tencent-bug-bounty-program

YesWeHackView on YesWeHack
RawAI Enhanced
1
In Scope
6
Out of Scope
In-Scope Assets (1)
AssetCategoryBountyQuick Links
In-Scope Products (for the full list please visit https://en.security.tencent.com/index.php/policy)OTHERYes-
Out-of-Scope Assets (6)
AssetCategoryBounty
*. myqcloud.comOTHERYes
*.qzoneapp.comOTHERYes
*Notes about Tencent Cloud (cloud.tencent.com as included in *.tencent.com)OTHERYes
Only vulnerabilities affecting the platform itself and IP owned by Tencent will be accepted. If an IP belongs to Tencent Cloud external customer, it is not considered in scope.OTHERYes
Please note that the vulnerabilities reported for the following assets will not be eligible for bounties.OTHERYes
Third-party applications and websitesOTHERYes
Scope Changes (27)
Feb 25, 2026
ChangeAssetCategoryScopeTime
Added*.qzoneapp.comWILDCARDOut of Scope19:09
Added*. myqcloud.comWILDCARDOut of Scope19:09
Addedthird-party applications and websitesOTHEROut of Scope19:09
Added*notes about tencent cloud (cloud.tencent.com as included in *.tencent.com)WILDCARDOut of Scope19:09
Addedonly vulnerabilities affecting the platform itself and ip owned by tencent will be accepted. if an ip belongs to tencent cloud external customer, it is not considered in scopeOTHEROut of Scope19:09
Addedin-scope products (for the full list please visit https://en.security.tencent.com/index.php/policy)OTHERIn Scope19:09
Addedplease note that the vulnerabilities reported for the following assets will not be eligible for bountiesOTHEROut of Scope19:09
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedplease note that the vulnerabilities reported for the following assets will not be eligible for bountiesOTHEROut of Scope00:52
Added*.qzoneapp.comWILDCARDOut of Scope00:52
Added*. myqcloud.comWILDCARDOut of Scope00:52
Addedthird-party applications and websitesOTHEROut of Scope00:52
Added*notes about tencent cloud (cloud.tencent.com as included in *.tencent.com)OTHEROut of Scope00:52
Addedonly vulnerabilities affecting the platform itself and ip owned by tencent will be accepted. if an ip belongs to tencent cloud external customer, it is not considered in scopeOTHEROut of Scope00:52
Addedin-scope products (for the full list please visit https://en.security.tencent.com/index.php/policy)OTHERIn Scope00:52
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removedin-scope products (for the full list please visit https://en.security.tencent.com/index.php/policy)OTHERIn Scope21:40
Removedplease note that the vulnerabilities reported for the following assets will not be eligible for bountiesOTHEROut of Scope21:40
Removed*.qzoneapp.comOTHEROut of Scope21:40
Removed*. myqcloud.comOTHEROut of Scope21:40
Removedthird-party applications and websitesOTHEROut of Scope21:40
Removed*notes about tencent cloud (cloud.tencent.com as included in *.tencent.com)OTHEROut of Scope21:40
Removedonly vulnerabilities affecting the platform itself and ip owned by tencent will be accepted. if an ip belongs to tencent cloud external customer, it is not considered in scopeOTHEROut of Scope21:40
Addedplease note that the vulnerabilities reported for the following assets will not be eligible for bountiesOTHEROut of Scope00:33
Added*.qzoneapp.comOTHEROut of Scope00:33
Added*. myqcloud.comOTHEROut of Scope00:33
Addedthird-party applications and websitesOTHEROut of Scope00:33
Added*notes about tencent cloud (cloud.tencent.com as included in *.tencent.com)OTHEROut of Scope00:33
Addedonly vulnerabilities affecting the platform itself and ip owned by tencent will be accepted. if an ip belongs to tencent cloud external customer, it is not considered in scopeOTHEROut of Scope00:33