Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4967Craft CMS – Why case matters Reflected XSS Content injection Craft CMS Markus Krell (@MarkusKrell) Bug Bounty2017-10-012023-06-13
4883Reflected XSS + Possible Server Side Template Injection in HubSpot CMS ( All Websites Uses HubSpot was affected ) Reflected XSS HubSpot Mohamed Haron (@m7mdharon) Bug Bounty2018-01-242023-06-13
4676Exploitation of Server Side Template Injection with Craft CMS plugin SEOmatic <=3.1.3 [CVE-2018-14716] SSTI SEOmatic CMS plugin Sebastian (ha.cker.info) Bug Bounty2018-07-242023-06-13
4389How I Takeover Wordpress Admin fiiipay.my Account takeover CMS default files FiiiPay Syahrul Akbar Rohmani (@sahruldotid) Bug Bounty2018-12-282023-06-13
3574Limited freemarker ssti to arbitrary liql query and manage lithium cms SSTI NA Mert (@mertistaken) Bug Bounty2020-03-302023-06-13
3362Bypassing file upload filter by source code review in Bolt CMS RCE Unrestricted file upload Path traversal Security code review Bolt CMS Sivanesh Ashok (@sivaneshashok) Bug Bounty2020-06-272023-06-13
2998WonderCMS 3.1.3 - Authenticated RCE & Blind SSRF Vulnerability Blind SSRF RCE WonderCMS Mas Zet (@zetc0de) Bug Bounty2020-11-292023-06-13
2102Multiple Concrete CMS Vulnerabilities ( Part1 – RCE ) RCE Race condition Concrete CMS FORTBRIDGE (@FORTBRIDGE1) Bug Bounty2021-11-052023-06-13
2052Multiple Vulnerabilities In Concrete CMS – Part2 (PrivEsc/SSRF/etc) Privilege escalation SSRF Concrete CMS FORTBRIDGE (@FORTBRIDGE1) Bug Bounty2021-11-252023-06-13
1582Hacking a Bank by Finding a 0day in DotCMS Directory traversal Unrestricted file upload RCE NA Shubham Shah (@infosec_au) Bug Bounty2022-05-032023-06-13
1517DNN CMS Server-Side Request Forgery (CVE-2021-40186) SSRF Security code review DNN (DotNetNuke) Appcheck NG Bug Bounty2022-05-262023-06-13
1023Exploits Explained: 5 Unusual Authentication Bypass Techniques Authentication bypass JWT CMS SSO NA Ozgur Alp (@ozgur_bbh) Bug Bounty2022-09-282023-06-13
345Authentication Bypass Vulnerability in Mura CMS and Masa CMS (CVE-2022-47003 and CVE-2022-47002) Authentication bypass Security code review ColdFusion Mura CMS Masa CMS Brian (@hoyahaxa) Bug Bounty2023-03-062023-06-13
282SSTI leads to RCE on PyroCMS SSTI RCE PyroCMS cupc4k3 Bug Bounty2023-03-202023-06-13
110A deep-dive on Pluck CMS vulnerability CVE-2023-25828 Unrestricted file upload RCE Security code review Pluck CMS Matthew Hogg Bug Bounty2023-05-082023-06-13