Help us keep HPanel secure. Find vulnerabilities, report responsibly, and earn your place in our Hall of Fame.
What you can and cannot test
*:2053)*:2057)*:2059)/api/*)hpanel.net)How we classify reported vulnerabilities
RCE, Auth Bypass, SQL Injection, Privilege Escalation to Root
Stored XSS, IDOR, Account Takeover, API Key Leakage
CSRF, Information Disclosure, Session Fixation
Reflected XSS, Verbose Errors, Missing Rate Limiting
Submit your findings with a valid Proof of Concept
Follow these rules to participate responsibly
We consider security research conducted in accordance with this policy to be authorized, helpful, and protected. We will not pursue legal action against researchers who follow these rules.
Security researchers who helped make HPanel safer
Be the first to find a vulnerability and earn your spot here.
Help us improve HPanel security — report responsibly and get recognized.
security@hpanel.netSubject: [Bug Bounty] [Severity] — Brief Description