The YesWeHack Bug Bounty Report 2025

January 14, 2025

The YesWeHack Bug Bounty Report 2025

We’ve learned a lot about CISOs’ priorities and challenges based on conversations with customers and the ‘hacktivity’ of our Bug Bounty platform.

As we celebrate our 10th anniversary, we’ve decided to share what we’ve observed in interviews with customers and hunters, along with tens of thousands of vulnerability reports they’ve resolved over the past 12 months.

Downloadable with a single click, our first-ever annual review of Bug Bounty trends is aimed at both hunters and security teams.

Trends & Insights for CISOs & Hunters

Among other things, it features:

  • The drivers behind growing adoption of crowdsourced security testing worldwide
  • What 2024’s Bug Bounty stats – such as the most common CWEs and highest payouts – tell us about vulnerability trends and the Bug Bounty model
  • Interviews with our heads of triage and customer success management teams
  • Final leaderboards for 2024 and hacking advice from some of our highest performers – including our all-time #1 hunter
  • A recap of a record year for YesWeHack live hacking events
  • And the merits and challenges of leveraging Bug Bounty to secure open source

Download the YesWeHack Bug Bounty Report without needing to enter your email or any other personal details.