← The brief
01 · The record
03 · The programme
Published finding · Bugcrowd
The Kroger Co - Vulnerability Disclosure Program A finding this programme accepted and published. Bugcrowd published no award figure for it.
Everything Bugcrowd published about this
- Programme
- The Kroger Co - Vulnerability Disclosure Program Not in our directory yet, so there is no grade or review page for it. The event is kept regardless.
- Platform handle
- kroger-vdp
- Asset
- Not published The platform did not name an asset for this entry.
- Severity
- Unrated The platform published no severity for this entry.
- Award
- Not published This does not mean nothing was paid. Both platforms let a programme accept a finding without publishing the figure, and most do.
- Found by
- Withheld The platform did not publish a name. We store that as withheld and never guess.
- State
- resolved — the programme has fixed it
- Accepted
- 31 August 2026 1 month ago. This is the date the programme accepted the finding.
- First seen here
- 1 September 2026 When our sweep first read this entry. It says nothing about the finding, only about us.
- Platform reference
- d9d4cb11-cc86-4425-bff8-9b1937c711ea
What else The Kroger Co - Vulnerability Disclosure Program has published
- *.harristeeter.com medium · unresolved · x3c · 6 days ago —
- *.harristeeter.com medium · unresolved · x3c · 6 days ago —
- *.8451.com medium · unresolved · withheld · 1 month ago —
- *.murrayscheese.com medium · unresolved · b1d0ws · 2 months ago —
Where this came from. One row of a public platform feed, stored as published and never edited. We hold no report title, no write-up and no reproduction steps, because the feeds do not carry them and we do not go looking for them. A withheld name stays withheld; if a finder later asks the platform to un-name them, the next sweep un-names them here. Absence of an award figure is publication policy, not evidence a programme did not pay.