Work at Just Eat Takeaway.com? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 19 Sep 2026.
Just Eat Takeaway.com values the security of its customers, partners and employees. We invite security researchers to test our public-facing defenses, helping us strengthen our platform. Ratings and rewards: We follow the Bugcrowd Vulnerability Rating Taxonomy for the initial classification of reported issues. This means certain vulnerability types have a capped to maximum level of severity. We may adjust prioritization based on real-world likelihood and business impact to JustEatTakeaway.com ’s platform. Submissions based purely on automated scanning output are generally not accepted unless they uncover a clearly significant issue. If a submission is reprioritized or downgraded, we will provide a detailed explanation and invite the researcher to appeal with further evidence or reasoning. Focus areas: We prioritize actionable vulnerabilities with direct business or operational impact: account takeovers, payment bypasses, customer data disclosure, authentication bypasses, and impactful business logic flaws. Reports must demonstrate clear exploitability, and findings without proper impact explanation may be considered bugs rather than security issues.
Scope
30 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| *.10bis.co.il | website | ✓ bounty | not set |
| *.bistro.sk | website | ✓ bounty | not set |
| *.jet-external.com | website | ✓ bounty | not set |
| *.just-data.io | api | ✓ bounty | not set |
| *.just-eat.ch | website | ✓ bounty | not set |
Show all 30 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| *.just-eat.co.il | website | ✓ bounty | not set |
| *.just-eat.co.uk | website | ✓ bounty | not set |
| *.just-eat.com | website | ✓ bounty | not set |
| *.just-eat.es | website | ✓ bounty | not set |
| *.just-eat.io | api | ✓ bounty | not set |
| *.justeat-int.com | api | ✓ bounty | not set |
| *.justeattakeaway.com | website | ✓ bounty | not set |
| *.lieferando.de | website | ✓ bounty | not set |
| *.pyszne.pl | website | ✓ bounty | not set |
| *.scoober.com | website | ✓ bounty | not set |
| *.skippayments.com | website | ✓ bounty | not set |
| *.skipthedishes.com | website | ✓ bounty | not set |
| *.takeaway.com | website | ✓ bounty | not set |
| *.thuisbezorgd.nl | website | ✓ bounty | not set |
| *.yourdelivery.de | website | ✓ bounty | not set |
| 10bis.co.il ltd. | android | ✓ bounty | not set |
| 10bis.co.il, Ltd | ios | ✓ bounty | not set |
| github.com/justeattakeaway | other | ✓ bounty | not set |
| Just-Eat Holding Limited | android | ✓ bounty | not set |
| Just-Eat.com | ios | ✓ bounty | not set |
| Skip Canada | android | ✓ bounty | not set |
| SkipTheDishes | ios | ✓ bounty | not set |
| Takeaway.com | android | ✓ bounty | not set |
| Takeaway.com Central Core B.V. | ios | ✓ bounty | not set |
| *.business.just-eat.co.uk | website | out | not set |