Due to an increased volume of invalid reports, we are temporarily suspending our bug bounty program. All reports submitted prior to November 13, 2024, will be reviewed and compensated in accordance with the original agreement.
Please team for further information.
The program covers our corporate website www.cdn77.com and our customer portal client.cdn77.com.
The primary focus is on identifying and mitigating critical security vulnerabilities, such as:
Certain areas are out of scope. The testing of any vulnerabilities outside the defined scope is strictly prohibited and will result in disqualification from eligibility for legal safe harbor protections.
The following issues are out of scope and will not be considered as security vulnerabilities:
These are not eligible unless they directly lead to one of the vulnerabilities described in P1–P4.
This taxonomy defines report severity levels for impactful security vulnerabilities. Cosmetic, best-practice, or informational issues (e.g., missing headers, TLS configs, outdated libraries, etc.) are excluded and not eligible for reward unless they directly lead to exploitability.
Direct, full compromise of sensitive data, user accounts, or internal systems without user interaction.
$1,000 – $2,000
(depending on impact and exploitability)
High-impact issues requiring some user interaction or specific conditions; can access/mod user data or escalate privileges.
$800 – $1,000
Exploitable vulnerabilities with practical impact, but limited scope or conditions required.
$400 – $800
Low-impact issues with limited harm or no direct security consequence.
$100 – $400