Louis Vuitton Malletier, commonly known as Louis Vuitton is a French fashion house and luxury goods company founded in 1854 by Louis Vuitton. The label's LV monogram appears on most of its products, ranging from luxury trunks and leather goods to ready-to-wear, shoes, watches, jewellery, accessories, sunglasses and books. Louis Vuitton is one of the world's leading international fashion houses; it sells its products through standalone boutiques, lease departments in high-end department stores, and through the e-commerce section of its website.
Regarding https://[it | fr | us | sg | …].louisvuitton.com, our program is limited to our e-commerce web application and its API. You may hunt on all country locals linked to *.louisvuitton.com (e.g. fr.louisvuitton.com, us.louisvuitton.com, au.louisvuitton.com, ...) but other subdomains are out of the scope of this program. You may refer to the following page which lists our country locals : https://eu.louisvuitton.com/dispatch?noDRP=true.
In addition to the ecommerce scope mentioned above you're welcome to test api.louisvuitton.com and other subdomains of .api.louisvuitton.com*, the rest of .louisvuitton.com* is to be considred as out of scope.
We ask you to respect the scope of our program and to don't hunt outside of it. Should you need to report anything outside of the scope of this program you may do so through our VDP program here https://vdp.louisvuitton.com/.
A common framework is deployed across all our country locals which means that if you find an issue rooted in this framework or shared ressrouces it'll likely be applicable to other country versions. In such a case, these issues won't be considered as systemic and would be closed as duplicate/informative since a single fix at the framework/ressource level will allow us to address it across all country locals.
For other situations the systemic issues rules will be applied as usual.
XSS and similar issues (e.g. open redirect, CSRF, HTMLi) will be considered as non qualifying issues for the time being on *.jsp for https://[it | fr | us | sg | …].louisvuitton.com.
Please adhere to the following rules while performing research on this program:
We are happy to thank everyone who submits valid reports which help us improve our security, however only those that meet the following eligibility requirements may receive a monetary reward:
Reward amounts are based on:
As a complement to the Program’s rules and testing policy :
| Scope Type | Scope Name |
|---|---|
| android_application | https://play.google.com/store/apps/details?id=com.vuitton.android&hl=fr&gl=US |
| api | *.api.louisvuitton.com |
| ios_application | https://apps.apple.com/fr/app/louis-vuitton/id709101942 |
| ios_application | https://apps.apple.com/fr/app/louis-vuitton-city-guide/id1014618396 |
| web_application | https://[it | fr | us | sg | …].louisvuitton.com |
| web_application | https://appgallery.huawei.com/#/app/C102099703?locale=zh_CN&source=appshare&subsource=C102099703 |
| Scope Type | Scope Name |
|---|---|
| undefined | All domains, subdomains or assets not listed in the above list of 'Scopes' must be considered as out of the scope of this program |
| web_application | *.louisvuitton.com |
Firebounty have crawled on 2025-04-01 the program Louis Vuitton Malletier - Public Bug Bounty Program on the platform Yeswehack.
FireBounty © 2015-2025