Work at Seek.com? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 3 Oct 2026.
No technology is perfect and Seek believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in the Seek platform. Good luck, and happy hunting! Ratings/Rewards: For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority. Program Rules: DO NOT interact or affect existing customers during testing. This includes many things, however it is particularly important that you do not post a job ad!! Denial of Service, Rate Limiting, and other automated attacks are not allowed. Please do NOT use automated tooling when conducting testing on seek.com assets. All testing must be conducted using your @bugcrowdninja.com email ID only. If you fail to use your @Bugcrowdninja.com email ID, you run the risk of getting blocked from accessing seek.com applications. Customer instances are not to be accessed in any way (i.e. no customer data is accessed, customer credentials are not to be used or "verified") If you believe you have found sensitive customer data (e.g., login credentials, API keys etc) or a way to access customer data (i.e. through a vulnerability) report it, but do not attempt to successfully validate if/that it works. Automated vulnerability scanning tools are strictly prohibited. seek.com regularly blocks attacks from users performing suspicious activity. All email addresses belonging to researchers should be your @bugcrowdninja.com. No use of third party vulnerability capturing services (run your own responder/collaborator) Use custom header with Bugcrowd username (X-bugcrowd: username). SEEK welcome receiving submissions from researchers who have found breached credentials. SEEK reserves the right to treat each submission and any option to reward on a case by case basis. Exclusion: Account takeover via pre-registration / account squatting. Cookie flags ie. Secure, HTTPOnly. Volume related issues ie. Brute-force, rate-limiting, denial of service. Social engineering of any kind against seek.com employees or its users. Email configuration ie. SPF, DKIM, DMARC. Error pages ie. verbose error messages, stack traces, invalid status codes. Admin or maintenance pages ie. monitoring system login pages, pages with no sensitive information. Clickjacking ie. missing X-Frame-Options header. Mobile issues that require root access ie. credentials in Android SharedPreferences. Non-sensitive exposed API keys ie. Google Maps, Raygun. Absent or misconfigured HTTP headers ie. Content-Security-Policy, Strict-Transport-Security, X-XSS-Protection, Cache-Control. Configuration that is not directly exploitable ie. weak TLS ciphers, password policy, session expiration, certificate pinning. Vulnerabilities exclusive to outdated, unpatched and unsupported browsers, mobile applications and mobile operating systems.
Scope
9 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| ████████████ | website | ✓ bounty | not set |
| ██████████████ | website | ✓ bounty | not set |
| ███████████████ | website | ✓ bounty | not set |
| █████████████████ | website | ✓ bounty | not set |
| ██████████████████ | website | ✓ bounty | not set |
Show all 9 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| ███████████████████ | website | ✓ bounty | not set |
| █████████████████████ | website | ✓ bounty | not set |
| ███████████████████████████ | website | ✓ bounty | not set |
| ████████████████████████████ | website | ✓ bounty | not set |
Bugcrowd lists 18 scope entries; its public listing groups many assets under one label, so identical entries are shown once.