moneybox-bug-bounty

YesWeHackView on YesWeHack
RawAI Enhanced
6
In Scope
3
Out of Scope
In-Scope Assets (6)
Out-of-Scope Assets (3)
AssetCategoryBounty
Content served by the Cloudflare Access service (https://moneyboxapp.cloudflareaccess.com/*) is out of scope. These pages intentionally do not set a CORS Allow-Origin policy. We have seen this reported several times as a vulnerability, but it is intended behaviour and is considered out of scope.OTHERYes
Security concerns originating from https://moneyboxapp.onelogin.com/ are typically considered out of scope. These pages and their content are served by OneLogin, and any issues should be reported to them directly. However, if an exploit explicitly enables bypassing OneLogin to access Moneybox systems or leaking Moneybox sensitive data, it is crucial to raise the concerns to both OneLogin and Moneybox.OTHERYes
The Moneybox public website https://www.moneyboxapp.com/ and other moneyboxapp.com / moneyboxapp.org domains not listed are out of scope.OTHERYes
Scope Changes (9)
Apr 16, 2026
ChangeAssetCategoryScopeTime
Addedhttps://api.moneyboxapp.com/URLIn Scope18:33
Addedhttps://admin.moneyboxapp.org/URLIn Scope18:33
Addedhttps://admin-roundups.moneyboxapp.org/URLIn Scope18:33
Addedhttps://apps.apple.com/gb/app/moneybox-save-and-invest/id1049797239IOSIn Scope18:33
Addedhttps://play.google.com/store/apps/details?id=com.moneyboxappANDROIDIn Scope18:33
Addedhttps://sycamore.moneyboxapp.org/URLIn Scope18:33
Addedthe moneybox public website https://www.moneyboxapp.com/ and other moneyboxapp.com / moneyboxapp.org domains not listed are out of scopeOTHEROut of Scope18:33
Addedcontent served by the cloudflare access service (https://moneyboxapp.cloudflareaccess.com/*) is out of scope. these pages intentionally do not set a cors allow-origin policy. we have seen this reported several times as a vulnerability, but it is intended behaviour and is considered out of scopeOTHEROut of Scope18:33
Addedsecurity concerns originating from https://moneyboxapp.onelogin.com/ are typically considered out of scope. these pages and their content are served by onelogin, and any issues should be reported to them directly. however, if an exploit explicitly enables bypassing onelogin to access moneybox systems or leaking moneybox sensitive data, it is crucial to raise the concerns to both onelogin and moneyboxOTHEROut of Scope18:33