Infosec Institute

Open Bug Bounty mentioned in the
Top 6 Bug Bounty programs of
2022 by the InfoSec Institute

The Hacker News

Open Bug Bounty named among the
Top 5 Bug Bounty programs of 2021
by The Hacker News

Platform update: please use our new authentication mechanism to securely use the Open Bug Bounty Platform.
For security researchers
Report a Vulnerability
Submit, help fixing, get kudos.
For website owners
Start a Bug Bounty
Run your bounty program for free.
1,706,133 coordinated disclosures
1,384,084 fixed vulnerabilities
1,992 bug bounty programs, 3,887 websites
47,255 researchers, 1,653 honor badges

kun-fly | Security Researcher Profile


Security researcher kun-fly has already helped fix 1264 vulnerabilities.



Researcher reputation:  550

Real name:
Kunal Jadhav

About me:
Ethical Hacker/Bug hunter/Cyber security researcher/Pentester/../etc/

Contact email:
[email protected]

Alternative Contacts:
[email protected]

DM me on Twitter - ikunaljadhav

Certifications & Diplomas:
Certified Ethical Hacker
Certified Penetration Testing Engineer
ICSI CNSS

Award / Bug Bounty I prefer:
Cryptocurrency/PayPal/Payoneer, voucher, gift cards, Letter of Appreciation
& a Recommendation on my profile. :)
BTC- 3E4NoHyaTusefWvPnUc5iJKosvFKxjoqbh

Halls of Fame:
None. Not needed.

Follow me on:
Twitter
Facebook
LinkedIn

Ethics and Rules:
Kunal Jadhav is required to abide by the ethics and rules of the Open Bug Bounty project. If you reasonably believe that rules are not respected, please report this to us.

Recommendations and Acknowledgements | Full List:

