expressvpn-bug-bounty-program

YesWeHackView on YesWeHack
RawAI Enhanced
30
In Scope
1
Out of Scope
In-Scope Assets (30)
AssetCategoryBountyQuick Links
*.expressvpn.comURLYes
*.polymoon.itURLYes
*.xvservice.netURLYes
*.xvtest.netURLYes
1pw-scim.prd.iat.it.xvservice.netURLYes
Any Applications under https://www.expressvpn.com/latestOTHERYes-
ExpressVPN APIsURLYes-
ExpressVPN RouterOTHERYes-
ExpressVPN VPN serversOTHERYes-
TrustedServer 100,000 Bonus Award (See Program Policy for Info)OTHERYes-
app.expressmailguard.comURLYes
corp.polymoon.itURLYes
expressvpn.jobsURLYes
gatekeeper.prd.iat.it.xvservice.netURLYes
gh-mail.expressvpn.comURLYes
https://api.blts.kape.comURLYes
https://api.dbs.kape.comURLYes
https://api.dts.kape.comURLYes
https://api.enc.kape.comURLYes
https://api.expressvpn.comURLYes
https://api.jwks.kape.comURLYes
https://api.pcrs.kape.comURLYes
https://cp.expressapisv2.netURLYes
https://github.com/expressvpn/lightwayOTHERYes-
https://xv-cp.apis-staging.xvtest.net/URLYes
iat.it.xvservice.netURLYes
it.xvservice.netURLYes
networkguard.comURLYes
prd.iat.it.xvservice.netURLYes
vector.prd.iat.it.xvservice.netURLYes
Out-of-Scope Assets (1)
AssetCategoryBounty
All domains or subdomains not listed in the above list of 'Scopes'OTHERYes
Scope Changes (94)
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedtrustedserver 100,000 bonus award (see program policy for info)OTHERIn Scope20:22
Added*.xvtest.netWILDCARDIn Scope19:08
Addedany applications under https://www.expressvpn.com/latestURLIn Scope19:08
Addedhttps://github.com/expressvpn/lightwayURLIn Scope19:08
Addedhttps://api.dbs.kape.comURLIn Scope19:08
Addedhttps://api.dts.kape.comURLIn Scope19:08
Addedhttps://api.jwks.kape.comURLIn Scope19:08
Addedall domains or subdomains not listed in the above list of 'scopes'OTHEROut of Scope19:08
Added*.expressvpn.comWILDCARDIn Scope19:08
Addedhttps://api.expressvpn.comURLIn Scope19:08
Addedhttps://api.pcrs.kape.comURLIn Scope19:08
Addedhttps://cp.expressapisv2.netURLIn Scope19:08
Addedgatekeeper.prd.iat.it.xvservice.netURLIn Scope19:08
Addediat.it.xvservice.netURLIn Scope19:08
Added*.polymoon.itWILDCARDIn Scope19:08
Addedcorp.polymoon.itURLIn Scope19:08
Addedexpressvpn apisURLIn Scope19:08
Addedhttps://xv-cp.apis-staging.xvtest.net/URLIn Scope19:08
Addedhttps://api.enc.kape.comURLIn Scope19:08
Addedit.xvservice.netURLIn Scope19:08
Added1pw-scim.prd.iat.it.xvservice.netURLIn Scope19:08
Addedprd.iat.it.xvservice.netURLIn Scope19:08
Addedgh-mail.expressvpn.comURLIn Scope19:08
Addedexpressvpn routerOTHERIn Scope19:08
Added*.xvservice.netWILDCARDIn Scope19:08
Addedvector.prd.iat.it.xvservice.netURLIn Scope19:08
Addednetworkguard.comURLIn Scope19:08
Addedexpressvpn.jobsURLIn Scope19:08
Addedhttps://api.blts.kape.comURLIn Scope19:08
Addedexpressvpn vpn serversOTHERIn Scope19:08
Addedapp.expressmailguard.comURLIn Scope19:08
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedgh-mail.expressvpn.comURLIn Scope00:51
Addedhttps://api.expressvpn.comURLIn Scope00:51
Added*.expressvpn.comWILDCARDIn Scope00:51
Addedhttps://api.pcrs.kape.comURLIn Scope00:51
