Work at Council on Foreign Relations? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 19 Sep 2026.
Company Overview The Council on Foreign Relations invites you to test their websites https://cfr.org and https://foreignaffairs.com! About CFR - The Council on Foreign Relations (CFR) is an independent, nonpartisan membership organization, think tank, and publisher dedicated to being a resource for its members, government officials, business executives, journalists, educators and students, civic and religious leaders, and other interested citizens in order to help them better understand the world and the foreign policy choices facing the United States and other countries. Founded in 1921, CFR takes no institutional positions on matters of policy. This program adheres to the Bugcrowd Vulnerability Rating Taxonomy for the prioritization/rating of findings.
Scope
7 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| ████████████████████ | website | ✓ bounty | not set |
| ██████████████████████████ | website | ✓ bounty | not set |
| █████████████████████████████ | website | ✓ bounty | not set |
| █████████████████████████ | website | out | not set |
| ██████████████████████████████ | website | out | not set |
Show all 7 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| ███████████████████████████████ | website | out | not set |
| █████████████████████████████████████ | website | out | not set |