Earlier quoted context omitted.
I found a XSS bug in a popular note taking app. It would allow an attacker to download all the users notes just by having them visit a URL. I reported it on HackerOne, it was only after I refused to post it on their free program that they added me to their paid private one. It was marked as "medium", I got $250 for it.
Do you disagree with the severity? I assess it to have a 6.5 (medium) CVSS score. https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L...
But I think how private that data is to the end user should also be taken into account. It’s a medium for technical risk (relative to server remote exec), but it should be seen as a high priority for the company and rewarded as such.
If an end user were to ask that company “why did you leak all my private data” their response would be “your data is worth less than $250 in human labour and is seen as a medium security risk”?