5295 | GraphQL exploitation – All you need to know |
GraphQL Exploitation |
OSCP |
Theo |
CheatSheet | 2023-05-16 | 2024-01-31 |
4834 | GraphQL abuse: Bypass account level permissions through parameter smuggling |
GraphQL
Privilege escalation |
New Relic |
Jon Bottarini (@jon_bottarini) |
Bug Bounty | 2018-03-14 | 2023-06-13 |
4042 | [TOKOPEDIA] Site-wide CSRF through GraphQL request |
CSRF |
Tokopedia |
Rafie Muhammad (@rafiem777) |
Bug Bounty | 2019-07-15 | 2023-06-13 |
3947 | Graphql Bug to Steal Anyone’s Address |
Information disclosure
GraphQL |
NA |
Pratik Yadav (@PratikY9967) |
Bug Bounty | 2019-09-01 | 2023-06-13 |
3891 | GraphQL Introspection leads to Sensitive Data Disclosure. |
Information disclosure |
NA |
Pranay Bafna |
Bug Bounty | 2019-10-02 | 2023-06-13 |
3856 | GraphQL introspection leads to sensitive data disclosure. |
Information disclosure |
NA |
Eshan Singh (@R0X4R) |
Bug Bounty | 2019-10-30 | 2023-06-13 |
3763 | GraphQL IDOR leads to information disclosure |
IDOR |
NA |
Eshan Singh (@R0X4R) |
Bug Bounty | 2019-12-24 | 2023-06-13 |
3300 | How I lost my followers on Medium |
GraphQL
Authorization flaw |
Medium |
Florian (@fh4ntke) |
Bug Bounty | 2020-07-17 | 2023-06-13 |
3017 | GraphQL IDOR in Facebook streamer dashboard. |
IDOR
GraphQL |
Meta / Facebook |
Kailash (@Corrupted_brain) |
Bug Bounty | 2020-11-18 | 2023-06-13 |
2846 | Access developer tasks list of any Facebook Application (GraphQL IDOR) |
IDOR |
Meta / Facebook |
Amine Aboud (@amineaboud) |
Bug Bounty | 2021-02-01 | 2023-06-13 |
2762 | Somebody Call The Plumber, GraphQL is Leaking Again… |
Information disclosure
GraphQL |
NA |
N0ur5 |
Bug Bounty | 2021-02-27 | 2023-06-13 |
2757 | Somebody Call The Plumber, GraphQL is Leaking Again… |
Information disclosure
GraphQL |
NA |
N0ur5 |
Bug Bounty | 2021-02-28 | 2023-06-13 |
2717 | De-anonymize the members of a private Facebook Group as a non-member. |
GraphQL
Information disclosure |
Meta / Facebook |
Baibhav Anand (@SpongeBhav) |
Bug Bounty | 2021-03-15 | 2023-06-13 |
2637 | (POC) Update business fyi message as Facebook page analyst |
IDOR
GraphQL |
Meta / Facebook |
Ahmad Talahmeh |
Bug Bounty | 2021-04-17 | 2023-06-13 |
2631 | Pwning your assignments: Stored XSS via GraphQL endpoint |
Stored XSS
GraphQL |
NA |
Kartik Sharma (@dominat0r98) |
Bug Bounty | 2021-04-18 | 2023-06-13 |
2530 | Disclose leads form details of any Facebook Business Account or Facebook Page (Bug Bounty) |
IDOR
GraphQL |
Meta / Facebook |
Amine Aboud (@amineaboud) |
Bug Bounty | 2021-05-23 | 2023-06-13 |
2478 | This is how I was able to see Private, Archived Posts/Stories of users on Instagram without following them |
IDOR
GraphQL |
NA |
Mayur Fartade (@mayurfartade) |
Bug Bounty | 2021-06-15 | 2023-06-13 |
2295 | Retrieve Archived Stories Of Any Public Instagram Account. |
IDOR
GraphQL |
Meta / Facebook |
Naveen |
Bug Bounty | 2021-08-25 | 2023-06-13 |
2256 | IDOR Vulnerability In GraphQL Api On Website |
IDOR
GraphQL |
NA |
Aidil Arief |
Bug Bounty | 2021-09-03 | 2023-06-13 |
2046 | How I got my first bounty on financial sector gateway site by using Previous GraphQL vulnerabilities. |
Information disclosure
GraphQL |
NA |
Night Hawk |
Bug Bounty | 2021-11-26 | 2023-06-13 |
2028 | Disclose Ad Accounts linked with Instagram Accounts |
Information disclosure
Logic flaw
GraphQL |
Meta / Facebook |
Naveen (@NaveenHax) |
Bug Bounty | 2021-12-02 | 2023-06-13 |
1766 | CVE-2021-4191: GitLab GraphQL API User Enumeration (FIXED) |
Username enumeration
GraphQL |
GitLab |
Jacob Baines (@junior_baines) |
Bug Bounty | 2022-03-03 | 2023-06-13 |
1167 | The Million Dollar IDOR |
IDOR
Race condition
GraphQL |
NA |
Monish Basaniwal |
Bug Bounty | 2022-08-27 | 2023-06-13 |
1059 | Apollo Router Security Audit Report (Q2 2022) |
DoS
CSRF |
Apollo GraphQL |
Norbert Szetei (@73696e65) |
Bug Bounty | 2022-09-20 | 2023-06-13 |
985 | The easiest bug to get a Hall of fame from a Billion dollar company. |
GraphQL
Information disclosure |
GeHealthcare |
Ravaan |
Bug Bounty | 2022-10-10 | 2023-06-13 |