Coordinated Vulnerability Disclosure (CVD) Hall of Fame

Welcome to our hall of fame where all the great bug-bounty hunters and security researchers that disclosed a vulnerability are ranked. The bigger the vulnerability (on terms of impact for the constituent), the higher the ranking. All high-impact vulnerability will also be rewarded. So can you reach the first place and help us to secure our systems even further?

Want to disclose a vulnerability? Please read the Coordinated Vulnerability Disclosure procedure provided by the constituent and file a report by using this form.

Disclose a vulnerability

Hall of Fame

  1. Koen van Hove - SaaS e-mail Spoofing/Impersonation
  2. CondaSecurity.nl
  3. Michael Jones - Skype for Business Vulnerability Disclosure
  4. Mark Fijneman - Registration bypass, XSS and multiple IDOR's
  5. Khaled Selim - HTML email injection / Blind XSS in admin panel / Stored XSS / Open Redirection / Rate Limiting
  6. Theologos Kokkinellis - Multiple reflected XXS
  7. Constantin Mader - HTTP Request Smuggling - CL.TE variant + TomCat Manager Access
  8. Marcus Jansson - Broken Authentication / Information Disclosure
  9. Wouter de Vries - Multiple Open Redirects
  10. Alwin Warringa - SQL Injection
  11. Ahmad Asaad - Stored XXS
  12. Raunak Gupta - Stored XSS
  13. Niek Flipse (TheWhiteBoot) - Reflected XSS
  14. Shail Sandip Patel - Reflected XSS
  15. Harsh Maheta
  16. Hassan Jaleel (CEO Tricklesoft.com) - Information Disclosure
  17. Kent Apostol
  18. Vít Chramosta - Confidential Information Disclosure
  19. Dhruvi Pandya
  20. Devansh  Chauhan - Session verrification
  21. Takshal Patel - Information Disclosure
  22. Jiehao Zhang - Information Disclosure