Programs/Auriga Retail

Auriga Retail

PublicManaged triage
Commerce storefront, apps and checkout · auriga.shop

Auriga Retail welcomes research across its storefront, shopping apps and checkout API. Anything that lets an attacker change a price, take over an account or read another customer's order is treated as critical.

Submit a report
Max bounty
$6,000
Avg. response
2.0 days
Reports resolved
133
Bounties paid
$168k
Researchers
51

Scope

In scope
www.auriga.shopWeb
checkout.auriga.shopWeb
Auriga mobile appsMobile
api.auriga.shopAPI
Out of scope
blog.auriga.shop
Third-party review widgets
Denial-of-service / volumetric
Coupon brute-forcing without impact

Rewards by severity

SeverityExamplesBounty
CriticalRCE, auth bypass, mass data exposure$2,400 – $6,000
HighSSRF, stored XSS, privilege escalation$920 – $2,300
MediumIDOR, CSRF on sensitive actions$220 – $560
LowReflected XSS, minor info disclosure$40 – $110

Rules & policy

01

Test only assets listed in scope. Never access, modify or delete data that does not belong to your test account.

02

Use your own test accounts. Stop immediately if you encounter another user's data and report it.

03

No denial-of-service, automated scanning at scale, or social engineering of staff or users.

04

Report each vulnerability once, with clear reproduction steps and evidence. Duplicates are closed against the earliest valid report.

05

Keep findings confidential until Auriga confirms a fix and agrees to disclosure. Good-faith research is authorized and will not be pursued legally.

Recent activity

LowReflected XSS on ?q= search paramResolved · $150
HighCart price manipulation via roundingResolved · $2,250
MediumOrder history exposed by guest token reuseAccepted
CriticalAccount takeover through password-reset raceResolved · $6,000

Found something on Auriga Retail?

Submit a structured report with steps and evidence. Managed triage reviews it, and a valid finding is rewarded by severity.

Submit a reportBack to programs