Bug Bounty Program

We value a complete report with full technical details. We must be able to reproduce the vulnerability and clearly demonstrate that it both exists and represents a weakness in our systems.

While we appreciate all types of reports, there needs to be at least one of the following in order to receive a reward:

1. A demonstrable data leak of our data or our customer data which is expected to not be publicly accessible
2. Sufficient evidence that the weakness can be exploited to sufficiently detrimental effect to cause obvious problems with our systems. (Example: unprivileged erasure of data)

If you find a leak in software created by third party vendors like WHMCS or Plesk, we’ll expect you to responsibly report it to the creator of that software as described under the heading Exclusions / Exceptions below. However, if you can prove the vulnerability is a result of a customization or configuration that is separate to the core software package, then we will investigate.

Important Note: due to the volume of frivolous bug reports generated by AI, any such reports will get no response from our staff unless they abide by the requirements on this page.

Testing Requirements:

Ensure that any vulnerability scanners are rate-limited. Please ensure to provide complete steps to reproduce and details on why you believe it to be a vulnerability.

Please do not submit lazy reports, like “your server says it uses this library which is old!” as many libraries either receive backports while keeping their older version number OR have no known vulnerabilities. You must successfully reproduce an attack on that library that satisfies the requirements described on this page for your report to be accepted.

Possible Awards:

Kudos is always guaranteed. Monetary rewards range from $5 to $5,000 CAD depending on the type and severity of the vulnerability being reported. To reach a higher amount, the vulnerability would need to be a significant leak of sensitive data or provide deep access to important systems.

Rewards can be paid out only via PayPal.

Exclusions / Exceptions

  • Plesk: If you have found a bug in Plesk Control Panel that can only be repaired by modifying the code, and not a web server configuration, you will need to submit it to the Plesk security team at security [@] plesk.com
  • WHMCS: If you have found a bug in the software at clients.websavers.ca that can only be repaired by modifying the code, and not a web server configuration, you will need to submit it to the WHMCS bug bounty program described here: https://www.whmcs.com/security-bounty-program/
  • Known issues or previously reported vulnerabilities
  • Security vulnerabilities in an underlying, yet supported, operating system that do not yet have a known patch
  • Something you consider a security risk, but which the software developer does not (examples: user enumeration in WordPress, having XML-API available).
  • Nearly anything to do with DNS records. No amount of missing DNS records will constitute a data leak. Similarly, we do not have any private or internal DNS records.

Examples of these exclusions in practice:

  • Simply allowing access to xml-rpc in WordPress is not a vulnerability unless you can prove that you can access truly private data using it, or that our firewalls are not effectively blocking bruteforce or DoS attacks against it at a level that would be necessary to actually crack it.
  • Usernames in WordPress are not considered private data as they are visible on post pages throughout the site – see the WordPress.org clear stance on this.

How to submit for a bounty

You may submit bug reports through OpenBugBounty.org or by email to bugs at websavers dot ca.