Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
Meetical
Meetical Bugcrowd $100–$1,500
3 more reviews needed for a grade
Write a review Claim this company profile

Work at Meetical? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Reviews

0 published

No reviews yet.

Be the first to review

Program profile Bugcrowd · imported

Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 1 Oct 2026.

This bounty is part of the Atlassian Marketplace Bounty Program Meetical helps companies to put effective meetings into practice. We automate manual and repetitive work necessary to plan, execute and document meetings. Instead of introducing all new tools, Meetical focuses on integrating with apps you already love and work with daily: Your Calendar and Atlassian Confluence. Get Started (tl;dr version) Do not access, impact, destroy or otherwise negatively impact Meetical or Atlassian customers, or customer data in any way. Do not test or join beta features. Ensure that you use your @bugcrowdninja.com email address. Ensure you understand the targets, scopes, exclusions, and rules below. Please note that the application listed in the target is in scope. The URL (the Marketplace page) itself is NOT. TLDR; Create a new Confluence DEV Instance (free up to 5 users) Contact support@meetical.io so they install the staging version of the app onto your instance – DO NOT USE THE PROD VERSION FROM MARKETPLACE Navigate to "Apps" -> "Meetings" in the Confluence Top Menu Use a Test Gmail or Outlook/Microsoft365 Account to Log in and Set Up your Account Explore the App, find security issues, and have fun! Info about the product Meetical for Confluence Cloud App on the official Marketplace Focus Areas Below is a list of some of the vulnerability classes that we are seeking reports for: Cross Instance Data Leakage/Access** Server-side Remote Code Execution (RCE) Server-Side Request Forgery (SSRF) Stored/Reflected Cross-site Scripting (XSS) Cross-site Request Forgery (CSRF) SQL Injection (SQLi) XML External Entity Attacks (XXE) Access Control Vulnerabilities (Insecure Direct Object Reference issues, etc) Path/Directory Traversal Issues Ensure you review the out of scope and exclusions list for further details. ** Cross Instance Data Leakage/Access refers to unauthorized data access between instances. Ratings/Rewards: For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority. Please see below for deviations.

Currency
USD
Submissions
Open
Launched
Sep 2020
Scope entries
4 Bugcrowd’s count

Scope

3 assets
AssetTypeEligibilityMax severity
Easy Calendar for Jira (Forge App) - https://marketplace.atlassian.com/apps/1229489/easy-calendar-integration-for-jira-sync-issues-ics-export?hosting=cloud other ✓ bounty not set
For reporting purposes only. Use staging environment listed in brief. website ✓ bounty not set
Meetical for Confluence Cloud - https://marketplace.atlassian.com/apps/1222405/meetical-for-confluence-cloud?hosting=cloud website ✓ bounty not set

Bugcrowd lists 4 scope entries; its public listing groups many assets under one label, so identical entries are shown once.