Hi @shirshak55 ,
Did you found a security.txt to help you find the good option ton contact them?
Regards,
Be part of JetBrains PHPverse 2026 on June 9 – a free online event bringing PHP devs worldwide together.
Today i found one Laravel website having serious vulnerability. The website was leaking personal data in one api endpoint and was publicly accessible to other user. Its like the end point needs authentication but they forgot to add authorization. Like I can download other's user passport etc.
I sent them emails, messaged but they never really cares. What would be good solution? And would I be in trouble in future because i reported it to them?
Thanks.
Please or to participate in this conversation.