Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
Quora
Quora HackerOne
3 more reviews needed for a grade
Write a review Claim this company profile

Work at Quora? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 24 Sep 2026.

What it pays, by severity

Critical amount not published 10 reports
High $2,800 avg 38 reports firm
Medium $417 avg 99 reports firm
Low $175 avg 212 reports firm

$230,000 paid to researchers in total, $5,000 of it in the last 90 days. Lifetime figure as HackerOne prints it: evidence this program has paid, not a promise about any one report.

Intake & responsiveness · last 90 days

Reports received
49
in 90 days
Resolved
387
all time, last one 7 days ago
Participants
330
hunters engaged
Response efficiency
33%
below its own targets, HackerOne’s figure
SLA misses
0
targets missed
Reports received · day by day, last 16 days 49–64
25 Aug 49 reports 24 Sep

Response targets it sets itself

First response
2 days
Triage
5 days
Bounty
30 days
Resolution
30 days

A target the program declared, not a measurement of it being met.

Getting in the door

bounty amounts hidden

Over 35 days (19 snapshots): intake down 18 reports; response efficiency down 27 points.

See how this programme’s report load compares to others →

Reviews

0 published

No reviews yet.

Be the first to review

Who this program credits

351 credited

Researchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.

# Researcher Reputation Recognised / submitted
1 nomi404 852 31 / 67 46%
2 cache-money 455 10 / 12 83%
3 mirzaaghazadeh 446 11 / 28 39%
4 kgadyrka 365 15 / 17 88%
5 find_me_here 220 11 / 28 39%
6 hundredpercent 216 9 / 20 45%
7 crossfire 182 7 / 8 88%
7 mwhx-404 182 8 / 35 23%
9 shreyaschavhan 181 7 / 18 39%
10 bassem_sadaqah 178 4 / 4 100%
11 adhamsadaqah 170 4 / 7 57%
12 bolabolabola 144 4 / 8 50%
13 dvx 143 4 / 6 67%
14 moaazadel219 136 7 / 15 47%
14 moaz219 136 7 / 15 47%
15 securitythinker 130 6 / 10 60%
16 i_am_no__one 124 7 / 14 50%
17 0xnan 123 4 / 4 100%
17 krishnaverma 123 4 / 11 36%
19 0xneutrall 120 5 / 17 29%
20 madguyyy 114 2 / 2 100%
20 root0401disabled 39 2 / 8 25%
21 buggedout 112 2 / 3 67%
22 bornwinnerrr 110 0 / 0
22 joumaaa 110 0 / 0

Showing the top 25 of 351 credited on HackerOne.

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 23 Sep 2026.

A place to share knowledge and better understand the world.

Responsiveness
40% HackerOne’s figure
Swag
No
Currency
USD
Submissions
Open
Launched
Dec 2016
Scope entries
4 HackerOne’s count

Scope

4 assets
AssetTypeEligibilityMax severity
*.quora.com WILDCARD ✓ bounty Critical
com.quora.android GOOGLE PLAY APP ID ✓ bounty Critical
com.quora.app.mobile APPLE STORE APP ID ✓ bounty Critical
http://poe.com URL ✓ bounty Critical