Addedexpressvpn routerOTHERIn Scope00:51
Addedall domains or subdomains not listed in the above list of 'scopes'OTHEROut of Scope00:51
Addedhttps://xv-cp.apis-staging.xvtest.net/URLIn Scope00:51
Addedhttps://api.jwks.kape.comURLIn Scope00:51
Addediat.it.xvservice.netURLIn Scope00:51
Addedhttps://github.com/expressvpn/lightwayURLIn Scope00:51
Addedtrustedserver 100,000 bonus award (see program policy for info)OTHERIn Scope00:51
Added*.xvtest.netWILDCARDIn Scope00:51
Addedgatekeeper.prd.iat.it.xvservice.netURLIn Scope00:51
Added1pw-scim.prd.iat.it.xvservice.netURLIn Scope00:51
Addedprd.iat.it.xvservice.netURLIn Scope00:51
Added*.polymoon.itWILDCARDIn Scope00:51
Addedcorp.polymoon.itURLIn Scope00:51
Addedexpressvpn apisOTHERIn Scope00:51
Addedhttps://api.dbs.kape.comURLIn Scope00:51
Addedhttps://api.blts.kape.comURLIn Scope00:51
Addedit.xvservice.netURLIn Scope00:51
Addednetworkguard.comURLIn Scope00:51
Addedhttps://cp.expressapisv2.netURLIn Scope00:51
Addedhttps://api.dts.kape.comURLIn Scope00:51
Addedany applications under https://www.expressvpn.com/latestURLIn Scope00:51
Addedapp.expressmailguard.comURLIn Scope00:51
Addedexpressvpn.jobsURLIn Scope00:51
Addedhttps://api.enc.kape.comURLIn Scope00:51
Addedexpressvpn vpn serversOTHERIn Scope00:51
Added*.xvservice.netWILDCARDIn Scope00:51
Addedvector.prd.iat.it.xvservice.netURLIn Scope00:51
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removed*.expressvpn.comURLIn Scope21:40
Removedapp.expressmailguard.comURLIn Scope21:40
Removedexpressvpn.jobsURLIn Scope21:40
Removedexpressvpn apisURLIn Scope21:40
Removedhttps://xv-cp.apis-staging.xvtest.net/URLIn Scope21:40
Removedhttps://cp.expressapisv2.netURLIn Scope21:40
Removedhttps://api.expressvpn.comURLIn Scope21:40
Removedhttps://api.enc.kape.comURLIn Scope21:40
Removedhttps://api.dbs.kape.comURLIn Scope21:40
Removedhttps://api.dts.kape.comURLIn Scope21:40
Removedhttps://api.blts.kape.comURLIn Scope21:40
Removedhttps://api.pcrs.kape.comURLIn Scope21:40
Removedhttps://api.jwks.kape.comURLIn Scope21:40
Removedexpressvpn vpn serversOTHERIn Scope21:40
Removedexpressvpn routerOTHERIn Scope21:40
Removed*.xvtest.netURLIn Scope21:40
Removed*.xvservice.netURLIn Scope21:40
Removedit.xvservice.netURLIn Scope21:40
Removed1pw-scim.prd.iat.it.xvservice.netURLIn Scope21:40
Removedgatekeeper.prd.iat.it.xvservice.netURLIn Scope21:40
Removediat.it.xvservice.netURLIn Scope21:40
Removedprd.iat.it.xvservice.netURLIn Scope21:40
Removedvector.prd.iat.it.xvservice.netURLIn Scope21:40
Removedgh-mail.expressvpn.comURLIn Scope21:40
Removed*.polymoon.itURLIn Scope21:40
Removedcorp.polymoon.itURLIn Scope21:40
Removednetworkguard.comURLIn Scope21:40
Removedany applications under https://www.expressvpn.com/latestOTHERIn Scope21:40
Removedhttps://github.com/expressvpn/lightwayOTHERIn Scope21:40
Removedtrustedserver 100,000 bonus award (see program policy for info)OTHERIn Scope21:40
Removedall domains or subdomains not listed in the above list of 'scopes'OTHEROut of Scope21:40
Addedall domains or subdomains not listed in the above list of 'scopes'OTHEROut of Scope00:33