moneybox-bug-bounty

YesWeHackView on YesWeHack
RawAI Enhanced
6
In Scope
1
Out of Scope
In-Scope Assets (6)
Out-of-Scope Assets (1)
AssetCategoryBounty
All domains or subdomains not listed in the above list of 'Scopes'OTHERYes
Scope Changes (47)
Apr 22, 2026
ChangeAssetCategoryScopeTime
Addedhttps://api.moneyboxapp.comURLIn Scope16:21
Removedthe moneybox public website https://www.moneyboxapp.com/ and other moneyboxapp.com / moneyboxapp.org domains not listed are out of scopeOTHEROut of Scope16:21
Addedhttps://api.moneyboxapp.comURLIn Scope16:21
Addedhttps://admin.moneyboxapp.orgURLIn Scope16:21
Addedhttps://admin-roundups.moneyboxapp.orgURLIn Scope16:21
Addedhttps://sycamore.moneyboxapp.orgURLIn Scope16:21
Addedall domains or subdomains not listed in the above list of 'scopes'OTHEROut of Scope16:21
Removedhttps://api.moneyboxapp.com/URLIn Scope16:21
Removedhttps://admin.moneyboxapp.org/URLIn Scope16:21
Removedcontent served by the cloudflare access service (https://moneyboxapp.cloudflareaccess.com/*) is out of scope. these pages intentionally do not set a cors allow-origin policy. we have seen this reported several times as a vulnerability, but it is intended behaviour and is considered out of scopeOTHEROut of Scope16:21
Removedhttps://admin-roundups.moneyboxapp.org/URLIn Scope16:21
Removedsecurity concerns originating from https://moneyboxapp.onelogin.com/ are typically considered out of scope. these pages and their content are served by onelogin, and any issues should be reported to them directly. however, if an exploit explicitly enables bypassing onelogin to access moneybox systems or leaking moneybox sensitive data, it is crucial to raise the concerns to both onelogin and moneyboxOTHEROut of Scope16:21
Removedhttps://sycamore.moneyboxapp.org/URLIn Scope16:21
Addedhttps://admin.moneyboxapp.orgURLIn Scope16:21
Addedhttps://admin-roundups.moneyboxapp.orgURLIn Scope16:21
Addedhttps://sycamore.moneyboxapp.orgURLIn Scope16:21
Addedall domains or subdomains not listed in the above list of 'scopes'OTHEROut of Scope16:21
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedcontent served by the cloudflare access service (https://moneyboxapp.cloudflareaccess.com/*) is out of scope. these pages intentionally do not set a cors allow-origin policy. we have seen this reported several times as a vulnerability, but it is intended behaviour and is considered out of scopeOTHEROut of Scope19:09
Addedhttps://play.google.com/store/apps/details?id=com.moneyboxappANDROIDIn Scope19:09
Addedhttps://sycamore.moneyboxapp.org/URLIn Scope19:09
Addedthe moneybox public website https://www.moneyboxapp.com/ and other moneyboxapp.com / moneyboxapp.org domains not listed are out of scopeOTHEROut of Scope19:09
Addedhttps://api.moneyboxapp.com/URLIn Scope19:09
Addedhttps://admin.moneyboxapp.org/URLIn Scope19:09
Addedhttps://apps.apple.com/gb/app/moneybox-save-and-invest/id1049797239IOSIn Scope19:09
Addedsecurity concerns originating from https://moneyboxapp.onelogin.com/ are typically considered out of scope. these pages and their content are served by onelogin, and any issues should be reported to them directly. however, if an exploit explicitly enables bypassing onelogin to access moneybox systems or leaking moneybox sensitive data, it is crucial to raise the concerns to both onelogin and moneyboxOTHEROut of Scope19:09
Addedhttps://admin-roundups.moneyboxapp.org/URLIn Scope19:09
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedhttps://admin.moneyboxapp.org/URLIn Scope00:52
Addedhttps://admin-roundups.moneyboxapp.org/URLIn Scope00:52
Addedhttps://play.google.com/store/apps/details?id=com.moneyboxappANDROIDIn Scope00:52
Addedhttps://sycamore.moneyboxapp.org/URLIn Scope00:52
Addedthe moneybox public website https://www.moneyboxapp.com/ and other moneyboxapp.com / moneyboxapp.org domains not listed are out of scopeOTHEROut of Scope00:52
Addedcontent served by the cloudflare access service (https://moneyboxapp.cloudflareaccess.com/*) is out of scope. these pages intentionally do not set a cors allow-origin policy. we have seen this reported several times as a vulnerability, but it is intended behaviour and is considered out of scopeOTHEROut of Scope00:52
Addedsecurity concerns originating from https://moneyboxapp.onelogin.com/ are typically considered out of scope. these pages and their content are served by onelogin, and any issues should be reported to them directly. however, if an exploit explicitly enables bypassing onelogin to access moneybox systems or leaking moneybox sensitive data, it is crucial to raise the concerns to both onelogin and moneyboxOTHEROut of Scope00:52
Addedhttps://api.moneyboxapp.com/URLIn Scope00:52
Addedhttps://apps.apple.com/gb/app/moneybox-save-and-invest/id1049797239IOSIn Scope00:52
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removedhttps://api.moneyboxapp.com/URLIn Scope21:40
Removedhttps://admin.moneyboxapp.org/URLIn Scope21:40
Removedhttps://admin-roundups.moneyboxapp.org/URLIn Scope21:40
Removedhttps://apps.apple.com/gb/app/moneybox-save-and-invest/id1049797239IOSIn Scope21:40
Removedhttps://play.google.com/store/apps/details?id=com.moneyboxappANDROIDIn Scope21:40
Removedhttps://sycamore.moneyboxapp.org/URLIn Scope21:40
Removedthe moneybox public website https://www.moneyboxapp.com/ and other moneyboxapp.com / moneyboxapp.org domains not listed are out of scopeOTHEROut of Scope21:40
Removedcontent served by the cloudflare access service (https://moneyboxapp.cloudflareaccess.com/*) is out of scope. these pages intentionally do not set a cors allow-origin policy. we have seen this reported several times as a vulnerability, but it is intended behaviour and is considered out of scopeOTHEROut of Scope21:40
Removedsecurity concerns originating from https://moneyboxapp.onelogin.com/ are typically considered out of scope. these pages and their content are served by onelogin, and any issues should be reported to them directly. however, if an exploit explicitly enables bypassing onelogin to access moneybox systems or leaking moneybox sensitive data, it is crucial to raise the concerns to both onelogin and moneyboxOTHEROut of Scope21:40
Addedcontent served by the cloudflare access service (https://moneyboxapp.cloudflareaccess.com/*) is out of scope. these pages intentionally do not set a cors allow-origin policy. we have seen this reported several times as a vulnerability, but it is intended behaviour and is considered out of scopeOTHEROut of Scope00:33
Addedsecurity concerns originating from https://moneyboxapp.onelogin.com/ are typically considered out of scope. these pages and their content are served by onelogin, and any issues should be reported to them directly. however, if an exploit explicitly enables bypassing onelogin to access moneybox systems or leaking moneybox sensitive data, it is crucial to raise the concerns to both onelogin and moneyboxOTHEROut of Scope00:33
Addedthe moneybox public website https://www.moneyboxapp.com/ and other moneyboxapp.com / moneyboxapp.org domains not listed are out of scopeOTHEROut of Scope00:33