This is the official vulnerability disclosure program for Contest Gallery. If you're a security researcher and believe that you have found a security vulnerability within our software, please send us details through the "report" form on this page. Please include as detailed information as possible, so we could verify the issue and get back to you as soon as possible with either additional questions or with a potential fix. All valid security vulnerabilities will receive a CVE and may also earn you rewards from Patchstack Alliance bug bounty program.
Members of the Bug Bounty program receive XP for their reports and are eligible for monthly cash rewards.
$2,000 Top ranking contributor
$1,400 Contributor ranking 2nd
$800 Contributor ranking 3rd
$600 Contributor ranking 4th
$500 Contributor ranking 5th
$400 Contributors ranking 6th to 10th
$200 Contributors ranking 11th to 15th
$100 Contributors ranking 16th to 19th
$50 Contributor ranking 20th
$50 One lucky pick
No active bounties by the developer
We would like to thank everyone who submits valid reports that help us improve the security of Contest Gallery. However, only those that meet the following eligibility requirements may receive a monetary reward for vulnerabilities found in the Contest Gallery source code.
You must be the first reporter of a vulnerability.
The vulnerability must be a qualifying vulnerability (see below).
Any vulnerability found must be reported no later than 24 hours after discovery and exclusively through patchstack.com.
You must avoid tests that could cause degradation or interruption of our service (refrain from using automated tools, and limit your requests per second). If you over do it, your IP address might be throttled or even (temporarily) blocked to protect our infrastructure. See how.
Reports on vulnerabilities are examined by our security analysts - our analysis is always based on worst case exploitation & the business criticality of the vulnerability, as is the reward we pay.
SQL Injection
Cross Site Scripting (XSS)
Remote/Local File Inclusion
Cross-Site Request Forgery (CSRF)
Open Redirection
Bypass Vulnerability
Broken Access Control
Privilege Escalation
Arbitrary File Read/Download/Upload/Deletion
Sensitive Data Exposure
Arbitrary/Remote Code Execution
Server Side Request Forgery (SSRF)
Denial of Service
PHP Object Injection
Deserialization of untrusted data
Insecure Direct Object References (IDOR)
CSV Injection
Broken Authentication
Path Traversal
Race Condition
Cross-Site Request Forgery (CSRF) on read-only actions
Pre-requisite of another vulnerability
Pre-requisite of specific or unusual conditions
Vulnerabilities that requires exotic server configurations or outdated server software
Missing encryption/hashing on potential sensitive information
Spoofing of data (User Agent, IP address, etc.) with no serious security impact
Members of the Patchstack Bug Bounty program are ellegible for monthly cash rewards.
 Top contributor
                            $2,000
                            Top contributor
                            $2,000
                         2nd contributor
                            $1,400
                            2nd contributor
                            $1,400
                         3rd contributor
                            $800
                            3rd contributor
                            $800
                         Monthly contributor ranking 4th receive
                                Monthly contributor ranking 4th receive
                             Monthly contributor ranking 5th receive
                                Monthly contributor ranking 5th receive
                             Contributors ranking 6th to 10th
                                Contributors ranking 6th to 10th
                             Contributors ranking 11th to 15th
                                Contributors ranking 11th to 15th
                             Contributors ranking 16th to 19th
                                Contributors ranking 16th to 19th
                             Contributor ranking 20th
                                Contributor ranking 20th
                             One lucky researcher receives*
                                One lucky researcher receives*
                            Additional bounties can be paid out to Patchstack Bug Bounty members for findings that are beneficial to the community, particularly interesting or hard to find. Please read our full guidelines and terms before reporting.
 Emili Castells
                                                        Emili Castells
                        
                                                                                
                                                             Dimas Maulana
                                                        Dimas Maulana
                        
                                                                                
                                                             Joshua Chan
                        
                                                                                
                                                        LVT-tholv2k
                                                        Joshua Chan
                        
                                                                                
                                                        LVT-tholv2k
                        
                                                                                
                                                             Dhabaleshwar Das
                        
                                                                                
                                                        CatFather
                                                        Dhabaleshwar Das
                        
                                                                                
                                                        CatFather
                        
                                                                                                                    
                                                             Trương Hữu Phúc (truonghuuphuc)
                        
                                                                                
                                                        Poystick
                        
                                                                                
                                                        D01EXPLOIT
                                                        Trương Hữu Phúc (truonghuuphuc)
                        
                                                                                
                                                        Poystick
                        
                                                                                
                                                        D01EXPLOIT