otto-de-bug-bounty

YesWeHackView on YesWeHack
RawAI Enhanced
10
In Scope
17
Out of Scope
In-Scope Assets (10)
Out-of-Scope Assets (17)
AssetCategoryBounty
/apps-messenger (the chatbot in general is out of scope)OTHERYes
/trackingOTHERYes
All domains not listed In-ScopeOTHERYes
Out-Of-Scope are also other applications hosted under the www.otto.de domain but have a different path, that is not part of our core online shop itself (you will notice, since the design of the page is completely different)OTHERYes
Please let us know if you have any questions regarding the scope.OTHERYes
Those include but are not limited to (if unsure, contact us before executing the tests):OTHERYes
https://keycloak.apps.otto.deOTHERYes
https://www.otto.de/claraOTHERYes
https://www.otto.de/kundenchatOTHERYes
https://www.otto.de/newsroomOTHERYes
https://www.otto.de/reblogOTHERYes
https://www.otto.de/roombeezOTHERYes
https://www.otto.de/soulfullyOTHERYes
https://www.otto.de/twoforfashionOTHERYes
https://www.otto.de/updatedOTHERYes
https://www.otto.de/user/contactFormSubmitOTHERYes
https://www.otto.de/user/sendcallbackrequestOTHERYes
Scope Changes (27)
Apr 16, 2026
ChangeAssetCategoryScopeTime
Addedhttps://www.otto.deURLIn Scope18:33
Addedhttps://www.otto.de/jobsURLIn Scope18:33
Addedhttps://play.google.com/store/apps/details?id=de.cellular.ottohybrid&hl=deANDROIDIn Scope18:33
Addedhttps://apps.apple.com/de/app/otto-shopping-m%C3%B6bel/id404844644IOSIn Scope18:33
Addedhttps://www.lascana.de/URLIn Scope18:33
Addedhttps://teleoptiprd.otto.deURLIn Scope18:33
Addedhttps://mmp.otto.deURLIn Scope18:33
Addedhttps://orbidder.otto.deURLIn Scope18:33
Addedhttps://supplier-connect.otto.deURLIn Scope18:33
Addedhttps://retail-api.otto.deURLIn Scope18:33
Addedout-of-scope are also other applications hosted under the www.otto.de domain but have a different path, that is not part of our core online shop itself (you will notice, since the design of the page is completely different)OTHEROut of Scope18:33
Addedthose include but are not limited to (if unsure, contact us before executing the tests):OTHEROut of Scope18:33
Addedhttps://www.otto.de/reblogOTHEROut of Scope18:33
Addedhttps://www.otto.de/roombeezOTHEROut of Scope18:33
Addedhttps://www.otto.de/twoforfashionOTHEROut of Scope18:33
Addedhttps://www.otto.de/soulfullyOTHEROut of Scope18:33
Addedhttps://www.otto.de/updatedOTHEROut of Scope18:33
Addedhttps://www.otto.de/newsroomOTHEROut of Scope18:33
Addedhttps://www.otto.de/kundenchatOTHEROut of Scope18:33
Addedhttps://www.otto.de/claraOTHEROut of Scope18:33
Addedhttps://www.otto.de/user/sendcallbackrequestOTHEROut of Scope18:33
Addedhttps://www.otto.de/user/contactFormSubmitOTHEROut of Scope18:33
Addedhttps://keycloak.apps.otto.deOTHEROut of Scope18:33
Addedall domains not listed in-scopeOTHEROut of Scope18:33
Added/apps-messenger (the chatbot in general is out of scope)OTHEROut of Scope18:33
Added/trackingOTHEROut of Scope18:33
Addedplease let us know if you have any questions regarding the scopeOTHEROut of Scope18:33