otto-de-bug-bounty

YesWeHackView on YesWeHack
RawAI Enhanced
10
In Scope
17
Out of Scope
In-Scope Assets (10)
Out-of-Scope Assets (17)
AssetCategoryBounty
/apps-messenger (the chatbot in general is out of scope)OTHERYes
/trackingOTHERYes
All domains not listed In-ScopeOTHERYes
Out-Of-Scope are also other applications hosted under the www.otto.de domain but have a different path, that is not part of our core online shop itself (you will notice, since the design of the page is completely different)OTHERYes
Please let us know if you have any questions regarding the scope.OTHERYes
Those include but are not limited to (if unsure, contact us before executing the tests):OTHERYes
https://keycloak.apps.otto.deOTHERYes
https://www.otto.de/claraOTHERYes
https://www.otto.de/kundenchatOTHERYes
https://www.otto.de/newsroomOTHERYes
https://www.otto.de/reblogOTHERYes
https://www.otto.de/roombeezOTHERYes
https://www.otto.de/soulfullyOTHERYes
https://www.otto.de/twoforfashionOTHERYes
https://www.otto.de/updatedOTHERYes
https://www.otto.de/user/contactFormSubmitOTHERYes
https://www.otto.de/user/sendcallbackrequestOTHERYes
Scope Changes (98)
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedhttps://retail-api.otto.deURLIn Scope19:09
Addedhttps://www.otto.de/newsroomURLOut of Scope19:09
Addedhttps://www.otto.de/user/sendcallbackrequestURLOut of Scope19:09
Addedhttps://www.otto.de/user/contactFormSubmitURLOut of Scope19:09
Addedall domains not listed in-scopeOTHEROut of Scope19:09
Added/apps-messenger (the chatbot in general is out of scope)OTHEROut of Scope19:09
Addedplease let us know if you have any questions regarding the scopeOTHEROut of Scope19:09
Addedhttps://www.lascana.de/URLIn Scope19:09
Addedhttps://orbidder.otto.deURLIn Scope19:09
Addedhttps://keycloak.apps.otto.deURLOut of Scope19:09
Added/trackingOTHEROut of Scope19:09
Addedhttps://www.otto.deURLIn Scope19:09
Addedhttps://apps.apple.com/de/app/otto-shopping-m%C3%B6bel/id404844644IOSIn Scope19:09
Addedhttps://teleoptiprd.otto.deURLIn Scope19:09
Addedhttps://mmp.otto.deURLIn Scope19:09
Addedhttps://www.otto.de/reblogURLOut of Scope19:09
Addedhttps://www.otto.de/twoforfashionURLOut of Scope19:09
Addedhttps://www.otto.de/soulfullyURLOut of Scope19:09
Addedhttps://www.otto.de/updatedURLOut of Scope19:09
Addedhttps://www.otto.de/jobsURLIn Scope19:09
Addedhttps://play.google.com/store/apps/details?id=de.cellular.ottohybrid&hl=deANDROIDIn Scope19:09
Addedhttps://supplier-connect.otto.deURLIn Scope19:09
Addedout-of-scope are also other applications hosted under the www.otto.de domain but have a different path, that is not part of our core online shop itself (you will notice, since the design of the page is completely different)OTHEROut of Scope19:09
Addedthose include but are not limited to (if unsure, contact us before executing the tests):OTHEROut of Scope19:09
Addedhttps://www.otto.de/roombeezURLOut of Scope19:09
Addedhttps://www.otto.de/kundenchatURLOut of Scope19:09
Addedhttps://www.otto.de/claraURLOut of Scope19:09
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedhttps://teleoptiprd.otto.deURLIn Scope00:52
Added/apps-messenger (the chatbot in general is out of scope)OTHEROut of Scope00:52
Added/trackingOTHEROut of Scope00:52
Addedplease let us know if you have any questions regarding the scopeOTHEROut of Scope00:52
Addedhttps://www.otto.de/reblogURLOut of Scope00:52
Addedhttps://www.otto.deURLIn Scope00:52
Addedhttps://www.otto.de/updatedURLOut of Scope00:52
Addedhttps://www.otto.de/kundenchatURLOut of Scope00:52
Addedhttps://www.otto.de/claraURLOut of Scope00:52
Addedhttps://www.otto.de/roombeezURLOut of Scope00:52
Addedhttps://www.otto.de/user/contactFormSubmitURLOut of Scope00:52
Addedhttps://keycloak.apps.otto.deURLOut of Scope00:52
Addedall domains not listed in-scopeOTHEROut of Scope00:52
Addedhttps://retail-api.otto.deURLIn Scope00:52
Addedhttps://www.otto.de/jobsURLIn Scope00:52
Addedhttps://play.google.com/store/apps/details?id=de.cellular.ottohybrid&hl=deANDROIDIn Scope00:52
Addedhttps://apps.apple.com/de/app/otto-shopping-m%C3%B6bel/id404844644IOSIn Scope00:52
