Scams
Unpaid
Programs
haqq.ai
Self-Hosted
Stored Cross-User XSS in Delete Confirmation Modal And Broken Link Hijack | haqq.ai
Taking Reports As Joke
streamfluent.ai
Self-Hosted
Race Condition | streamfluent.ai
The company acknowledged and marked my report as valid. But till now they didn’t provided any response regarding the payout!
iproyal.com
Self-Hosted
Priv escalation | iproyal.com
Bug Bounty time travel
companyinfo.nl,fdmediagroep.nl,fdmg.nl
Self-Hosted
otp bypass | companyinfo.nl,fdmediagroep.nl,fdmg.nl
i reported otp bypass on fdmediagroep.nl and not a single reply from company {auotmated}
boldcommerce.com
Self-Hosted
BAC | boldcommerce.com
Approved Security Bounty Still Unpaid Months After Validation
projectbios.com
Self-Hosted
critical vulns | projectbios.com
i reported multiple bugs on projectbios now it dosnt exist haha
bevolkingsonderzoeknederland.nl
Self-Hosted
(NOT_Scam) text injection | bevolkingsonderzoeknederland.nl
i reported a text injection but email dosnt exist
westermo.com
Self-Hosted
reflected xss | westermo.com
reflected xss report ignored
alphanodus.com
Self-Hosted
html injection | alphanodus.com
html injection on signup page
wazoku.com
Self-Hosted
Sensitive Data Exposure | wazoku.com
Cancelled the decided reward amount after asked updates for proceed payment
gifty.nl
Self-Hosted
RCE | gifty.nl
Dependency Confusion Vulnerability
scantrust.com
Self-Hosted
Stored XSS | scantrust.com
Silent Fix,No Response
boat-lifestyle.com
Self-Hosted
Reflected XSS | boat-lifestyle.com
Responsible Disclosure – Reflected XSS Vulnerability in Search Input on boat-lifestyle.com
rfgstudios.com
Self-Hosted
IDOR | rfgstudios.com
Silent Fix | Bounty Denied
zoviz.com
Self-Hosted
Improper Access Control | zoviz.com
Premium Feature Bypass
www.proxsys.nl
Self-Hosted
Open Redirect | www.proxsys.nl
floatbot.ai
Self-Hosted
RCE | floatbot.ai
Reported a Remote code execution
signageos.io
Self-Hosted
logical bugs | signageos.io
no payout and this program reported by sevral researcher marked as scam
plumsail.com
Self-Hosted
logical bug | plumsail.com
Unauthenticated Webhook Subscription Deletion — Missing Authentication + Confirmed Data Destruction
zetrix.com
Self-Hosted
multiple bugs | zetrix.com
Reports Rejected, No Response
Yatra.com
Self-Hosted
multiple bugs | Yatra.com
Yatra Bug Ignored
conductor.com
Self-Hosted
BAC | conductor.com
no Response
punchzee.com
Self-Hosted
Logic | punchzee.com
no Response
float.com
Self-Hosted
Org Takover | float.com
no Response
increase.com
Self-Hosted
BAC | increase.com
Reject valid vulnerability
klikkit.no
Self-Hosted
idor|htmli|cors | klikkit.no
IDORs CORS Misconfiguration, HTML Injection, and 1 Year of Silence
wayfair.com
HackerOne
CSRF | wayfair.com
The program don’t accept any kind of csrf vulnerability and Their response time is very very bad.
cutshort.io
Self-Hosted
subdomain takeover | cutshort.io
subdomain takeover report ignored by company

REPORT A SCAM

All submissions reviewed before publishing.

Program

📸
Click or drag
Max 5MB

Incident

🖼
Multiple photos
Up to 10, 5MB each

Your Info

Contact never published.
Submitted! Will appear after review.

Get in Touch

Have a question, tip, or partnership inquiry? Reach out to us directly.

🐛
Report a Scam
Use the Submit tab to file a detailed report with evidence.
🛡
Security Issues
Found a vulnerability on our site? Email us directly.
🤝
Partnerships
Interested in collaborating? We'd love to hear from you.

⌕ Program Lookup

Check if a bug bounty program has scam reports

☠ Wall of Shame

Programs with the most scam reports from the community

◈ Scam Analytics

⧖ Track Report

Enter your tracking ID to check submission status

Blog

☆ Weekly Digest