Work at Web.com Bug Bounty? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 19 Sep 2026.
Web.com provides many services and products targeted at small and medium sized businesses. No technology is perfect, and Web.com believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our web applications. Good luck and happy hunting! Eligibility You may not participate in this program if you are an employee or family member of an employee, or a current vendor or employee of such vendor of Newfold Digital and any of its subsidiaries. You are also prohibited from participating if you are (i) in a country or territory that is the target of U.S. sanctions (including Cuba, Iran, Syria, North Korea, or the Crimea region of Ukraine), (ii) designated as a Specially Designated National or Blocked Person by the U.S. Department of the Treasury’s Office of Foreign Assets Control or otherwise owned, controlled, or acting on behalf of such a person or entity, or (iii) otherwise a prohibited party under U.S. trade and export control laws. Ratings/Rewards The program relies on CVSS to evaluate impact and determine reward allocations. It is essential to highlight that the priority of a vulnerability might be altered due to its likelihood or impact. CVSS Score VRT Classification 9.0-10.0 P1-Critical 7.0-8.9 P2-High 4.0-6.9 P3-Medium 2.0-3.9 P4-Low 0.0-1.9 P5-Informational We reserve the right to make any final determination of rating levels for any reported vulnerability. Report Formatting In the Description of a Vulnerability Report, please format the replication process as an Ordered List. Valid reports, formatted the following way, will be prioritized and accepted faster by Newfold Digital: Steps To Reproduce: (Add details for how we can reproduce the issue) [add step 1] [add step 2] [add step 3]...
Scope
10 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| app.web.com | website | ✓ bounty | not set |
| https://www.bluehost.com/ | website | ✓ bounty | not set |
| https://www.hostgator.com/ | website | ✓ bounty | not set |
| www.networksolutions.com | website | ✓ bounty | not set |
| *.bluehost.com | website | out | not set |
Show all 10 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| *.hostgator.com | website | out | not set |
| *.networksolutions.com | website | out | not set |
| *.register.com | website | out | not set |
| *.web.com | website | out | not set |
| https://app.gator.com/ | website | out | not set |