Main meniu
Main meniu
Main meniu

Bug Bounty disclosure program

Omnisend looks forward to working with the security community to find security vulnerabilities to keep our business and customers safe. If you believe you've found a security issue, we encourage you to notify us.

Program
rules

  • Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.

  • Submit one vulnerability per report unless you need to chain vulnerabilities to provide impact.

  • When duplicates occur or known vulnerabilities, we only award the first report received (provided that it can be fully reproduced).

  • Multiple vulnerabilities caused by the same underlying issue will be awarded one payout.

  • Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services.

  • Test vulnerabilities only on accounts you own or have explicit permission from the account holder.

  • Report Wordpress plugin vulnerabilities to Patchstack.

Scope

Web application

app.omnisend.com

Marketing site

omnisend.com

Wordpress plugins

profiles.wordpress.org/omnisend/#content-plugins

App Market

appmarket.omnisend.com

API endpoint

api.omnisend.com

Partner portal

partners.omnisend.com

Out-of-Scope vulnerabilities

When reporting vulnerabilities, please consider the attack scenario (exploitability) and the security impact of the bug. The following issues are considered out of scope:

Phishing

Social engineering

Any form of denial of service attack

Contact

Please contact us at

Get plan recommendation