Superhuman (formerly Grammarly) Program Statistics
6 total issues disclosed
$250 total paid publicly
Most disclosed (2 disclosures) — Violation of Secure Design Principles
Disclosed Reports
| Report Title | Vulnerability Type | Disclosed By | Severity | Disclosed on |
|---|---|---|---|---|
| Can register any mobile number in MFA without current code. | Improper Access Control - Generic | chackmate | Low | 2019-08-15 |
| DOM based CSS Injection on grammarly.com | Cross-site Scripting (XSS) - DOM | gamer7112 | Low | 2019-05-06 |
| Reflected Cross Site Scripting (XSS) | Cross-site Scripting (XSS) - Reflected | sarmadkhan | Medium | 2019-04-30 |
| Emails from Grammarly missing sanitization(lack of validation?) -> HTML injection in emails | Violation of Secure Design Principles | metnew | Low | 2019-04-30 |
| "More on Wikipedia" link disclose "Referrer" and leak `window.opener` reference for arbitrary websites | Violation of Secure Design Principles | metnew | Low | 2019-04-30 |
| `open-url` command allows opening unlimited number of tabs pointing to arbitrary URLs | None supplied | metnew | Medium | 2019-04-23 |
Getting started
Learn about vulnerability types
Getting started in bug bounties
Test your knowledge
Free Web Application Challenges
Guides for your hunts
ZSeano's Methodology
Effective Note Taking for bug bounties
Useful Resources
Disclosed HackerOne Reports
Our community
Endorsed Members
Hackevents
Member Articles