{"id":"3873b40e-2e15-4d7e-9134-6655143961ce","engagementId":"f27efbfb-c9ac-4c75-a09f-2418aa9106bb","data":{"brief":{"id":"ff04ae48-8dfb-4188-9b5f-177e4be6d1cf","name":"Pexels","tagline":"The best free stock photos, royalty free images \u0026 videos shared by creators. Help us secure Pexels, we are part of the Canva family!","description":"\u003ch1\u003eGuidelines\u003c/h1\u003e\n\n\u003cp\u003e\u003cstrong\u003eWe require that all researchers:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eMake a every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction of data during security testing\u003c/li\u003e\n\u003cli\u003ePerform research only within the scope set out below\u003c/li\u003e\n\u003cli\u003eUse the identified communication channels to report vulnerability information to us\u003c/li\u003e\n\u003cli\u003eUse your @bugcrowdninja email when testing\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThank you for participating, it is your work that will help to keep us secure.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as In-Scope. \u003cem\u003eAny domain/property of Canva not listed in the targets section is out of scope. This includes any/all subdomains not listed above.\u003c/em\u003e If you believe you've identified a vulnerability on a system outside the scope, please reach out to support@bugcrowd.com before submitting. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eCredentials\u003c/h3\u003e\n\n\u003cp\u003ePlease sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://researcherdocs.bugcrowd.com/v2.0/docs/your-bugcrowdninja-email-address\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cp\u003eThe Canva team is currently only paying rewards for vulnerabilities P3 and higher. The Canva team is particularly concerned with the impact that can be demonstrated from a given vulnerability - for example they are less interested in seeing XSS generated alert boxes and more interested in understanding how the attack can be used to steal cookies/session/etc.\u003c/p\u003e\n\n\u003cp\u003eDemonstrating the vulnerabilities impact will help ensure the severity of the issue is clear and demonstrating the full impact of the bug will influence its payout.\u003c/p\u003e\n\n\u003ch3\u003eOut of scope\u003c/h3\u003e\n\n\u003cp\u003eThe use of noisy automated tools are out of scope for this engagement. Please keep requests limited to one request per second.\u003c/p\u003e\n\n\u003cp\u003eWe will not accept rate limiting bypass submissions, except where you are able to bypass OTP controls.\u003c/p\u003e\n\n\u003ch3\u003e3rd party providers\u003c/h3\u003e\n\n\u003cp\u003eThis is within reason. If you discover issues with our AWS or Cloudflare setup, we're going to want to know! But \u003cem\u003emeh\u003c/em\u003e for generic vulnerability reports for third party providers such as:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ehttps://pagely.com/\u003c/li\u003e\n\u003cli\u003ehttps://zendesk.com/\u003c/li\u003e\n\u003cli\u003ehttp://mandrillapp.com\u003c/li\u003e\n\u003cli\u003eThird-party add-ons\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eUnsafe testing\u003c/h3\u003e\n\n\u003cp\u003eIn the interest of the safety of our users, staff, the Internet at large, you must ensure that our users are in no way impacted by your testing. Please ensure you're testing using your own accounts, and do not access user data that you do not own in any way. The following are excluded from scope, and not eligible for a reward:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eIf you discover user or employee credentials, cookies, or API keys (e.g. through dorking or otherwise), please do not attempt to verify them. We will validate credentials and evaluate impact\u003c/li\u003e\n\u003cli\u003ePhysical security tests\u003c/li\u003e\n\u003cli\u003eRubber hose cryptanalysis\u003c/li\u003e\n\u003cli\u003eDoS / DDoS\u003c/li\u003e\n\u003cli\u003ePhishing\u003c/li\u003e\n\u003cli\u003eMalicious software/extensions\u003c/li\u003e\n\u003cli\u003eDisclosure of non-sensitive information, such as product/framework version\u003c/li\u003e\n\u003cli\u003eID enumeration (such as user, design, folder, etc) without any further impact\u003c/li\u003e\n\u003cli\u003eDisclosure of users information that is publicly available\u003c/li\u003e\n\u003cli\u003eInsecure cookie settings for non-sensitive cookies\u003c/li\u003e\n\u003cli\u003eFindings from applications or systems not listed in the ‘Targets’ section\u003c/li\u003e\n\u003cli\u003eFunctional, UI and UX bugs and spelling mistakes\u003c/li\u003e\n\u003cli\u003eReports based on product/protocol version without a proof of concept of exploiting the vulnerability\u003c/li\u003e\n\u003cli\u003eIssues only affecting browsers that Canva does not support, docs located \u003ca href=\"https://support.canva.com/uncategorized/supported-browsers/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eMethods to bypass review of uploaded content. The review is not a security control, but an anti-abuse measure.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eWe are specifically not paying for issues that have been identified by internal testing.\u003c/h3\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"d6f47133-2496-4b91-980d-5403aeda9da5","name":"In Scope Targets","targets":[{"id":"c29d81cc-505a-4907-8c92-0c734ab491a5","uri":"https://www.pexels.com/","name":"*.pexels.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"fd54fc52-5901-4577-829c-5dc314a97280","sortOrder":0},"sortOrder":0,"tags":[{"id":"dd477d24-b394-460d-aaf7-9bd213555968","name":"Ruby","targetId":"c29d81cc-505a-4907-8c92-0c734ab491a5"},{"id":"4e9d5c53-3b04-4bca-ba30-e8e33d87019a","name":"Ruby on Rails","targetId":"c29d81cc-505a-4907-8c92-0c734ab491a5"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"c29d81cc-505a-4907-8c92-0c734ab491a5"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"a0fabdd2-6310-4dd0-aa35-114029d957fa","p1MaxCents":600000,"p1MinCents":600000,"p2MaxCents":250000,"p2MinCents":250000,"p3MaxCents":85000,"p3MinCents":85000,"p4MaxCents":10000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":6000,"max":6000},"2":{"min":2500,"max":2500},"3":{"min":850,"max":850},"4":{"min":100,"max":100},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"f27efbfb-c9ac-4c75-a09f-2418aa9106bb","code":"pexels","state":"in_progress","endsAt":null,"bountyId":"20372fcb-ec16-4a08-a13e-b2fff4d628d7","startsAt":"2020-12-22T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/engagement_brief_logos/engagement_brief/logo/ff04ae48-8dfb-4188-9b5f-177e4be6d1cf/4ec7c39f-1085-4f52-8b46-b27115650ec6.png","logoBackgroundColor":"#FFFFFF","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2020-12-22T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/pexels","changelogs":"/engagements/pexels/changelog","submissions":null,"announcements":"/engagements/pexels/announcements","hallOfFame":"/engagements/pexels/hall_of_fames","crowdstream":null},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/pexels/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=pexels\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/pexels/engagement_subscribers","engagementChangelogsUrl":"/engagements/pexels/changelog","publishedAt":"2026-09-09T04:06:43.452Z","engagementChangelogUrl":"/engagements/pexels/changelog/3873b40e-2e15-4d7e-9134-6655143961ce","createUserFeedbacksUrl":"/engagements/pexels/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}