If you'd like to get a sense of the payout you can expect for a certain bug, it's useful to look at both the individual page of the bounty you're participating in and a vulnerability rating system created by Bugcrowd called the Vulnerability Rating Taxonomy (VRT). The VRT (https://bugcrowd.com/vulnerability-rating-taxonomy) is an attempt to systematically assess a vulnerability's severity in a way that provides a common frame of reference for researchers, developers, and managers alike. The VRT is also compatible with another attempt at providing a common threat metric, the Common Vulnerability Scoring System (CVSS)—VRT can be used to calculate CVSS. Understanding the VRT can help you direct your efforts to bugs that will give you the most value for your time.
Writing a bounty that will get you the...