This article explains how Presspage handles vulnerability reports and what to include when submitting one.
Presspage takes security seriously and welcomes vulnerability reports at cvd [at] presspage [dot] com. There is currently no bug bounty program in place, and Presspage has no plans to implement one.
Per our Terms & Conditions, testing our production environment is prohibited. That said, if you come across a vulnerability, we want to hear about it.
Provide a report that includes steps to reproduce. Screenshots, videos, and scripts are welcome.
Out of scope:
- DDoS and brute-force attacks
- Third-party services
- Social engineering
- Reports from automated tools without manual verification
- Anything leading to data loss, data changes, or degraded performance
Warning:
Do not test the Newsroom of any Presspage customer without their explicit written permission.