vulns.co
/
GKData.io MCP

Back to Platforms

Bugcrowd

Broad crowdsourced platform with a well-defined severity taxonomy and researcher-matching to private programs.

Tags: public, vrt, crowdmatch

Program model
Bounty · VDP · Pentest · ASM
Regions
Global
Payout
USD; rewards mapped to the VRT severity of the finding

Specialties: web, api, mobile, iot

How to approach it

The Vulnerability Rating Taxonomy (VRT) tells you upfront how a bug class is rated - learn it to predict payouts and avoid arguing severity.

What the platform publishes

Bugcrowd's disclosure docs say coordinated disclosure is the recommended default for new public programs, and nondisclosure is the default for On-Demand and Pen Test MAX. If a program brief disagrees with the standard terms, the brief wins. Full safe harbor is for programs that meet the disclose.io requirements Bugcrowd lists. A program that does not meet them is marked partial. Severity labels on Bugcrowd come from the Vulnerability Rating Taxonomy, which is a priority scale, not a CVSS score.

Read the policy

  • Study the public VRT (bugcrowd.com/vulnerability-rating-taxonomy) before submitting - it sets expectations.
  • Points and quality feed CrowdMatch, which drives private-program invites.
  • Bugcrowd runs many managed enterprise programs; polished, on-scope reports get accepted fastest.

Official links