Skip to main content

Scopes & Reward Grid

Understand better programs' scopes and rewards' grid to help you hunting

Updated over a week ago

Program Scopes

In a Bug Bounty program, a Scope is an asset that organisations want to be tested.

Scopes may include:

  • Web applications

  • Mobile applications (iOS and/or Android)

  • APIs

  • Desktop software

  • IoT devices

  • Firmware

  • IP addresses

  • Cloud infrastructure or third-party services

  • Etc.

πŸ’‘ This list is essential to know what you are allowed to test in the framework of this program.

These are the only assets eligible for a reward if a (valid) vulnerability is found.


Rewards

Rewards depend on 2 criteria:

  • Final CVSS score after company's assessment

  • Applicable reward grid for the vulnerable scope

⚠️ Reward grids are defined as the potential maximum reward per severity level.

For example:

If you were to find a valid vulnerability on a critical scope (e.g., https://yeswehack.com) you might be rewarded up to 15000€.

Did this answer your question?