Vulnerability Disclosure Program
Help Us Stay Secure
We welcome security researchers to responsibly disclose vulnerabilities found on VulnHack. Your efforts help us build a safer platform for the cybersecurity community.
Submit a Report
In Scope
- vulnhack.com domain and all subdomains
- All public-facing web pages and API endpoints
- Authentication and authorization mechanisms
- Writeup submission, comments, and profile features
Out of Scope
- Denial of Service (DoS) attacks
- Social engineering or phishing
- Physical attacks or theft
- Third-party services or infrastructure
- Issues already reported or publicly known
- Automated vulnerability scanner output without proof of concept
Disclosure Process
1
Acknowledgment
We confirm receipt within 48 hours.
2
Investigation
We verify and assess the impact.
3
Remediation
We develop and deploy a fix.
4
Disclosure
We coordinate public disclosure with you.
Hall of Fame
No submissions yet. Be the first researcher to be featured here.
