Welcome

Welcome @ your-website-is-vulnerable. This website is dedicated to protect security experts against people who get angry when you are telling them that their website is vulnerable.

I'm a security expert and always want to know if the website I'm using (and I'm submitting personal data to) is safe. Most of the time when I report security issues it is really appreciated and solved very quickly.

But... One time I found an issue where changing url parameters allowed me to see other customer information including mobile number and phonenumbers. If I can do this, everyone could and I reported this issue to the website owner with the understanding that the vulnerability will be repaired soon.

The website owner called me a hacker and denied me further access to their website (as if that will solve the problem) and treatened to report this issue to the authorities. First of all, this is no hacking because a website is public and changing url parameters can be done by everyone. Second they should appreciate that I'm pointing them this issue and not someone else who could have exploited this issue.

This website is dedicated to security experts and they can inform us about vulnerabilities and we will protect them. This way we can make the internet a bit more secure. Without being afraid of being reported as a hacker.