Security Bounty Program
Security researchers play an important part in helping keep our product secure. Our security bounty program is our way to reward security researchers for finding and reporting security vulnerabilities to us.
Participation: The WHMCS security bounty program is managed through private, invite-only HackerOne program. Please use the contacts listed in the security.txt to send reports. If your report is valid, you will be invited to the private program.
How do I participate?
The WHMCS Security Bounty Program is managed through private invite-only HackerOne program. Please use the contacts listed in the security.txt to send reports.
If you have identified a vulnerability, you must report it responsibly via our bounty program to be eligible for a reward. Not every report may qualify for a reward.
How much do you pay for the discovery of security vulnerabilities?
Rewards range from $100.00 to $2,000.00 depending on the type and severity of the vulnerability being reported.
Payments are made via our private HackerOne program only, to which you will be invited if your report is valid.
What qualifies as a vulnerability?
Any design or implementation issue within the WHMCS software that substantially affects the confidentiality or integrity of user data or the system.
Examples include:
- Cross-site scripting.
- Cross-site request forgery.
- Privilege escalation.
- Authentication or authorization flaws.
- Information disclosure.
The detailed scope will be sent to you by email upon request.
What is out of scope?
- Known issues or previously reported vulnerabilities.
- Security vulnerabilities in third-party applications that integrate with WHMCS.
- Security vulnerabilities in the underlying operating system.
- All the issues listed in Core Ineligible Findings.
Note: Vulnerability reports regarding “third-party” applications are communicated to the relevant party. WHMCS works with these parties to coordinate a fix wherever possible.
Acknowledgements
We would like to thank the following individuals, researchers, and firms who have helped make WHMCS better through responsible disclosure.
