The notoriety board is back — but with a tighter scope. I genuinely enjoy this part of the web and want to celebrate legitimate findings. Please read the scope below before submitting.
As a small company, Westbury Digital isn't in a position to offer financial remuneration. However, I genuinely welcome responsible disclosure and value the effort that goes into finding real issues.
Genuine, exploitable vulnerabilities with a demonstrable attack path. Examples: XSS with real impact, authentication or authorisation bypasses, SQL injection, sensitive data exposure, or similar issues where you can show meaningful harm.
The following will not be accepted or acknowledged:
Latest from the blog
Setting up SSL on my home network led to an uncomfortable realisation: the padlock shows you where encryption starts, not where it ends. That distinction matters more than most people think
2026-05-15
Read post →A place on the board. Any verified, in-scope finding gets your name or handle listed here with the vulnerability and its potential impact.
| CVSS | Name / Handle | Vulnerability | Potential Impact |
|---|---|---|---|
| 3.5 | Alan Jose | Host Header Injection | Crash Online Store |
| 6.1 [CVE-2022-38796] | Nilesh Agrawal Koyo | Prototype Pollution Attack | Serverside misdirection if incorrectly referenced |
What's CVSS? An open industry standard for scoring vulnerability severity from 1–10.
Use the submission form to report a finding. You'll receive a tracking ID so you can check the status of your submission.
Submit a FindingAlready submitted? Track your submission with your ID.