Early access: this site has moved to bugrater.com.
NR Unrated
Mozilla
Mozilla HackerOne
3 more reviews needed for a grade
Write a review Claim this company profile

Work at Mozilla? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 22 Sep 2026.

What it pays, by severity

Critical $4,229 avg 34 reports firm
High $2,636 avg 49 reports firm
Medium $1,169 avg 182 reports firm
Low $304 avg 136 reports firm

$485,800 paid to researchers in total, $80,950 of it in the last 90 days. Lifetime figure as HackerOne prints it: evidence this program has paid, not a promise about any one report.

Intake & responsiveness · last 90 days

Reports received
766
in 90 days
Resolved
415
all time, last one today
Participants
360
hunters engaged
Response efficiency
79%
meeting its targets, HackerOne’s figure
SLA misses
0
targets missed
Reports received · day by day, last 28 days 766–859
25 Aug 766 reports 22 Sep

Response targets it sets itself

First response
5 days
Triage
10 days
Bounty
30 days
Resolution
30 days

A target the program declared, not a measurement of it being met.

Getting in the door

submissions paused

Over 34 days (33 snapshots): intake up 3 reports; response efficiency down 7 points; 90-day payout down $12,850.

See how this programme’s report load compares to others →

Reviews

0 published

No reviews yet.

Be the first to review

Who this program credits

377 credited

Researchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.

# Researcher Reputation Recognised / submitted
1 d0xing 598 27 / 32 84%
2 griffinf 390 14 / 16 88%
3 sndd 332 13 / 28 46%
4 svennergr 292 6 / 6 100%
5 suul 270 14 / 57 25%
6 dvtuan 247 6 / 16 38%
7 trein 242 6 / 7 86%
8 holybugx 240 16 / 20 80%
9 faav 239 6 / 18 33%
10 psycho_012 238 8 / 22 36%
11 parablack 233 7 / 8 88%
12 ghaazy 198 16 / 93 17%
13 harshinsecurity 189 4 / 9 44%
14 mikey96 186 2 / 4 50%
15 tipsen 156 8 / 15 53%
16 celesian 148 4 / 9 44%
17 dyls 136 2 / 2 100%
18 kawakatz 128 4 / 14 29%
19 0x5t 123 4 / 9 44%
20 ky0tofu 122 4 / 16 25%
21 regex-33 112 6 / 9 67%
22 fdeleite 110 6 / 18 33%
23 luskabol 108 3 / 7 43%
24 ilaygoldman 101 0 / 2 0%
24 yakirka 101 3 / 4 75%

Showing the top 25 of 377 credited on HackerOne.

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 23 Sep 2026.

Mozilla web bug bounty program specific to encouraging security research in Mozilla's products and web services.

Responsiveness
79% HackerOne’s figure
Swag
No
Currency
USD
Submissions
Paused
Launched
May 2023
Scope entries
58 HackerOne’s count

Scope

43 assets
AssetTypeEligibilityMax severity
accounts.firefox.com URL ✓ bounty Critical
addons.allizom.org URL ✓ bounty Critical
api.profiler.firefox.com URL ✓ bounty Critical
aus5.mozilla.org URL ✓ bounty Critical
bugzilla.mozilla.org URL ✓ bounty Critical
Show all 43 assets
AssetTypeEligibilityMax severity
com.ideashower.readitlater.pro GOOGLE PLAY APP ID ✓ bounty Critical
community-tc.services.mozilla.com URL ✓ bounty Critical
contile.services.mozilla.com URL ✓ bounty Critical
Core Sites OTHER ✓ bounty Critical
crash-reports.allizom.org URL ✓ bounty Critical
crash-stats.allizom.org URL ✓ bounty Critical
Critical Sites OTHER ✓ bounty Critical
developer.mozilla.org URL ✓ bounty Critical
Firefox Homepage Newtab OTHER ✓ bounty Critical
firefox-ci-tc.services.mozilla.com URL ✓ bounty Critical
firefox.settings.services.mozilla.com URL ✓ bounty Critical
getpocket.com URL ✓ bounty Critical
hg.mozilla.org URL ✓ bounty Critical
lando.services.mozilla.com URL ✓ bounty Critical
location.services.mozilla.com URL ✓ bounty Critical
merino.services.mozilla.com URL ✓ bounty Critical
monitor.firefox.com URL ✓ bounty Critical
monitor.mozilla.org URL ✓ bounty Critical
Mozilla Ad Routing Service OTHER ✓ bounty Critical
Mozilla VPN Clients OTHER ✓ bounty Critical
mozilla-pontoon-staging.herokuapp.com URL ✓ bounty Critical
phabricator.allizom.org URL ✓ bounty Critical
pontoon.allizom.org URL ✓ bounty Critical
pontoon.mozilla.org URL ✓ bounty Critical
Product Delivery OTHER ✓ bounty Critical
profiler.firefox.com URL ✓ bounty Critical
push.services.mozilla.com URL ✓ bounty Critical
relay.firefox.com URL ✓ bounty Critical
stage.taskcluster.nonprod.cloudops.mozgcp.net URL ✓ bounty Critical
support.mozilla.org URL ✓ bounty Critical
sync.services.mozilla.com URL ✓ bounty Critical
vpn.mozilla.org URL ✓ bounty Critical
www.firefox.com URL ✓ bounty Critical
www.mozilla.org URL ✓ bounty Critical
hello.dev.myhubs.net URL out None
hubs.mozilla.com URL out None
shavar.services.mozilla.com URL out None
uploads-prod.reticulum.io URL out None

HackerOne lists 58 scope entries; its public listing groups many assets under one label, so identical entries are shown once.