Bug Bounty Severity Chart
Priority & severity definitions based on impact and exploitability.
| Priority | Severity | Description | Example Vulnerabilities |
|---|---|---|---|
| P1 | Critical | Complete system compromise | RCE, SQL Injection (auth bypass), Account Takeover (no auth), SSRF โ internal access |
| P2 | High | Significant impact, limited constraints | Stored XSS, IDOR (sensitive data), Privilege Escalation |
| P3 | Medium | Moderate risk, user interaction needed | Reflected XSS, CSRF (non-critical), partial info disclosure |
| P4 | Low | Minor impact, hard to exploit | Clickjacking, rate limit issues, verbose errors |
| P5 | Informational | No real security impact | Missing headers, best practice issues |
Bounty amounts determined by severity + tier scope
Bounty Payment Chart
Three program tiers โ from Standard to VIP โ each with tailored rewards. Higher tier, higher bounties.
๐ Program Notes
All bounties are paid in USD / crypto (USDC) upon validation. Duplicate reports follow standard disclosure policy. Tier selection depends on scope & criticality of target. The Ezekiel team reserves the right to adjust rewards based on exploit complexity. Hall of Fame recognition for all validated P5 submissions in Tier 1.
๐ Private Researcher Hub
Submit vulnerabilities via encrypted channel or join our private Telegram group for real-time discussion & submission guidelines.
โ๏ธ For secure communication, use our official channel.