Skip to main content

Bug Bounty Program

The Planner 5D Bug Bounty Program allows independent security researchers to report security vulnerabilities discovered in Planner 5D services. Eligible reports may qualify for a reward based on the severity of the issue.

Before you start

  • Please review the Terms of the Program.

  • You must meet the program eligibility requirements.

  • Reports must be submitted in good faith.

  • Security findings must not be publicly disclosed without prior approval from Planner 5D.


How to report a security vulnerability

  1. Identify a security vulnerability in a Planner 5D service.

  2. Document the issue, including:

    • A description of the vulnerability

    • Its potential impact

    • Evidence of the issue

    • Steps to reproduce it

  3. Send your report to security@planner5d.com.


What happens after submission

Planner 5D reviews each report and evaluates whether it qualifies for the Bug Bounty Program.

If the reported issue is valid and meets the program requirements, the reporter may be eligible for a reward.


Bugs that are eligible for submission:

Severity:

Bugs:

Maximum Bounty payout:

Critical

  • Privilege escalation

  • Injection (SQL, code, file, e-mail, HTTP header)

  • Server-side remote code execution (RCE)

  • Disclosure of sensitive or personally identifiable information - no victim action is required, for example select data from database

  • Other security vulnerabilities determined to be high severity

up to 1000 USD

High

  • Memory safety

  • Disclosure of sensitive or personally identifiable information - victim action is required, for example: navigating through website and opening page with Stored Cross-Site Scripting

  • Stored Cross-Site Scripting

  • Payments issue that happens to most users

  • Other security vulnerabilities determined to be high severity

up to 250 USD

Medium

  • HTTP response splitting

  • Stored Cross-Site Scripting

  • App crash that affects most of users

  • Other security vulnerabilities determined to be medium severity

up to 50 USD

Low

  • All types of Cross-Site Scripting (XSS) except stored XSS

  • All types of Cross-Site Request Forgery (CSRF)

  • Stale cookies

  • Other security vulnerability determined to be low severity

  • Paid feature does not work after purchase

  • Website is not loading / working for some specific URIs (for example showing white page)

  • Bad translations

  • Payments issue that happens in rare edge cases or due to halted server

  • 2D / 3D editor issues that cause incorrect materials, colors, sizes or control problems

  • Other app or website issues - will be decided on case by case basis

up to 10 HD Renders


Bugs that are not eligible for submission:

  • Previously submitted bugs

  • Any other submission determined to be medium or low severity, based on unlikely or theoretical attack vectors, requiring significant user interaction, or resulting in minimal impact

Did this answer your question?