Adore Me · Vulnerability Disclosure
Adore Me Vulnerability Disclosure
Vulnerability disclosure
Adore Me runs a coordinated vulnerability disclosure program on Bugcrowd.
CompanyE-CommerceRetailApparelIntimate ApparelDirect to ConsumerFashionConsumerSubscription CommerceMobile
Program: Bugcrowd
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-09-07'
method: searched
source: https://bugcrowd.com/adoreme-vdp
program:
name: Adore Me Vulnerability Disclosure Program
platform: Bugcrowd
type: vulnerability-disclosure
tier: VDP Pro
url: https://bugcrowd.com/adoreme-vdp
managed: true
rewards: false
note: >-
A Bugcrowd-managed Vulnerability Disclosure Program (not a paid bug bounty). Bugcrowd
describes the engagement as using the Bugcrowd Vulnerability Rating Taxonomy for
initial prioritization, with a documented appeal path when a submission is downgraded,
and Bugcrowd's standard disclosure terms. The program is discoverable from a "Report a
vulnerability" link in the adoreme.com site footer.
discovery:
- surface: adoreme.com footer
link_text: Report a vulnerability
target: https://bugcrowd.com/adoreme-vdp
security_txt:
published: false
probed:
- url: https://www.adoreme.com/.well-known/security.txt
status: 404
- url: https://adoreme.com/.well-known/security.txt
status: 404
note: >-
Adore Me runs a real disclosure program but does not advertise it in an RFC 9116
security.txt at either the apex or www host. A researcher who follows the standard
discovery path finds nothing; the program is only reachable by reading the rendered
site footer. Publishing a /.well-known/security.txt with a Policy: line pointing at
https://bugcrowd.com/adoreme-vdp would close that gap with a single static file, and
is the single cheapest security-surface improvement available to this company.
no_securitytxt_pointer: >-
No `SecurityTxt` pointer is wired in apis.yml, because no security.txt is served.
A `Security` pointer IS wired, pointing at the Bugcrowd program, which is real.
safe_harbor:
stated: unknown
note: >-
The Bugcrowd brief page renders its scope, safe-harbor and reward terms client-side
and gates the full brief behind a researcher login, so the safe-harbor language could
not be read anonymously and is not asserted here.
scope:
targets: unknown
note: >-
In-scope targets are published inside the Bugcrowd brief, which is not readable
without a Bugcrowd account. Not recorded rather than guessed.
x-evidence:
- url: https://bugcrowd.com/adoreme-vdp
http_status: 200
fetched: '2026-09-07'
- url: https://www.adoreme.com/.well-known/security.txt
http_status: 404
fetched: '2026-09-07'
- url: https://www.adoreme.com/
http_status: 200
fetched: '2026-09-07'
note: Footer carries the "Report a vulnerability" link to the Bugcrowd program.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/adore-me-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.