Public
YouPorn
bug reports.
4,419
Bug Reports -
$2,030,173
Paid Out
Last Updated:
12th September, 2017
Team
Bounty
Title
YouPorn
-
I am because bug
YouPorn
$250
DOM-based XSS on youporn.com (main page)
YouPorn
$100
XSS via login cookie
YouPorn
-
[Android API] SQL injection ( errortoken.json )
YouPorn
$250
Reflected XSS in Meta Tag
YouPorn
$2,500
Time Based SQL-inject in post-parametr login[username] [domain - youporn.com]
YouPorn
$150
Find whether a video has been favourited or not, for any user [via YouPorn Mobile API]
YouPorn
$1,000
Account hijack via deleted PH account
YouPorn
$1,000
IDOR - Access to private video thumbnails even if video requires password authentication
YouPorn
$1,000
Account takeover via Pornhub Oauth