← The brief
01 · The record
03 · The programme
Published finding · Bugcrowd
JLL Vulnerability Disclosure Engagement A finding accepted against *.jllt.com. Bugcrowd published no award figure for it.
Everything Bugcrowd published about this
- Programme
- JLL Vulnerability Disclosure Engagement Not in our directory yet, so there is no grade or review page for it. The event is kept regardless.
- Platform handle
- jll-vdp-pro
- Asset
- *.jllt.com The specific asset the finding landed against, as the platform named it.
- Severity
- medium Bugcrowd rates P1–P5; this is that rating in HackerOne's words so the two feeds can sit in one table.
- Award
- Not published This does not mean nothing was paid. Both platforms let a programme accept a finding without publishing the figure, and most do.
- Found by
- Withheld The platform did not publish a name. We store that as withheld and never guess.
- State
- unresolved — accepted, not yet fixed
- Accepted
- 12 August 2026 2 months ago. This is the date the programme accepted the finding.
- First seen here
- 13 August 2026 When our sweep first read this entry. It says nothing about the finding, only about us.
- Platform reference
- 4792b9cb-afde-40a7-ae16-46040e96a138
What else JLL Vulnerability Disclosure Engagement has published
- *.jll.com critical · resolved · Yash008 · 1 month ago —
- *.corrigopro-qa.com critical · unresolved · Wolfareen · 1 month ago —
- *.jll.com medium · unresolved · YTrineshReddy · 2 months ago —
Where this came from. One row of a public platform feed, stored as published and never edited. We hold no report title, no write-up and no reproduction steps, because the feeds do not carry them and we do not go looking for them. A withheld name stays withheld; if a finder later asks the platform to un-name them, the next sweep un-names them here. Absence of an award figure is publication policy, not evidence a programme did not pay.