Work at The Plugin People? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 3 Oct 2026.
We are a development company with products for Atlassian Jira and Confluence, this bounty is focused ONLY on our apps and NOT Atlassian platform or supporting systems, check the scope below: In Scope Systems and Services In Scope rewards are for vulnerabilities found in our apps or caused by our apps: Cloud apps A self hosted Atlassian Jira Data Center instance with ANY of our published Cloud apps that are not EOL: [Cloud] Enterprise Mail Handler for Jira Cloud (JEMHC) [Cloud] Custom Space User Management (CSUMC) for DC and Cloud Data Center apps A self hosted Atlassian Jira Data Center instance with ANY of our published Data Center apps that are not EOL: [DC] Enterprise Mail Handler (JEMH) for Jira [DC] Custom Space User Management (CSUM) for Confluence [DC] Latex for Confluence [DC] Switch User (SU) for Confluence [DC] Switch User (SU) for Jira Out Of Scope Atlassian Systems and Services *ALL 3rd party systems including Atlassian services * are *NOT * in scope here and will be rejected. Vulnerabilities in such platforms should be logged with Atlassian via https://bugcrowd.com/atlassian Examples of out of scope systems: marketplace.atlassian.com id.atlassian.com team.atlassian.com admin.atlassian.com my.atlassian.com Targets: We have targets for each of our in scope apps, deployed to DataCenter and Cloud. Please pick targets when logging reports! Ratings/Rewards: For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.
Scope
7 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| [Cloud] Custom Space User Management (CSUM) for Confluence Cloud | website | ✓ bounty | not set |
| [Cloud] Enterprise Mail Handler (JEMHC) for Jira Cloud | website | ✓ bounty | not set |
| [DC] Custom Space User Management (CSUM) | website | ✓ bounty | not set |
| [DC] Enterprise Mail Handler (JEMH) for Jira | website | ✓ bounty | not set |
| [DC] Latex for Confluence | website | ✓ bounty | not set |
Show all 7 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| [DC] Switch User (SU) for Confluence | website | ✓ bounty | not set |
| [DC] Switch User (SU) for Jira | website | ✓ bounty | not set |