DenMarket Bug Bounty Program

Defend Denmark runs coordinated security testing for DenMarket, an online marketplace. We invite researchers to find and responsibly report vulnerabilities so we can fix them before they hurt our users.

Sign up to participate I already have a token

Scope

✅ In scope

  • *.denmarket.dk — all subdomains and services of the DenMarket platform

⛔ Out of scope

  • This portal — hack.denmarket.dk — is OUT of scope. Do not test the submission platform itself.
  • The underlying server / VPS, its SSH, and the hosting provider
  • Any host or service outside denmarket.dk
  • Denial of service, volumetric/automated scanning that degrades the service
  • Social engineering of staff or other researchers

Rules of engagement

How findings are judged

There are no flags. You demonstrate impact with a clear writeup and a proof artifact — the concrete evidence that you achieved the impact, e.g.:

Reports are scored on impact, clarity, and reproducibility. A great writeup that lets us reproduce and fix the issue beats a vague high-severity claim.

SeverityTypical examples
CriticalRCE, full admin takeover, mass data exposure
HighSQLi, auth bypass, SSRF to internal secrets
MediumStored XSS, IDOR, CSRF on sensitive actions
LowReflected XSS, user enumeration, info leaks
InfoBest-practice notes, hardening suggestions

How to participate

  1. Sign up with a username — you’ll get a long-lived API token. Save it; it’s shown once.
  2. Hack the in-scope targets.
  3. Submit a report for each finding with steps and your proof artifact.
  4. Track status under My reports as we triage.

Questions during the event? Grab an organizer or email security@denmarket.dk.