jtcsec has reached Level 4 with 75+ unique vulnerabilities discovered and they have proven to us that they understand web application vulnerabilities and how to discover them. If you run a bug bounty/vulnerability disclosure program and you are looking for an active, professional researcher, we recommend considering this user
 
  
    
        
        
        
     
    
     
    
        
        
        
        
     
    
     
    
        
        
        
        
     
    
        
     
    
        
     
    
        
        
        
        
        
        
        
    
    
              
        | Report Title | Event ID | Severity | Vulnerability Type | 
|---|---|---|---|
| Stored XSS via canceled appointment message | FirstBlood v1 | CRITICAL | Stored XSS | 
| Stored XSS via malicious appointment message leads to ATO | FirstBlood v1 | High | Stored XSS |