Product · free template

Bug Bounty Report Form

Structured vulnerability disclosure form for security researchers, covering severity, reproduction steps and impact.

A ready-to-use technology, saas & dev form for engineering, IT and product teams: 12 questions, 2 pages, 3 conditional rules.

Questions
12
Pages
2
Layouts
classic · card
Conditional rules
3
Typical time
8 min
Preview it in the gallery

Searches this template answers

Also filed under

Live preview and test console

This is the real form. Answer it to test the 2 conditional rules — nothing is sent or stored.

Page 1 of 2Vulnerability details

Report a vulnerability

Attach a file up to 10 MB.

Any file type up to 10.0 MB (larger files are rejected) · uploads are saved on the live form

1 question is hidden by conditional logic right now — change an answer above to reveal it.

What happens after submit: nothing is stored in this preview. On your own copy, every response triggers an instant email notification and lands in your response dashboard, ready to export or forward.

Happy with it? Take a copy into your workspace — every question, rule and setting comes with it.

Who this template is for

Bug Bounty Report Form is built for engineering, IT and product teams who need to route technical requests with the context needed to triage them.

  • Engineering, IT and product teams working in technology, saas & dev.
  • Teams who need to route technical requests with the context needed to triage them without writing code or paying for a custom build.
  • Anyone replacing vague reports that can't be reproduced or prioritised with one structured record per enquiry.
  • Respondents are users, testers and internal stakeholders — the form asks them 12 questions across 2 screens.
  • Mobile-heavy audiences, thanks to the one-question-per-screen card layout.

Why this form is useful

It removes the cost of vague reports that can't be reproduced or prioritised and turns each submission into a record your team can act on immediately.

  • 8 questions are required, so submissions arrive complete instead of needing a follow-up email.
  • It collects a verified email address so replies and confirmations land.
  • It accepts a document or photo upload as evidence.
  • It allows multiple selections without free text.
  • Conditional logic hides 3 questions until they are relevant — shorter forms convert better than long ones.
  • Splitting the form across 2 pages keeps each screen short and shows respondents how much is left.
  • Every response is stored, searchable and exportable, so nothing depends on one person's inbox.

How to use this template

From copy to live form is a few minutes of work, and every step is reversible.

  1. 1Press “Use this template” — a fresh copy of Bug Bounty Report Form lands in your workspace, ready to edit.
  2. 2Rename or delete any question, and change what is required. Nothing here is fixed.
  3. 3Open Notifications and add the email addresses that should be alerted on each submission; add an auto-reply to the respondent if the form collects an email address.
  4. 4Check the upload limits on the file question so respondents can attach what you actually need.
  5. 5Publish it, then either share the link directly or paste the embed snippet into your site — the embedded form resizes to fit and loads no marketing or advertising trackers.
  6. 6Watch responses land in Submissions, where you can filter, label and export them to CSV or PDF.

Logic and conditions blueprint

Exactly how this form behaves as it is answered — 3 conditional rules ship with it.

  • Features conditional validation: if “Severity (your assessment)” is Critical, “Steps to reproduce” becomes mandatory before the form can be sent.
  • Features advanced show logic: if “Have you already disclosed this publicly?” is Yes, the form dynamically exposes “Where was it disclosed?”. Otherwise that question never appears.
  • Features advanced show logic: if “Vulnerability type” is Other, the form dynamically exposes “Please describe the vulnerability type”. Otherwise that question never appears.
  • All 3 rules are editable in the Logic tab, and the built-in checker warns about rules that contradict each other.

About this template

A bug bounty report is fundamentally different from an ordinary bug report: it needs to establish severity and reproducibility precisely enough that a security team can triage it without a lengthy back-and-forth, and it needs to record researcher details cleanly enough that a reward or acknowledgement can actually be paid out. This form opens by asking the researcher to self-assess severity against a standard scale, which is not the final word on classification but gives triage a starting point. Affected asset and vulnerability type are asked as structured fields, since a security team routing reports by system or by class of bug relies on being able to filter and sort submissions, not read every one in full to categorise it. A step-by-step reproduction field is treated as the most important part of the form, since an unreproducible report — however serious it sounds — cannot be verified or fixed. Proof-of-concept file upload is optional but encouraged, covering screenshots, request logs or scripts. A disclosure-timeline acknowledgement asks the researcher to confirm they'll hold public disclosure until a fix ships, which is standard practice for responsible disclosure programs and protects both the company and its users while a fix is in progress.

What this form asks

Every question is editable — rename it, make it optional, or delete it entirely.

Page 1 — Vulnerability details

  • Affected asset (URL, app, or system)required
  • Vulnerability typerequired
  • Please describe the vulnerability type
  • Severity (your assessment)required
  • Steps to reproducerequired
  • Impact if exploited
  • Proof of concept (screenshot, video or script)

Page 2 — Disclosure & researcher details

  • Have you already disclosed this publicly?required
  • Where was it disclosed?
  • Researcher namerequired
  • Email addressrequired
  • I agree to hold public disclosure until a fix has shippedrequired

12 questions in total.

