Live program
DEFENZ — defenz.org platform bug bounty
DEFENZ — Bug bounty de la plateforme defenz.org
Run by the DEFENZ team against its own platform: public site, researcher and company workspaces, API and the listed subdomains. Report what you see — we pay what matters.
- Reports
- 2
- 1st response
- —
- Assets
- 2
- Updated
- Oct 5, 2026
Rewards
| Severity | Rewards |
|---|---|
| P1Critical | Up to 5,000 $ |
| P2High | Up to 2,000 $ |
| P3Medium | Up to 500 $ |
| P4Low | Up to 100 $ |
| P5Informational | — |
Escrow: 750 $
In scope
| Scope | Type | Value |
|---|---|---|
| defenz.org | Web application | High |
| www.defenz.org | Web application | High |
Out of scope
- SPF/DKIM/DMARC alone
- Self-XSS
- Missing security headers without impact
- Rate limiting without abuse scenario
- Denial of service
Vulnerability types
Qualifying
- SQLi (CWE-89)
- XSS (CWE-79)
- IDOR (CWE-639)
- SSRF (CWE-918)
- RCE
- Auth bypass (CWE-287)
- Privilege escalation
- PII leak
Non-qualifying
- Missing headers alone
- Self-XSS
- Clickjacking without impact
- Known CVE without PoC
- DoS/DDoS
- User enumeration
- SPF/DKIM/DMARC
- Outdated libraries
Safe harbor
Good-faith research against the listed assets only. No legal action will be taken for reports within this scope, without service degradation or personal-data exfiltration. Coordinated disclosure (90 days, Law No 2010/012).
I agree to test only the authorized scope. No scope = no test.