Find a vulnerability on an in-scope site. Only the sites and categories below are eligible.
Every other Vultr domain and subdomain is out of scope.
This list is closed. If your finding is not on this list, it is out of scope. We decide which category your report falls into. We decide whether a misconfiguration is significant.
XSS and CSRF are out of scope.
Self-XSS is out of scope. A bug that only affects the user who triggers it is not a vulnerability.
An alert box is not a proof of concept. A missing token is not a vulnerability.
Submit it on our report form with everything below. Your report must contain both a proof of concept and an impact statement.
Once we close your ticket, the decision is final. We will not reopen it. Do not submit the same report again.
We will close your report if you send us AI output or tool output that you did not verify yourself.
Wait for our security team to assess it. We rate accepted reports with Bugcrowd's Vulnerability Rating Taxonomy (VRT). Only P4 to P1 issues are paid. We assign the rating.
| Rating | Payout |
|---|---|
| P4 | $50 - $300 |
| P3 | $300 - $500 |
| P2 | $500 - $1,000 |
| P1 | $1,000 - $10,000 |
Thank you for your contribution to Vultr's security!
A member of the engineering team will review it and contact you shortly.