Report a Security Issue
If you have found a security vulnerability on winiba.com, please tell us. We review every legitimate report and aim to fix confirmed issues quickly.
Last updated: October 2026How we protect the store
Encrypted connection
winiba.com is served over HTTPS with SSL/TLS encryption.
PCI DSS compliant payments
Payments are processed by Stripe and PayPal. Winiba does not store card data.
Ground rules
If you follow these principles when reporting an issue, we will not take legal action against you in response to your report. We ask that you:
- give us reasonable time to review and fix the issue before disclosing it to anyone else;
- do not access or interact with accounts without the owner’s consent;
- make a good-faith effort to avoid privacy violations, service disruption and data destruction;
- do not exploit the issue, including to demonstrate further risk or to access customer data;
- comply with all applicable laws.
Bounty program
We may reward researchers who help protect the store. Bounties are awarded at our discretion, based on risk, impact and report quality. To be considered you must:
- follow the ground rules above;
- report a valid bug that poses a real risk to privacy or security;
- email contact@winiba.com with the subject line Security Vulnerability Report, and not contact team members individually;
- disclose any accidental privacy violation or disruption in your first report;
- keep the report confidential until the issue is fixed.
Scope
In scope
- The winiba.com website and storefront
- Customer account and login systems
- Checkout and payment redirection
- Order management and personal data handling
Out of scope
- Third-party plugins, CDNs and services outside our control
- Denial-of-service (DoS/DDoS) attacks
- Social engineering, spam and phishing
- Physical security of our premises
Rewards
Rewards reflect impact and severity. Reports must include clear, reproducible steps; issues we cannot reproduce are not eligible. The first valid report of an issue receives the bounty, and several bugs with one root cause count as one report.
| Severity | Reward | Examples |
|---|---|---|
| Critical | $200 | Remote code execution, vertical authentication bypass, SQL injection exposing sensitive data, full account or database takeover |
| High | $100 | Lateral authentication bypass, disclosure of sensitive internal data, stored XSS affecting other users, local file inclusion |
| Medium | $50 | Business logic flaws, insecure direct object references (IDOR) |
| Low | Recognition | Open redirects, reflected XSS, low-sensitivity information leaks |
Report a vulnerability
Email us with the subject line “Security Vulnerability Report”.