Roblox Program Statistics
7 total issues disclosed
$6,800 total paid publicly
Most disclosed (2 disclosures) — Privilege Escalation
Disclosed Reports
| Report Title | Vulnerability Type | Disclosed By | Severity | Disclosed on |
|---|---|---|---|---|
| Malformed string sent through FireServer leads to server freezing/hanging | Denial of Service | albertl | Medium | 2020-04-30 |
| Insecure redirect rule results in bypassing ban redirect on certain pages | Insecure Direct Object Reference (IDOR) | jfc5sb | Medium | 2020-04-26 |
| Subdomain Takeover to Authentication bypass | None supplied | geekboy | Critical | 2020-04-23 |
| Reflected XSS through multiple inputs in the issue collector on Jira | Cross-site Scripting (XSS) - Reflected | jackb898 | Medium | 2020-03-24 |
| Subdomain Takeover at creatorforum.roblox.com | Privilege Escalation | jackb898 | High | 2020-03-24 |
| Subdomain Takeover at creatorforum.roblox.com | Privilege Escalation | jackb898 | High | 2020-03-24 |
| Reflected XSS through multiple inputs in the issue collector on Jira | Cross-site Scripting (XSS) - Reflected | jackb898 | Medium | 2020-03-24 |
Getting started
Learn about vulnerability types
Getting started in bug bounties
Test your knowledge
Free Web Application Challenges
Guides for your hunts
ZSeano's Methodology
Effective Note Taking for bug bounties
Useful Resources
Disclosed HackerOne Reports
Our community
Endorsed Members
Hackevents
Member Articles