HackerOne · VDP

Clarivate Vulnerability Disclosure Program

Complete guide to Clarivate's vulnerability disclosure program on HackerOne. View in-scope assets, reward amounts, response times, and tips for finding vulnerabilities.

Program Overview

Clarivate runs a vulnerability disclosure program on HackerOne. The program has 5027 in-scope assets and is managed by HackerOne's triage team.

5027
In-Scope Assets
4h
Avg Response
72%
Efficiency

In-Scope Assets

AssetTypeMax SeverityEligible
03al1450.comURLCriticalNo Bounty
03mn1500.comURLCriticalNo Bounty
04ag1525.comURLCriticalNo Bounty
0510billing.comURLCriticalNo Bounty
05yo1560.comURLCriticalNo Bounty
09ek1225.comURLCriticalNo Bounty
100topinnovators.comURLCriticalNo Bounty
123demo-domainz.bizURLCriticalNo Bounty
123demo-domainz.co.ukURLCriticalNo Bounty
123demo-domainz.netURLCriticalNo Bounty
123demo-domainz.orgURLCriticalNo Bounty
123efgdemo-domainz.netURLCriticalNo Bounty
124mmdemodomains.infoURLCriticalNo Bounty
1790.comURLCriticalNo Bounty
1790.netURLCriticalNo Bounty
1790.orgURLCriticalNo Bounty
1st2file.comURLCriticalNo Bounty
1st2file.netURLCriticalNo Bounty
1stedit.comURLCriticalNo Bounty
247realmedia.frURLCriticalNo Bounty
3dnma.comURLCriticalNo Bounty
6degreesofcitation.comURLCriticalNo Bounty
ab123domains.infoURLCriticalNo Bounty
ab123domains.netURLCriticalNo Bounty
ab124domains.infoURLCriticalNo Bounty
ab124domains.netURLCriticalNo Bounty
abacusdatamanagement.comURLCriticalNo Bounty
abacusint.comURLCriticalNo Bounty
abacusint.infoURLCriticalNo Bounty
abacusvalue.co.ukURLCriticalNo Bounty
abacusvalue.comURLCriticalNo Bounty
aboutaxspa.caURLCriticalNo Bounty
aboutproquest.comURLCriticalNo Bounty
aboutproquest.netURLCriticalNo Bounty
academic-e-books.comURLCriticalNo Bounty
academichelp.comURLCriticalNo Bounty
academicvideoonline.comURLCriticalNo Bounty
academicvideostore.comURLCriticalNo Bounty
accelanation.comURLCriticalNo Bounty
acceleratingthepaceofinnovation.comURLCriticalNo Bounty
accesspolaris.comURLCriticalNo Bounty
acetheclass.comURLCriticalNo Bounty
acetheclass.netURLCriticalNo Bounty
acetheclass.orgURLCriticalNo Bounty
acethecourse.comURLCriticalNo Bounty
acethecourse.netURLCriticalNo Bounty
acethecourse.orgURLCriticalNo Bounty
aclasta.caURLCriticalNo Bounty
activatenetwork.netURLCriticalNo Bounty
activatenetworks.netURLCriticalNo Bounty

Showing 50 of 5027 in-scope assets. View all on HackerOne.

Out-of-Scope Assets

  • bigstockphoto.fr
  • ofcourse.com

Tips for Hacking Clarivate

  1. Read the policy — Understand what's in scope, out of scope, and any specific testing restrictions before you start.
  2. Enumerate the attack surface — Use subdomain enumeration and directory bruteforcing to map all accessible endpoints.
  3. Focus on high-impact bugs — Look for SQL injection, SSRF, and IDOR vulnerabilities first.
  4. Test authentication flows — Check for OAuth misconfigurations and CSRF in login/signup flows.
  5. Write clear reports — Include steps to reproduce, impact assessment, and suggested remediation. Use Burp Suite to capture evidence.

Frequently Asked Questions

How do I start hacking Clarivate?

Sign up on HackerOne, read the program policy carefully, review the in-scope assets listed above, and start testing. Always stay within scope and follow responsible disclosure guidelines.

Does Clarivate pay bounties?

No, Clarivate runs a Vulnerability Disclosure Program (VDP) without monetary rewards. You may receive recognition or swag.

What types of vulnerabilities does Clarivate accept?

Clarivate accepts reports for vulnerabilities found in their 5027 in-scope assets. Common accepted vulnerability types include XSS, SQL injection, SSRF, IDOR, authentication bypass, and RCE. Check the program policy for specific exclusions.