
Ian Dunn
External Program
Submit bugs directly to this organization
I'm a developer, so I'm mostly interested in source code bugs, rather than network intrusions. Reports must meet these criteria to be accepted:
Scope Exclusions section.Reports that don't meet those criteria will be marked as Not Applicable.
There are more targets listed in the In Scope section below.
| Severity | Award |
|---|---|
| High | $100 - $400 |
| Medium | $25-50 |
| Low | $0 |
Severity is based on CVSS 3, but may be adjusted up or down at my discretion. For example, a vulnerability in a plugin with 10,000 active installations may be higher than a vulnerability in a plugin with 100 active installations.
Informative. For example, CEMI attacks using standard trigger characters (like #151516) are welcome, but characters that only work in Excel, or only in old versions of software, etc are not accepted (see #124223).Invalid reports will be disclosed in order to help other researchers and programs learn from them.