REWARDS

Our rewards are based on the severity of a vulnerability. We use CVSS 3.1 (Common Vulnerability Scoring Standard) to calculate severity.

We may pay more for unique, hard-to-find bugs, or for high-quality reports; we may also pay less for bugs with complex prerequisites that lower the risk of exploitation.

Please note, however, that reward decisions are up to the discretion of Xsolla. Issues may receive a lower severity due to the presence of compensating controls and context.

The amounts shown in the table should be considered the MAXIMUM amounts for each severity level, though bonuses may be given at Xsolla’s discretion.

SeverityAmount (in USD)
Critical$1,000 - $2,000
High$800
Medium$500
Low$100

When duplicates occur, we award the first report that we can completely reproduce.

Multiple vulnerabilities stemming from a single underlying issue are eligible for only one bounty, which will be granted to the first report that reveals the issue. Bounties are awarded upon validation. Although sometimes it can take more time to investigate the vulnerability severity and the bounty may be paid later.

Test only with your own account(s) when investigating bugs, and do not interact with other accounts, or engage in actions that may harm other users or violate their privacy. All rules must be followed to be eligible for rewards.

CONTACT US
REPORT SUBMISSION

By submitting a bug report, you agree to comply with the Xsolla Bounty Program Policy, which prohibits both public and private disclosure of any vulnerability or bug details related to Xsolla.

By participating in this program, you agree to adhere to the above rules and conditions. All rules must be followed to be eligible for rewards.

Please make sure to use this User-Agent string for testing:xsolla-bugbounty-%your-email-before@%Learn more...
Average response time : 48 hours for tickets