Addedhttps://www.lascana.de/URLIn Scope00:52
Addedhttps://www.otto.de/soulfullyURLOut of Scope00:52
Addedhttps://supplier-connect.otto.deURLIn Scope00:52
Addedhttps://mmp.otto.deURLIn Scope00:52
Addedhttps://www.otto.de/user/sendcallbackrequestURLOut of Scope00:52
Addedhttps://orbidder.otto.deURLIn Scope00:52
Addedout-of-scope are also other applications hosted under the www.otto.de domain but have a different path, that is not part of our core online shop itself (you will notice, since the design of the page is completely different)OTHEROut of Scope00:52
Addedthose include but are not limited to (if unsure, contact us before executing the tests):OTHEROut of Scope00:52
Addedhttps://www.otto.de/twoforfashionURLOut of Scope00:52
Addedhttps://www.otto.de/newsroomURLOut of Scope00:52
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removedhttps://teleoptiprd.otto.deURLIn Scope21:40
Removedhttps://www.otto.deURLIn Scope21:40
Removedhttps://www.otto.de/jobsURLIn Scope21:40
Removedhttps://play.google.com/store/apps/details?id=de.cellular.ottohybrid&hl=deANDROIDIn Scope21:40
Removedhttps://apps.apple.com/de/app/otto-shopping-m%C3%B6bel/id404844644IOSIn Scope21:40
Removedhttps://mmp.otto.deURLIn Scope21:40
Removedhttps://orbidder.otto.deURLIn Scope21:40
Removedhttps://supplier-connect.otto.deURLIn Scope21:40
Removedhttps://retail-api.otto.deURLIn Scope21:40
Removedout-of-scope are also other applications hosted under the www.otto.de domain but have a different path, that is not part of our core online shop itself (you will notice, since the design of the page is completely different)OTHEROut of Scope21:40
Removedthose include but are not limited to (if unsure, contact us before executing the tests):OTHEROut of Scope21:40
Removedhttps://www.otto.de/reblogOTHEROut of Scope21:40
Removedhttps://www.otto.de/roombeezOTHEROut of Scope21:40
Removedhttps://www.otto.de/twoforfashionOTHEROut of Scope21:40
Removedhttps://www.otto.de/soulfullyOTHEROut of Scope21:40
Removedhttps://www.otto.de/updatedOTHEROut of Scope21:40
Removedhttps://www.otto.de/newsroomOTHEROut of Scope21:40
Removedhttps://www.otto.de/kundenchatOTHEROut of Scope21:40
Removedhttps://www.otto.de/claraOTHEROut of Scope21:40
Removedhttps://www.otto.de/user/sendcallbackrequestOTHEROut of Scope21:40
Removedhttps://www.otto.de/user/contactFormSubmitOTHEROut of Scope21:40
Removedhttps://keycloak.apps.otto.deOTHEROut of Scope21:40
Removedall domains not listed in-scopeOTHEROut of Scope21:40
Removed/apps-messenger (the chatbot in general is out of scope)OTHEROut of Scope21:40
Removed/trackingOTHEROut of Scope21:40
Removedplease let us know if you have any questions regarding the scopeOTHEROut of Scope21:40
Removedhttps://www.lascana.de/URLIn Scope21:40
Addedthose include but are not limited to (if unsure, contact us before executing the tests):OTHEROut of Scope00:33
Addedhttps://www.otto.de/reblogOTHEROut of Scope00:33
Addedhttps://www.otto.de/roombeezOTHEROut of Scope00:33
Addedhttps://www.otto.de/twoforfashionOTHEROut of Scope00:33
Addedhttps://www.otto.de/soulfullyOTHEROut of Scope00:33
Addedhttps://www.otto.de/updatedOTHEROut of Scope00:33
Addedhttps://www.otto.de/newsroomOTHEROut of Scope00:33
Addedhttps://www.otto.de/kundenchatOTHEROut of Scope00:33
Addedhttps://www.otto.de/claraOTHEROut of Scope00:33
Addedhttps://www.otto.de/user/sendcallbackrequestOTHEROut of Scope00:33
Addedhttps://www.otto.de/user/contactFormSubmitOTHEROut of Scope00:33
Addedhttps://keycloak.apps.otto.deOTHEROut of Scope00:33
Addedall domains not listed in-scopeOTHEROut of Scope00:33
Added/apps-messenger (the chatbot in general is out of scope)OTHEROut of Scope00:33
Added/trackingOTHEROut of Scope00:33
Addedplease let us know if you have any questions regarding the scopeOTHEROut of Scope00:33
Addedout-of-scope are also other applications hosted under the www.otto.de domain but have a different path, that is not part of our core online shop itself (you will notice, since the design of the page is completely different)OTHEROut of Scope00:33