2 Critical · oldest 4d · SLA 5d.
| # | Title | Severity | State | Age | Owner | Suggested |
|---|---|---|---|---|---|---|
| 487 | SSRF via webhook URL validatorapp.example.com · 2 attachments · @lyra-h | Critical 9.4 | New | 4d | unassigned | $8,000 |
| 486 | Stored XSS in profile bio rendererapp.example.com · 1 attachment · @vinh-d | High 7.8 | New | 3d | PSPriya | $2,500 |
| 485 | IDOR on /api/v2/teams/:id/invitesapi.example.com · @ksenia-r | Medium 5.3 | New | 2d | MRMarc | $1,200 |
| 484 | Open redirect via auth callback paramapp.example.com · @arvi-7 | Low 3.1 | New | 2d | unassigned | $400 |
| 483 | Account enumeration via password-reset timingapp.example.com · @nikolaj-q | Medium 4.7 | New | 1d | unassigned | $900 |
| 482 | Subdomain takeover on legacy.acme.commarketing · @lyra-h | High 7.2 | New | 18h | unassigned | $2,500 |
| 481 | CSRF on team-billing email changeapp.example.com · @maru-9 | Low 3.6 | New | 6h | unassigned | $500 |
Validation locks the severity score and starts the payout decision SLA. The researcher receives an automated update with the decision.
Rejection closes the report without payout. The researcher receives the reason you write below. This can be reopened within 30 days.
Archived reports move out of the active queue. They stay searchable from the audit log and the disclosure log. The original researchers keep their credit.
This queues a $8,000 payout to @lyra-h. Funds debit from the Q2 program budget. The researcher gets an emailed receipt and a status update.
Generates a CSV with the current filters applied. Internal notes and attachments are not included.
Use this for in-person disclosures, third-party reports, or internal findings that need to enter the triage queue. The researcher will not be emailed automatically.