How the form changes as it's filled in

This template ships with 3 conditional rules, grouped into 3 behaviours driven by 3 questions. Everything below is already set up — edit or delete any rule once the template is in your workspace.

Driven by “Severity (your assessment)

  • Makes answers required

    If “Severity (your assessment)” is Critical, “Steps to reproduce” becomes required before the form can be submitted.

Driven by “Have you already disclosed this publicly?

  • Reveals questions

    If “Have you already disclosed this publicly?” is Yes, the form reveals “Where was it disclosed?”.

Driven by “Vulnerability type

  • Reveals questions

    If “Vulnerability type” is Other, the form reveals “Please describe the vulnerability type”.

Set it up step by step

  1. 1

    Treat reproduction steps as the core of the report

    A severity rating without reliable reproduction steps can't be verified — ask for exact, numbered steps rather than a general description.

  2. 2

    Let researchers self-assess severity, then re-triage internally

    Their initial rating gives triage a useful starting point, but your security team should confirm classification against internal impact before rewarding or closing.

  3. 3

    Require the disclosure agreement before accepting the report

    Confirming a hold on public disclosure protects users while a fix is developed, and it's standard practice across responsible disclosure programs.

  4. 4

    Ask about prior public disclosure directly

    Knowing whether a vulnerability is already public changes your response timeline completely — treat it as an urgent path when the answer is yes.

Mistakes to avoid

  • Accepting reports without reproduction steps and then being unable to verify or fix the issue.
  • Not asking whether the vulnerability has already been disclosed publicly, missing an urgent case.
  • Skipping the researcher's contact details, making it impossible to follow up or issue a reward.

What it pairs with

Most teams don't run this form on its own. These are the forms and systems it sits next to.

What to do with the responses

Triage by severity and reproducibility first, confirm the finding internally, and keep the researcher updated on status even if resolution takes time — that communication is what keeps a bounty program's reputation intact.

Works in both layouts

These pages cover the same subject ground as the bug bounty report form, matched on the words people actually search for.

Frequently asked questions

How is this different from the Software Bug Report or Quick Bug Report templates?

Those are built for ordinary product bugs reported by users or QA — functional issues, not security vulnerabilities. This form adds severity self-assessment, vulnerability classification and a responsible-disclosure agreement that a security-specific intake needs.

Should severity be decided by the researcher's answer?

No — use it as a starting point for triage only. Your security team should independently confirm severity based on internal impact and exploitability before deciding on remediation priority or reward.

Do I need the disclosure agreement checkbox?

Yes, it's standard practice for responsible disclosure programs — it sets a clear expectation that the researcher will hold public disclosure until a fix is live, protecting users in the meantime.

What if the researcher wants to stay anonymous?

You can make the name and email fields optional, but note that anonymous reports usually can't receive a bounty payout or follow-up questions if the reproduction steps are unclear.

Is the Bug Bounty Report Form template free to use?

Yes. You can preview and test Bug Bounty Report Form on this page without an account, and take a copy into your own HelloForms workspace on the free plan. There is nothing to install and no card required to publish it.

What does the Bug Bounty Report Form template ask for?

It asks 12 questions across 2 pages, 8 of which are required. Every question is listed in full further down this page, and each one can be renamed, reordered, made optional or deleted after you copy the template.

Can I edit the Bug Bounty Report Form form after copying it?

Yes — the copy is entirely yours. Change wording, add or remove questions, switch between the classic and card layouts, restyle it to match your brand, and set who gets notified on each submission.

How does the conditional logic in this technology, saas & dev form work?

3 conditional rules ship with the template: Features conditional validation: if “Severity (your assessment)” is Critical, “Steps to reproduce” becomes mandatory before the form can be sent. Features advanced show logic: if “Have you already disclosed this publicly?” is Yes, the form dynamically exposes “Where was it disclosed?”. Otherwise that question never appears. Features advanced show logic: if “Vulnerability type” is Other, the form dynamically exposes “Please describe the vulnerability type”. Otherwise that question never appears. All rules are editable in the Logic tab.

Where do responses to the Bug Bounty Report Form form go?

Submissions land in your workspace under Submissions, where you can search, filter, label and export them to CSV or PDF. You can also email a notification to your team on every submission and send the respondent an auto-reply.

Can I embed the Bug Bounty Report Form form on my own website?

Yes. Publish the form and paste the embed snippet into any page or share the direct link. The embedded form resizes to fit its container and loads no advertising or marketing trackers inside the iframe.

Can respondents upload files?

Yes. This template includes a file upload question, so respondents can attach documents or photos with their answers. You can adjust the accepted file types and size limits on that question.

More forms teams pair with the bug bounty report form.

Related categories