Work at Quizlet? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 4 Oct 2026.
Quizlet is the world's largest student and teacher online learning community. Every month, over 30 million active learners from 130 countries practice and master more than 200 million study sets of content on every conceivable subject and topic. Our mission is simple: To help students (and their teachers) practice and master whatever they are learning. Quizlet provides engaging, customizable activities with contributions from people everywhere. Quizlet invites you to test and help secure our primary publicly facing assets—focusing on our web, mobile, and API applications. We appreciate your efforts and hard work in making the internet (and Quizlet) more secure and look forward to working with the researcher community to create a meaningful and successful bug bounty program. Good luck and happy hunting! Please note: Quizlet is an educational platform, not an assessment platform for cheating or academic dishonesty. As such, submissions related to cheating mechanisms within our gaming features, testing functionality, or attempts to manipulate user interactions to gain an unfair advantage will not be considered in scope. Similarly, issues such as rate limiting, scraping of publicly available content, or automation concerns are out of scope unless they directly pertain to accessing or exploiting premium content or introduce a significant security impact. Rewards/Ratings For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.
Scope
7 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| 3.0 API | api | ✓ bounty | not set |
| https://*.quizlet.com | website | ✓ bounty | not set |
| Quizlet Android App | android | ✓ bounty | not set |
| Quizlet iOS App | ios | ✓ bounty | not set |
| api.quizlet.com/2.0 | api | out | not set |
Show all 7 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| get.quizlet.com | website | out | not set |
| help.quizlet.com (zendesk) | website | out | not set |