@UUCSIRT     22 February, 2021
    Twitter UUCSIRT Hans Liss from Uppsala university:
Thanks for your responsible disclosure of and XSS vulnerability on one of our webpages. It's appreciated!
@businessofdesi1     23 July, 2020
    Twitter businessofdesi1 R. Klein from Business of Design:
Kunal was able to find and alert us to the presence of a serious vulnerability in one of our Wordpress plugins. We in turn alerted the developer, who issued an update with a fix. We highly recommend Kunal as a professional and diligent ethical hacker who'll help secure your site.
@vmarci21     25 June, 2020
    Twitter vmarci21 Marton :
Thanks to finding the XSS vulnerability!
We are really appreciated your work.
@vmarci21     25 June, 2020
    Twitter vmarci21 Marton :
Thanks to finding the XSS vulnerability!
We are really appreciated your work.
@Grada48040091     24 June, 2020
    Twitter Grada48040091 Carlos Jacobs from Grada:
Appreciate you founded a XSS bug on our website. ¡Thank you very much!
@plaxiva     22 April, 2020
    Twitter plaxiva Konstantin :
Helped with finding XSS vulnerability, recommend as security specialist.
@phistrom     2 March, 2020
    Twitter phistrom Phillip from The Stromberg Group:
We really appreciate your help identifying an XSS exploit on our website. Your responsible disclosure and example URL allowed us to immediately find and correct the problem. Thank you for your hard work to make the internet a safer place.
@fitzsimons_jim     2 March, 2020
    Twitter fitzsimons_jim Jim Fitzsimons from Granite Digital:
Kunal identified an XSS vulnerability on one of our sites, communicated the issue clearly to us and helped us solve it. Excellent work from a fine researcher. Highly recommended!
@LarryParker98     26 February, 2020
    Twitter LarryParker98 Larry Parker from University at Albany:
Kunal, thank you for reporting the vulnerability on our web site. We greatly appreciate your help in securing our site.
@GeraldKjellberg     13 January, 2020
    Twitter GeraldKjellberg Frankie :
Thanks mate for finding XSS vulnerability on our website.
@GeraldKjellberg     13 January, 2020
    Twitter GeraldKjellberg Katherine :
We need researchers like you! Thanks.
@GeraldKjellberg     13 January, 2020
    Twitter GeraldKjellberg Jacquelin :
Good researcher!
@GeraldKjellberg     13 January, 2020
    Twitter GeraldKjellberg Astor :
You reported and we fixed! Thanks :)
@GeraldKjellberg     13 January, 2020
    Twitter GeraldKjellberg Lauren :
Appreciate you founded a XSS bug on our website. Keep it up.
@GeraldKjellberg     13 January, 2020
    Twitter GeraldKjellberg Roger :
Yay! We fixed the XSS bug. Thanks.
@GeraldKjellberg     13 January, 2020
    Twitter GeraldKjellberg Kylie :
Thanks for helping us kill the XSS bug! :)
@GeraldKjellberg     13 January, 2020
    Twitter GeraldKjellberg Jon :
Thanks! For finding xss bug
@GeraldKjellberg     13 January, 2020
    Twitter GeraldKjellberg Vincent :
Appreciate your work!
@GeraldKjellberg     13 January, 2020
    Twitter GeraldKjellberg Tyler :
We killed that XSS bug. Thanks for letting us know.
@BrianWi28100399     13 January, 2020
    Twitter BrianWi28100399 Henry :
Great researcher. Already patched the XSS bug. Thanks!
@BrianWi28100399     13 January, 2020
    Twitter BrianWi28100399 Ben :
Keep hunting! Thank you for finding XSS bug on our website
@BrianWi28100399     13 January, 2020
    Twitter BrianWi28100399 Watson :
You made our website more secure. Thank you!
@BrianWi28100399     13 January, 2020
    Twitter BrianWi28100399 Alan :
Appreciate you find a bug on our website.
@BrianWi28100399     13 January, 2020
    Twitter BrianWi28100399 Stephan :
Great work! Here is our recommendtion to you. Keep it up.
@BrianWi28100399     13 January, 2020
    Twitter BrianWi28100399 Lewis :
Great bug hunter! Thanks for letting us know.
@BrianWi28100399     13 January, 2020
    Twitter BrianWi28100399 Philip :
Thanks for making our website more secure.
@BrianWi28100399     13 January, 2020
    Twitter BrianWi28100399 George :
Thanks from our team for finding XSS vulnerability. Great work!
@BrianWi28100399     13 January, 2020
    Twitter BrianWi28100399 Taylor :
Patched the XSS bug which you've reported. Thanks for letting us know.
@BrianWi28100399     13 January, 2020
    Twitter BrianWi28100399 Kate :
Thanks for finding XSS vulnerability. Keep it up!
@BrianWi28100399     13 January, 2020
    Twitter BrianWi28100399 Anne :
Thanks for finding the bug. Feel free to report more issues on our website.
@BrianWi28100399     13 January, 2020
    Twitter BrianWi28100399 Beck :
Thanks for that bug you found. Learned something new. Appreciate your work.
@BrianWi28100399     13 January, 2020
    Twitter BrianWi28100399 Beck :
Thanks for that bug you found. Learned something new. Appreciate your work.
@RuebenGomez2     13 January, 2020
    Twitter RuebenGomez2 Rueben :
Genuine researcher. Glad you find the bug. Appreciate.
@MdeRteU     8 January, 2020
    Twitter MdeRteU Michiel de Roo :
A helpful and trustworthy researcher.
@JakePer98117086     6 January, 2020
    Twitter JakePer98117086 Candace :
Thanks for finding XSS vulnerability and reporting it. Our team has patched it.
@JakePer98117086     6 January, 2020
    Twitter JakePer98117086 Timothy :
Nice catch. Thanks for finding XSS vulnerability on our website.
@JakePer98117086     6 January, 2020
    Twitter JakePer98117086 Noah :
Thanks for letting us know.
@JakePer98117086     6 January, 2020
    Twitter JakePer98117086 Delilah :
Keep hunting! Thank you for finding XSS vulnerability.
@JakePer98117086     6 January, 2020
    Twitter JakePer98117086 David :
Keep hunting those bugs! Thank you!
@JakePer98117086     6 January, 2020
    Twitter JakePer98117086 Joe :
Great work! Let us know if you find more vulnerabilities. Thank you!
@JakePer98117086     6 January, 2020
    Twitter JakePer98117086 Amy from Unknown:
Really appreciated your work. Please let us know if you find more. Thank you!
@JakePer98117086     6 January, 2020
    Twitter JakePer98117086 Robert :
Thank you! For letting us know.
@JakePer98117086     6 January, 2020
    Twitter JakePer98117086 David :
Thanks for letting us know about the XSS vulnerability.
@JakePer98117086     6 January, 2020
    Twitter JakePer98117086 Jake :
Thank you! for finding XSS vulnerability.
@Broly157     5 January, 2020
    Twitter Broly157 Broly :
Well submitted report thank you for helping us for securing our website

