PentestingHere
Log in Join

Canva

Canva on Bugcrowd · Bugcrowd Active

Official page

Scope

At a glance

  • Maximum payout: $15,000
  • Public disclosure: Not allowed
  • Managed by the platform: Yes
  • Safe harbour: Partial

In scope

  • https://www.canva.com
  • https://www.canva.com/developers/
  • Apps SDK Sandboxing
  • https://api.canva.com
  • *.canva.com
  • *.canva-apps.com
  • https://*.canva.tech
  • https://www.canva.com/en_au/help/chatgpt-templates/
  • https://www.canva.com/integrations/slack/
  • Canva Desktop (macOS / Windows)
  • Canva (iOS)
  • Canva (Android)
  • Canva (Chrome Extension)
  • *.canva.cn
  • *.canva-apps.cn
  • Leaked Credentials and Secrets (Canva Employee/Contractor)
  • Leaked Credentials and Secrets (Canva User)
  • 3rd-Party Provider Vulnerability

Imported from the public directory. Always confirm scope on the official program page before testing.

Is it worth your time?

Read the community feedback

0 reviews rating communication, triage, payouts and whether it suits beginners.

Open feedback