OTHEROut of Scope21:40
Removedcraft cms on www.siilo.comOTHEROut of Scope21:40
Removedwww.doctolib.(fr|de|it)URLIn Scope21:40
Addedcommunity.doctolib.com|.fr|.de|.itOTHEROut of Scope00:33
Addeddoctocommit.doctolib.frOTHEROut of Scope00:33
Addeddoctolib.atlassian.netOTHEROut of Scope00:33
Addeddoctolib.zendesk.comOTHEROut of Scope00:33
Addedstore.doctolib.comOTHEROut of Scope00:33
Addedshare.doctolib.netOTHEROut of Scope00:33
Addedvettore.it (and any related vettore assets)OTHEROut of Scope00:33
Addedcraft cms on www.siilo.comOTHEROut of Scope00:33
Addednote: should you discover a critical issue within an asset that falls outside the program's scope, we would appreciate it and may choose to offer a reward at our discretionOTHEROut of Scope00:33