Since the beginning of the year, security researchers have submitted more than 100 valid vulnerability reports to Facebook through its bug bounty program , continuing the upward trend seen in 2014.

The company says that last year, the rate of bug reports increased by 16%, after receiving reports of 17,011 malfunctions affecting the social networking platform and other services in its portfolio.
Of these, 61 entries were confirmed to have a high severity level and have been fixed by developers. The number represents almost 50% more than in 2013.
The total amount of money paid to external researchers amounted to $1.3/€1,150,000, almost half of what Facebook has paid out since the start of its rewards program in 2011.
321 researchers from 65 countries were compensated, averaging $1,788/€1,580. As for the total number of countries from which the reports came, Facebook announced in a blog post on Wednesday that it has now reached 123.
At the top of the list is India, with 196 reports and an average fee of $1,343 / €1,190. Then there is Egypt, with 81 bugs (average fee of $1,220 / €1080), and the US, with 61 vulnerabilities (average fee of $2,470 / €2,186).
The company did not provide any information about the highest fee it paid last year, but said that the “top five amounts of the previous year totaled $256,750 [€227,400].”
Among the top vulnerabilities Facebook has received since 2014 was hidden parameters input, which allowed backend code to receive multiple values for the same parameter, leading to “unintended consequences in subsequent stages.”
Another vulnerability related to Amazon Web Services, which could affect other websites, was a regex error.
