Public Respondly bug reports.

Team Bounty Title
Respondly - XSS in the input
Respondly - OAuth Bug
Respondly - Full Path Disclosure
Respondly - No Bruteforce Protection
Respondly - Deleting team members
Respondly - Allowed method disclosure
Respondly - X-Content-Type-Options header missing
Respondly - XSS via Email Link
Respondly - HTTP Strict transport security policy not enabled
Respondly - DNS Misconfiguration
Respondly - x-frame options-sameorigin warning
Respondly - Clickjacking - changing role
Respondly - XSS via Email
Respondly - Find, private notes Cross-site scripting.
Respondly - Import emails from Gmail are activate XSS
Respondly - OAuth open redirect
Respondly - Persistent Cross-site scripting vulnerability settings.