← The brief
01 · The record
03 · The finder
04 · The programme
Published finding · Bugcrowd
Comcast Xfinity Vulnerability Disclosure Program A finding this programme accepted and published. Bugcrowd published no award figure for it.
Everything Bugcrowd published about this
- Programme
- Comcast Xfinity Vulnerability Disclosure Program In our directory, so it has reviews and a grade.
- Platform handle
- comcastvdp
- Asset
- Not published The platform did not name an asset for this entry.
- Severity
- critical Bugcrowd rates P1–P5; this is that rating in HackerOne's words so the two feeds can sit in one table.
- Award
- Not published This does not mean nothing was paid. Both platforms let a programme accept a finding without publishing the figure, and most do.
- Found by
- p4fg Named because the finder allowed the platform to name them.
- State
- unresolved — accepted, not yet fixed
- Accepted
- 24 August 2026 1 month ago. This is the date the programme accepted the finding.
- First seen here
- 24 August 2026 When our sweep first read this entry. It says nothing about the finding, only about us.
- Platform reference
- d84585ad-3613-47b6-87de-a4c33fc13888
What else p4fg has published on Bugcrowd
9published findings
6programmes
4critical
$18,850published awards
- New Blue Website (NBW) - VWFS Bug Bounty Program high · https://www.vwfs.sk · 15 days ago —
- EPAM Systems Managed Bug Bounty Program critical · *.lab.epam.com · 1 month ago $300
- eToro Managed Bug Bounty Engagement low · *.etoro.com · 2 months ago $200
- Comcast Xfinity Bug Bounty medium · *.comcast.com · 3 months ago $200
- Trello critical · *.trello.services · 3 months ago $12,000
- Comcast Xfinity Bug Bounty medium · *.xfinity.com · 5 months ago $150
- Comcast Xfinity Bug Bounty critical · *.xcal.tv · 6 months ago $5,500
- Comcast Xfinity Bug Bounty medium · *.comcast.com · 6 months ago $500
Counted within Bugcrowd only. The same handle on another platform may or may not be the same person, and this page will not assume it is.
What else Comcast Xfinity Vulnerability Disclosure Program has published
- Finding accepted medium · unresolved · akintech · 1 month ago —
- Finding accepted medium · unresolved · akintech · 1 month ago —
- Finding accepted medium · unresolved · akintech · 1 month ago —
- Finding accepted medium · unresolved · akintech · 1 month ago —
- Finding accepted medium · unresolved · akintech · 1 month ago —
- Finding accepted medium · unresolved · akintech · 1 month ago —
- Finding accepted medium · unresolved · akintech · 1 month ago —
- Finding accepted medium · unresolved · akintech · 1 month ago —
See Comcast Xfinity Vulnerability Disclosure Program's grade and researcher reviews →
Where this came from. One row of a public platform feed, stored as published and never edited. We hold no report title, no write-up and no reproduction steps, because the feeds do not carry them and we do not go looking for them. A withheld name stays withheld; if a finder later asks the platform to un-name them, the next sweep un-names them here. Absence of an award figure is publication policy, not evidence a programme did not pay.