5273 | Multiple Open URL Redirection Vulnerability on Facebook worth $1500 |
Open redirect |
Meta / Facebook |
Arul Kumar (@ArulVaiyapuri) |
Bug Bounty | 2022-08-05 | 2023-06-13 |
5272 | Delete any Photo from Facebook by Exploiting Support Dashboard - $12,500 Bug |
IDOR |
Meta / Facebook |
Arul Kumar (@ArulVaiyapuri) |
Bug Bounty | 2013-09-01 | 2023-06-13 |
5190 | Command injection which got me "6000$" from #Google |
OS command injection |
Google |
Venkatesh Sivakumar (@pranavvenkats) |
Bug Bounty | 2016-03-15 | 2023-06-13 |
5117 | IDOR in Facebook%27s Acquisition (Parse) |
IDOR |
Meta / Facebook |
Venkatesh Sivakumar (@pranavvenkats) |
Bug Bounty | 2016-12-11 | 2023-06-13 |
4567 | [XSS] survey.dropbox.com |
XSS |
Dropbox |
Kumar |
Bug Bounty | 2018-09-25 | 2023-06-13 |
4553 | Facebook Bug Bounty: Email Id, Phone Number Can be exposed Through Business Manager |
Logic flaw
Information disclosure |
Meta / Facebook |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2018-10-03 | 2023-06-13 |
4522 | A possibility of Account Takeover in Medium |
Account takeover
Logic flaw |
Medium |
Prashant Kumar (@notsoshant) |
Bug Bounty | 2018-10-20 | 2023-06-13 |
4487 | Object name Exposure — ING Bank Responsible Disclosure Program |
Information disclosure |
ING Bank |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2018-11-08 | 2023-06-13 |
4475 | Facebook Vulnerability: Hiding from the view of Business Admin in the Business Manager |
Logic flaw
Authorization flaw |
Meta / Facebook |
Ritish Kumar Singh |
Bug Bounty | 2018-11-15 | 2023-06-13 |
4390 | How I Was Able To Takeover All User Account And Admin Panel |
IDOR
Account takeover |
NA |
Dipak kumar Das (@d1pakdas) |
Bug Bounty | 2018-12-28 | 2023-06-13 |
4363 | Facebook Vulnerability: Unremovable facebook group admin |
Logic flaw |
Meta / Facebook |
Ritish Kumar Singh |
Bug Bounty | 2019-01-15 | 2023-06-13 |
4336 | A short tale of Account verification bypass |
Email verification bypass
Authorization flaw |
NA |
Satyendra Kumar |
Bug Bounty | 2019-01-27 | 2023-06-13 |
4298 | Facebook/Workplace Bug Exposed Offsite Employee Events, Sensitive emails Putting Employees at Risk |
Information disclosure |
Meta / Facebook |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2019-02-16 | 2023-06-13 |
4295 | Stored XSS on Edmodo |
Stored XSS |
Edmodo |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2019-02-18 | 2023-06-13 |
4250 | User Account Takeover [Password Change]— Nice Catch! |
Account takeover
Password reset |
NA |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2019-03-14 | 2023-06-13 |
4246 | Disclosure of Pending Roles for any Facebook Page |
IDOR |
Meta / Facebook |
Avinash Kumar (@itsavinash_) |
Bug Bounty | 2019-03-16 | 2023-06-13 |
4224 | Facebook Vulnerability: Hiding from Facebook Page Admin(s) in /hacked workflow |
Logic flaw |
Meta / Facebook |
Ritish Kumar Singh |
Bug Bounty | 2019-04-02 | 2023-06-13 |
4114 | Facebook Vulnerability: Non-unfriendable user in /hacked workflow |
Logic flaw |
Meta / Facebook |
Ritish Kumar Singh |
Bug Bounty | 2019-06-11 | 2023-06-13 |
4093 | Business user Employees could have applied block list to all ad accounts listed in the business manager. |
Authorization flaw
Logic flaw |
Meta / Facebook |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2019-06-17 | 2023-06-13 |
4090 | Facebook Vulnerability: Unremovable Co-Host in facebook group events |
Logic flaw |
Meta / Facebook |
Ritish Kumar Singh |
Bug Bounty | 2019-06-19 | 2023-06-13 |
4058 | Facebook Vulnerability: Unremovable Co-Host in facebook page events |
Logic flaw
DoS |
Meta / Facebook |
Ritish Kumar Singh |
Bug Bounty | 2019-07-04 | 2023-06-13 |
4035 | CSRF Email Confirmation Vulnerability for Gmail & G-Suite in Facebook |
CSRF |
Meta / Facebook |
Lokesh Kumar (@lokeshdlk77) |
Bug Bounty | 2019-07-16 | 2023-06-13 |
3971 | ByPassing fix of Domain Blocking feature in Business Manager |
Authorization flaw
Logic flaw |
Meta / Facebook |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2019-08-15 | 2023-06-13 |
3957 | From Github Recon To Account Takeover |
Information disclosure
Account takeover |
NA |
Dipak kumar Das (@d1pakdas) |
Bug Bounty | 2019-08-24 | 2023-06-13 |
3934 | Oculus identity verification bypass through brute-force |
OTP bypass
Lack of rate limiting |
Meta / Facebook |
karthik kumar reddy (@karthiksunny007) |
Bug Bounty | 2019-09-09 | 2023-06-13 |