Ad

Comp AI

Burpsuite — The most widely used web application security testing software

bug BugBounty Directory
Programs Blogs Get Featured
Programs Blogs Get Featured
Komoot

Komoot

Komoot is one of the most popular route-planning apps on the market and has many functions that are designed to make route planning an easier experience.

Web2Mobile

Bounty

Visit Komoot

low

$100

medium

$200

high

$500

critical

$5000

Komoot

Please visit the official website for the latest information.

Security vulnerability reward program

Komoot rewards the effort of security researchers who help us to make our platform more secure. We offer rewards for finding security vulnerabilities in our website, mobile applications and backend infrastructure.

Scope

  • Our website on komoot.com, account.komoot.com (and its language domains komoot.de/fr/it/etc.). This also includes subdomains like account.komoot.com, but not blog.komoot.com/de/fr/it/... or *tile.komoot.* or *thunderforest.komoot.* . Note that some integrations are run by 3rd parties so we might delegate your submission to our partners.
  • Our mobile apps including Android, iOS, Garmin and Samsung Watch.
  • Our oauth2 integration for 3rd parties.
  • Our backend APIs on *.komoot.net and *.komoot.de.
  • Our AWS infrastructure including access to AWS APIs with vulnerable permissions or network access to our VPCs.
  • Our DNS configuration.
  • Our email system.

low

$100

medium

$200

high

$500

critical

$5000

Ad

burpsuite

Burpsuite

Burp Suite is a web application security tool that allows users to test web applications for vulnerabilities. It is a very popular tool used by many bug bounty hunters.

Recommended Blogs

How I turned Self XSS to Stored via CSRF

How I turned Self XSS to Stored via CSRF

Abhishek

•

Nov 29, 2019

Don’t underestimates the Errors - They can provide good $$$ Bounty!

Don’t underestimates the Errors - They can provide good $$$ Bounty!

Aditya Sharma

•

Jun 7, 2019

$5K Misconfigured Reset password that leads to Account Takeover (No user Interaction ATO)

$5K Misconfigured Reset password that leads to Account Takeover (No user Interaction ATO)

Aditya Sharma

•

Aug 24, 2021

Browse

ProgramsBlogsGet Featured

Quick Links

About
mailxgithub

© 2025 Bug Bounty Directory. All rights reserved.

Made with 💖 on my PC

✨ Inspired by OpenAlternative