Pabbly · Vulnerability Disclosure
Pabbly Vulnerability Disclosure
Vulnerability disclosure
Pabbly runs a coordinated vulnerability disclosure program on Hackerone.
AutomationEmail MarketingSubscription BillingBillingPaymentsWebhookMessagingWhatsAppEmail VerificationFormsNo-CodeSoftware-as-a-Service
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-08-13'
method: searched
source: https://www.pabbly.com/security-vulnerability-disclosure/
provider: Pabbly
providerId: pabbly
program:
published: true
name: Pabbly Security Vulnerability Disclosure Program
url: https://www.pabbly.com/security-vulnerability-disclosure/
mirror: https://buy.pabbly.com/security-vulnerability-disclosure/
type: responsible-disclosure
platform: self-hosted
bug_bounty_platform: null
note: >-
Not on HackerOne, Bugcrowd or Intigriti — Pabbly runs the program itself and
takes reports through its own form.
reporting:
form: https://forms.pabbly.com/form/share/DPHw-722603307
email_published: true
email_obfuscated: true
email_note: >-
A reporting address is published on the page but is Cloudflare
email-obfuscated in the markup, so it is not recorded verbatim here.
security_txt: false
security_txt_note: >-
/.well-known/security.txt returned 404 on every Pabbly host — the program
exists but is not machine-discoverable (see well-known/pabbly-well-known.yml).
scope:
in_scope:
- Pabbly web applications and services
out_of_scope:
- https://pabbly.hellonext.co
- https://forum.pabbly.com
qualifying:
- authentication flaws
- cross-site scripting (XSS)
- server-side code execution
- CORS / CSRF issues
non_qualifying:
- cookie flag issues
- SPF / DKIM / DMARC configuration reports
- denial-of-service attacks
safe_harbor:
published: true
language: >-
"Do not cause any harm, hinder application fluency or act against our Terms
of Use Agreement." Researchers must not access non-public data beyond what is
needed to demonstrate the issue and must follow responsible disclosure.
response_commitment:
acknowledgement: >-
"We answer all submissions within a few days."
fix_timeline: >-
"Timelines for fixes will vary with the severity of the vulnerability and
availability of engineering resources to address it."
rewards:
offered: true
discretionary: true
maximum: 50
currency: USD
criteria:
- severity
- impact
- originality
payout_method: PayPal, after the fix ships, minus processing fees
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/pabbly-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.