Vulnerability Disclosure Program

Help Us Stay Secure

We welcome security researchers to responsibly disclose vulnerabilities found on VulnHack. Your efforts help us build a safer platform for the cybersecurity community.

Submit a Report

In Scope

  • vulnhack.com domain and all subdomains
  • All public-facing web pages and API endpoints
  • Authentication and authorization mechanisms
  • Writeup submission, comments, and profile features

Out of Scope

  • Denial of Service (DoS) attacks
  • Social engineering or phishing
  • Physical attacks or theft
  • Third-party services or infrastructure
  • Issues already reported or publicly known
  • Automated vulnerability scanner output without proof of concept

Disclosure Process

1

Acknowledgment

We confirm receipt within 48 hours.

2

Investigation

We verify and assess the impact.

3

Remediation

We develop and deploy a fix.

4

Disclosure

We coordinate public disclosure with you.

Hall of Fame

No submissions yet. Be the first researcher to be featured here.