Please login via Twitter to add a recommendation

Honor Badges


Number of Secured Websites

10+ Secured Websites Badge
50+ Secured Websites Badge
500+ Secured Websites Badge
Web Security Veteran Badge
10+ Websites
50+ Websites
500+ Websites
WEB SECURITY VETERAN
1000+ Websites

Advanced Security Research

WAF Bypasser Badge
CSRF Master Badge
AppSec Logic Master Badge
Fastest Fix Badge
WAF Bypasser
CSRF Master
30+ Reports
AppSec Logic Master
30+ Reports
Fastest Fix
Fix in 24 hours

Outstanding Achievements

Secured OBB Badge
OBB Advocate Badge
Improved OBB Badge
Secured OBB
OBB Advocate
Improved OBB

Commitment to Remediate and Patch

Patch Master Badge
Patch Guru Badge
Patch Lord Badge
Patch Master
55% Patched
Patch Guru
65% Patched
Patch Lord
75% Patched

Recommendations and Recognition

REPUTABLE Badge
FAMOUS Badge
GLOBALLY TRUSTED Badge
REPUTABLE
10+ Recommends
FAMOUS
25+ Recommends
GLOBALLY TRUSTED
50+ Recommends

Distinguished Blog Author

Distinguished Blog Author Badge
Distinguished Blog Author Badge
Distinguished Blog Author Badge
1 Post
3 Posts
5+ Posts

Research Statistics



Total reports:4347
Total reports on VIP sites:136
Total patched vulnerabilities:1264
Recommendations received:45
Active since:08.12.2019

Open Bug Bounty Certificate


Researcher Certificate

Reported Vulnerabilities

All Submissions VIP SubmissionsFeatured Submissions




No posts in blog yet










  Latest Patched

 02.05.2024 iuclid6.echa.europa.eu
 02.05.2024 capim.pb.gov.br
 01.05.2024 siat-sz.edu.cn
 01.05.2024 tmsteam.me
 28.04.2024 pedralva.mg.gov.br
 28.04.2024 novaubirata.mt.gov.br

  Latest Blog Posts

04.12.2023 by BAx99x
Unmasking the Power of Cross-Site Scripting (XSS): Types, Exploitation, Detection, and Tools
04.12.2023 by a13h1_
$1120: ATO Bug in Twitter’s
04.12.2023 by ClumsyLulz
How I found a Zero Day in W3 Schools
04.12.2023 by 24bkdoor
Hack the Web like a Pirate: Identifying Vulnerabilities with Style
04.12.2023 by 24bkdoor
Navigating the Bounty Seas with Open Bug Bounty

  Recent Recommendations

    1 May, 2024
    Mek:
Got a recommendation to fix an SQL injection vulnerability on my website. As I am a hobbyist and my page is a hobby project, I can't offer money, so I am recommending this researcher. Thanks again.
    26 April, 2024
    I_bims_Mike:
Thank you very much for identifying the XSS vulnerability and for our friendly email exchange.
    22 April, 2024
    genoverband:
Thank you for your invaluable help in ensuring the security of our domain and its visitors!
    10 April, 2024
    Mars:
Hatim uncovered a XSS bug that we were able to quickly resolve. Thanks very much for your assistance and help.
    8 April, 2024
    Panthermedia:
Thanks to the support of Hatim Chabik, we were able to identify and solve an XSS bug.