Tucows (VDP) Program Statistics
6 total issues disclosed
$0 total paid publicly
Most disclosed (2 disclosures) — Business Logic Errors
Disclosed Reports
| Report Title | Vulnerability Type | Disclosed By | Severity | Disclosed on |
|---|---|---|---|---|
| Password Strength Policy Bypass via Server-Side Validation Flaw | Business Logic Errors | 2026 | Low | 2026-03-27 |
| Unauthenticated Access Control Bypass — Private WordPress Post Disclosure (Outdated WordPress 4.9.40) | Improper Authorization | 1prince1 | No rating | 2025-10-14 |
| Information Disclosure via Accessible debug.log on ExactHosting | Information Disclosure | 1prince1 | No rating | 2025-10-14 |
| CSRF allowing unauthorized modification of user Notes on ███████ | Cross-Site Request Forgery (CSRF) | kanon4 | Low | 2025-10-10 |
| Vulnerability: XML-RPC Interface Enabled and Accessible | Information Disclosure | emad2466 | No rating | 2025-10-10 |
| Business Logic Error – Bypass of OTP Verification During Signup on hover.com | Business Logic Errors | c0rvuz | None | 2025-09-02 |
Getting started
Learn about vulnerability types
Getting started in bug bounties
Test your knowledge
Free Web Application Challenges
Guides for your hunts
ZSeano's Methodology
Effective Note Taking for bug bounties
Useful Resources
Disclosed HackerOne Reports
Our community
Endorsed Members
Hackevents
Member Articles