Public Xero bug reports.

Team Bounty Title
Xero - Insecure Payment System Integration
Xero - Default.aspx exposing full path and other info on wip.origin-community.xero.com
Xero - stored xss issue in folder name on go.xero.com/Docs/Folders
Xero - Open-redirect on login.xero.com
Xero - Additonal stored XSS in Add note/Expected payment Date
Xero - Vulnerability : XSS Vulnerability