pluxee-global-bug-bounty-program

YesWeHackView on YesWeHack
RawAI Enhanced
14
In Scope
7
Out of Scope
In-Scope Assets (14)
AssetCategoryBountyQuick Links
https://api.pluxee.app/gl/cwc/consumer-front-api/URLYes
https://api.pluxee.app/gl/eva/bffURLYes
https://apps.apple.com/fr/app/pluxee/id1437173271IOSYes-
https://apps.apple.com/ro/app/pluxee/id6504407951?l=roIOSYes-
https://connect.pluxee.appURLYes
https://consommateurs.pluxee.tnURLYes
https://consumatori.pluxee.roURLYes
https://consumers.pluxee.[at|bg|de|lu]URLYes-
https://play.google.com/store/apps/details?id=com.pluxeegroup.consumers.globalANDROIDYes
https://play.google.com/store/apps/details?id=com.sodexo.cwc.ro&hl=enANDROIDYes
https://www.inspirus.comWILDCARDYes
https://www.pluxee.[fr|ro|be|cz|de|ph|tn|ma|at|bg|cl|lu|co.id|com.tr|uk|pt|es|mx|co|pe|uy|it|pa|in|com.br]WILDCARDYes-
https://www.pluxeeforfintech.mxWILDCARDYes
https://www.pluxeegroup.comWILDCARDYes
Out-of-Scope Assets (7)
AssetCategoryBounty
Any asset not listed in the scope sectionOTHERYes
Non-production assets hosted on our wildcards scopes are considered as out of the scope of this program (e.g. domains with "uat", "tst", "pprd", "dev", "demo", ...).OTHERYes
clientes.pluxee.com.brOTHERYes
flex.clientes.pluxee.esOTHERYes
portal-atos.clients.uat.pluxee.beOTHERYes
portal.clients.pluxee.beOTHERYes
terceros.clientes.pluxee.coOTHERYes
Scope Changes (21)
Apr 16, 2026
ChangeAssetCategoryScopeTime
Addedhttps://www.pluxeegroup.comWILDCARDIn Scope18:33
Addedhttps://www.pluxee.[fr|ro|be|cz|de|ph|tn|ma|at|bg|cl|lu|co.id|com.tr|uk|pt|es|mx|co|pe|uy|it|pa|in|com.br]WILDCARDIn Scope18:33
Addedhttps://www.pluxeeforfintech.mxWILDCARDIn Scope18:33
Addedhttps://www.inspirus.comWILDCARDIn Scope18:33
Addedhttps://consumers.pluxee.[at|bg|de|lu]URLIn Scope18:33
Addedhttps://consumatori.pluxee.roURLIn Scope18:33
Addedhttps://consommateurs.pluxee.tnURLIn Scope18:33
Addedhttps://play.google.com/store/apps/details?id=com.sodexo.cwc.ro&hl=enANDROIDIn Scope18:33
Addedhttps://apps.apple.com/fr/app/pluxee/id1437173271IOSIn Scope18:33
Addedhttps://api.pluxee.app/gl/cwc/consumer-front-apiURLIn Scope18:33
Addedhttps://connect.pluxee.appURLIn Scope18:33
Addedhttps://api.pluxee.app/gl/eva/bffURLIn Scope18:33
Addedhttps://apps.apple.com/ro/app/pluxee/id6504407951?l=roIOSIn Scope18:33
Addedhttps://play.google.com/store/apps/details?id=com.pluxeegroup.consumers.globalANDROIDIn Scope18:33
Addedany asset not listed in the scope sectionOTHEROut of Scope18:33
Addednon-production assets hosted on our wildcards scopes are considered as out of the scope of this program (e.g. domains with "uat", "tst", "pprd", "dev", "demo", ...)OTHEROut of Scope18:33
Addedclientes.pluxee.com.brOTHEROut of Scope18:33
Addedportal.clients.pluxee.beOTHEROut of Scope18:33
Addedflex.clientes.pluxee.esOTHEROut of Scope18:33
Addedterceros.clientes.pluxee.coOTHEROut of Scope18:33
Addedportal-atos.clients.uat.pluxee.beOTHEROut of Scope18:33