Security Hall of Fame

ISO Mate is grateful to the security researchers who take the time to responsibly report vulnerabilities to us. Their work helps us keep our platform and our customers safe. This page recognizes the people who have made a valued contribution to the security of ISO Mate.

A Note on Compensation

ISO Mate does not currently operate a guaranteed paid bug bounty program. As an early-stage company, we are not yet in a position to offer immediate monetary rewards for vulnerability reports, and we want to be completely transparent about this.

However, we deeply value the security community and do not want your hard work to go unappreciated. We carefully track all valid submissions. While future payouts cannot be legally guaranteed today, it is our earnest goal to recognize these early contributions retrospectively as our company grows. ISO Mate reserves the right to issue discretionary, retroactive rewards to eligible researchers when our financial position allows.

Being listed here in our Security Hall of Fame serves as a permanent record of your invaluable contribution to our security and our gratitude for your help.

Responsible Disclosure

We ask that researchers give us a reasonable opportunity to investigate and remediate a reported issue before disclosing it publicly. To protect our customers, we only add a researcher and the details of their finding to this page after the vulnerability has been fully remediated. Entries are published with the researcher’s permission, and we are happy to credit you by name, handle, or anonymously, whichever you prefer.

Safe Harbor and Scope

We want researchers to test with confidence. If you act in good faith and follow our disclosure policy, we consider your research authorized and will not pursue legal action against you. The policy also sets out which systems are in scope, which are out of scope, and the testing activities we do not permit. Please review it before you begin: Vulnerability Disclosure Policy.

Recognized Researchers

The researchers below have responsibly disclosed vulnerabilities that we have since remediated. We add new entries here as reports are validated and fixed, with each researcher’s permission.

Von ISO Mate anerkannte Sicherheitsforscher
ForscherGemeldete SchwachstelleDatum der Anerkennung
Omkar DalaviZugriffstoken blieb nach der Abmeldung gültigAugust 2026
Jahidul Hasan MunnaFehlerhafte Autorisierung auf Funktionsebene bei Dashboard-EndpunktenAugust 2026
Jahidul Hasan MunnaFehlende Ratenbegrenzung bei der Datensatzerstellung ermöglicht Überflutung des ArbeitsbereichsAugust 2026
Swatantra KokareFehlerhafte OAuth-Kontobindung nach einer Änderung der E-Mail-AdresseAugust 2026
Manas Pipersaniya (VIT Bhopal University)Fehlende Sicherheitsheader bei statisch ausgelieferten DateienAugust 2026
Aseeruddin MullaFehlende Durchsetzung von Kontingenten auf Kontoebene ermöglicht unkontrollierte BenutzeranlageAugust 2026
Karan PatilGespeichertes Cross-Site-Scripting (XSS) in geteilten NotizenAugust 2026
Jebin JoseFehlender Selbsthilfeweg aus der Sperre wegen nicht verifizierter E-MailAugust 2026
Vijay RaghavGespeicherte HTML-Injektion in NotizinhaltenAugust 2026
Sahil MoreHost-Header-Injection ermöglicht Weiterleitung auf eine beliebige DomainAugust 2026
Pramod RathodAktive Sitzungen nach dem Zurücksetzen des Passworts nicht ungültig gemachtAugust 2026
Arjun Pandurang TupeUmgehung der E-Mail-Verifizierung über die Anmeldung mit GoogleAugust 2026
Pramod RathodFehlende Validierung der Eingabelänge im RegistrierungsformularAugust 2026
Umar (Stalker)Fehlende Ratenbegrenzung bei Benutzereinladungen ermöglicht Missbrauch des ausgehenden E-Mail-VersandsAugust 2026
Umar (Stalker)Rechteausweitung in der Konto- und RollenverwaltungAugust 2026
Umar (Stalker)Unzureichende Rechteverwaltung bei Rollendelegation und KontoinhaberschaftAugust 2026
Umar (Stalker)Gespeichertes Cross-Site-Scripting (XSS) über Dateianhang-UploadAugust 2026
AnonymUnbeschränkte Kalendererstellung ermöglicht RessourcenerschöpfungAugust 2026
Mayuri S. PatwardhanFehlende Content-Security-Policy in der AnwendungskonsoleJuli 2026
Mayuri S. PatwardhanContent-Security-Policy, die Inline-Skripte zulässtJuli 2026
Mayuri S. PatwardhanCookie ohne SameSite-Attribut gesetztJuli 2026
Mayuri S. PatwardhanVeraltete X-XSS-Protection-Kopfzeile zurückgegebenJuli 2026
Mayuri S. PatwardhanFehlende Kopfzeilen zur Cross-Origin-IsolierungJuli 2026
Pathan AslamSpoofing von E-Mail-Adressen durch Unicode-HomoglyphenJuli 2026
Pathan AslamGespeichertes Cross-Site-Scripting (XSS) über Logo-UploadJuli 2026
Pathan AslamUnzureichende Verifizierung bei der Änderung der Konto-E-MailJuli 2026
Pathan AslamAktive Sitzungen bei Passwortänderung nicht ungültig gemachtJuli 2026
Pathan AslamFehlende Validierung der maximalen PasswortlängeJuli 2026
Pathan AslamFehlende Benachrichtigungs-E-Mail bei PasswortänderungJuli 2026
Pathan AslamFehlende erneute Authentifizierung bei sensiblen administrativen Aktionen (Benutzerlöschung)Juli 2026
Soham D. JadhavGespeicherte Hyperlink-InjektionJuli 2026
Team TrinityXploitEnumeration von Benutzernamen über AnmeldefehlermeldungenJuli 2026
Omkar YepreDetails auf Wunsch des Forschers vertraulich behandeltJuli 2026
Team TrinityXploitVom Benutzer kontrollierte Links in Benachrichtigungs-E-Mails wiedergegebenJuli 2026
Kartik Kapil LonkarUnkontrollierter Ressourcenverbrauch über den Endpunkt für geplante AufgabenJuli 2026
Sankalp TripathiUmgehung der Testbeschränkung über E-Mail-Adressen-AliaseJuli 2026
Vivek Rajendra UdaneNicht validierte E-Mail-Empfängerdomains ermöglichen Missbrauch des ausgehenden E-Mail-VersandsJuli 2026
Akif Ali KhanOffenlegung der Webserver-Version über die Server-KopfzeileJuli 2026
AnonymFehlende Durchsetzung von HTTP Strict Transport Security (HSTS)Juni 2026

How to Report a Vulnerability

If you believe you have found a security vulnerability in ISO Mate, please email us at security@isomate.io with enough detail for us to reproduce and validate the issue. We will acknowledge your report, keep you informed as we investigate, and let you know once the issue is resolved. For the full rules of engagement, see our Vulnerability Disclosure Policy. For more information about how we protect your data, see our Security Practices page.

Contact

For anything related to security or responsible disclosure, please contact us at security@isomate.io.