Program Overview
Clarivate runs a vulnerability disclosure program on HackerOne. The program has 5027 in-scope assets and is managed by HackerOne's triage team.
In-Scope Assets
| Asset | Type | Max Severity | Eligible |
|---|---|---|---|
| 03al1450.com | URL | Critical | No Bounty |
| 03mn1500.com | URL | Critical | No Bounty |
| 04ag1525.com | URL | Critical | No Bounty |
| 0510billing.com | URL | Critical | No Bounty |
| 05yo1560.com | URL | Critical | No Bounty |
| 09ek1225.com | URL | Critical | No Bounty |
| 100topinnovators.com | URL | Critical | No Bounty |
| 123demo-domainz.biz | URL | Critical | No Bounty |
| 123demo-domainz.co.uk | URL | Critical | No Bounty |
| 123demo-domainz.net | URL | Critical | No Bounty |
| 123demo-domainz.org | URL | Critical | No Bounty |
| 123efgdemo-domainz.net | URL | Critical | No Bounty |
| 124mmdemodomains.info | URL | Critical | No Bounty |
| 1790.com | URL | Critical | No Bounty |
| 1790.net | URL | Critical | No Bounty |
| 1790.org | URL | Critical | No Bounty |
| 1st2file.com | URL | Critical | No Bounty |
| 1st2file.net | URL | Critical | No Bounty |
| 1stedit.com | URL | Critical | No Bounty |
| 247realmedia.fr | URL | Critical | No Bounty |
| 3dnma.com | URL | Critical | No Bounty |
| 6degreesofcitation.com | URL | Critical | No Bounty |
| ab123domains.info | URL | Critical | No Bounty |
| ab123domains.net | URL | Critical | No Bounty |
| ab124domains.info | URL | Critical | No Bounty |
| ab124domains.net | URL | Critical | No Bounty |
| abacusdatamanagement.com | URL | Critical | No Bounty |
| abacusint.com | URL | Critical | No Bounty |
| abacusint.info | URL | Critical | No Bounty |
| abacusvalue.co.uk | URL | Critical | No Bounty |
| abacusvalue.com | URL | Critical | No Bounty |
| aboutaxspa.ca | URL | Critical | No Bounty |
| aboutproquest.com | URL | Critical | No Bounty |
| aboutproquest.net | URL | Critical | No Bounty |
| academic-e-books.com | URL | Critical | No Bounty |
| academichelp.com | URL | Critical | No Bounty |
| academicvideoonline.com | URL | Critical | No Bounty |
| academicvideostore.com | URL | Critical | No Bounty |
| accelanation.com | URL | Critical | No Bounty |
| acceleratingthepaceofinnovation.com | URL | Critical | No Bounty |
| accesspolaris.com | URL | Critical | No Bounty |
| acetheclass.com | URL | Critical | No Bounty |
| acetheclass.net | URL | Critical | No Bounty |
| acetheclass.org | URL | Critical | No Bounty |
| acethecourse.com | URL | Critical | No Bounty |
| acethecourse.net | URL | Critical | No Bounty |
| acethecourse.org | URL | Critical | No Bounty |
| aclasta.ca | URL | Critical | No Bounty |
| activatenetwork.net | URL | Critical | No Bounty |
| activatenetworks.net | URL | Critical | No Bounty |
Showing 50 of 5027 in-scope assets. View all on HackerOne.
Out-of-Scope Assets
- bigstockphoto.fr
- ofcourse.com
Tips for Hacking Clarivate
- Read the policy — Understand what's in scope, out of scope, and any specific testing restrictions before you start.
- Enumerate the attack surface — Use subdomain enumeration and directory bruteforcing to map all accessible endpoints.
- Focus on high-impact bugs — Look for SQL injection, SSRF, and IDOR vulnerabilities first.
- Test authentication flows — Check for OAuth misconfigurations and CSRF in login/signup flows.
- Write clear reports — Include steps to reproduce, impact assessment, and suggested remediation. Use Burp Suite to capture evidence.
Frequently Asked Questions
How do I start hacking Clarivate?
Sign up on HackerOne, read the program policy carefully, review the in-scope assets listed above, and start testing. Always stay within scope and follow responsible disclosure guidelines.
Does Clarivate pay bounties?
No, Clarivate runs a Vulnerability Disclosure Program (VDP) without monetary rewards. You may receive recognition or swag.
What types of vulnerabilities does Clarivate accept?
Clarivate accepts reports for vulnerabilities found in their 5027 in-scope assets. Common accepted vulnerability types include XSS, SQL injection, SSRF, IDOR, authentication bypass, and RCE. Check the program policy for specific exclusions.