5189 | Uber Bug Bounty: Turning Self-XSS into Good-XSS |
XSS |
Uber |
Jack Whitton (@fin1te) |
Bug Bounty | 2016-03-22 | 2023-06-13 |
5145 | Turning Self-XSS into Good XSS v2: Challenge Completed but Not Rewarded |
XSS |
Uber |
- |
Bug Bounty | 2016-08-29 | 2023-06-13 |
4981 | Chaining Self XSS with UI Redressing is Leading to Session Hijacking (PWN users like a boss) |
Self-XSS
Clickjacking |
NA |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2017-09-18 | 2023-06-13 |
4789 | Turning Self-XSS into non-Self Stored-XSS via Authorization Issue at “PayPal Tech-Support and Brand Central Portal |
Stored XSS |
Paypal |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2018-04-21 | 2023-06-13 |
4759 | Self-XSS + CSRF to Stored XSS |
Self-XSS
CSRF
Stored XSS |
NA |
Renwa (@RenwaX23) |
Bug Bounty | 2018-05-20 | 2023-06-13 |
4367 | Turning Self XSS to good XSS via access control |
Stored XSS
Self-XSS |
NA |
Yusuf Yazir (@Hacklad) |
Bug Bounty | 2019-01-13 | 2023-06-13 |
3988 | self XSS to stored XSS [ think out the box] |
Self-XSS
Stored XSS |
TIBCO |
Abdelhak Kharroubi |
Bug Bounty | 2019-08-06 | 2023-06-13 |
3812 | The AccountTakeOver Killing Chain |
Account takeover
CSRF
Self-XSS |
NA |
أنس روبي (@xhzeem) |
Bug Bounty | 2019-11-23 | 2023-06-13 |
3803 | How I turned Self XSS to Stored via CSRF |
Self-XSS
CSRF |
NA |
Abhishek Yadav (@abhishake100) |
Bug Bounty | 2019-11-29 | 2023-06-13 |
3747 | Exploiting a Self Stored XSS with an IDOR |
Self-XSS
Stored XSS
IDOR |
NA |
Shuaib Oladigbolu (@_sawzeeyy) |
Bug Bounty | 2019-12-31 | 2023-06-13 |
3659 | My First Bounty From Google. |
Self-XSS
HTML injection |
Google |
Syahri Ramadan (@adonkidz7) |
Bug Bounty | 2020-02-18 | 2023-06-13 |
3624 | Google Ads Self-XSS & Html Injection $5000 |
Self-XSS
HTML injection |
Google |
Syahri Ramadan (@adonkidz7) |
Bug Bounty | 2020-03-07 | 2023-06-13 |
3566 | Always escalate! From Self-XSS to Persistent XSS on Login Portal |
Self-XSS
CSRF |
NA |
Phuriphat Boontanon (@zanezenzane) |
Bug Bounty | 2020-04-02 | 2023-06-13 |
3533 | From P5 to P2, from nothing to 1000+$ |
Race condition
Self-XSS
Blind XSS |
NA |
Mohamed Daher (@DaherMohamed4) |
Bug Bounty | 2020-04-22 | 2023-06-13 |
3432 | How I leveraged an interesting CSRF vulnerability to turn self XSS into a persistent attack? |
Self-XSS
CSRF |
NA |
Akash Methani (@0xAkash) |
Bug Bounty | 2020-06-01 | 2023-06-13 |
2982 | Story of the best vulnerability I’ve found so far… |
Self-XSS
Blind XSS
Account takeover |
NA |
Vedant Tekale (@_justYnot) |
Bug Bounty | 2020-12-07 | 2023-06-13 |
2951 | Cookie Tossing to RCE on Google Cloud JupyterLab |
Self-XSS
DoS
CSRF
RCE |
Google |
s1r1us (@s1r1u5_) |
Bug Bounty | 2020-12-23 | 2023-06-13 |
2869 | Chaining a self XSS to Account Takeover |
Self-XSS
Reflected XSS
Account takeover |
NA |
Arman Sameer (@ArmanSameer95) |
Bug Bounty | 2021-01-25 | 2023-06-13 |
2825 | Self-XSS to rXSS via Uploaded File Name |
Self-XSS
Reflected XSS |
NA |
P4nda (@InfoSecP4nda) |
Bug Bounty | 2021-02-09 | 2023-06-13 |
2394 | Escalating Self-XSS To Stored XSS via Image injection + IDOR |
Self-XSS
Stored XSS
IDOR |
NA |
Demon (@R29k_) |
Bug Bounty | 2021-07-21 | 2023-06-13 |
2364 | How I escalate my Self-Stored XSS to Account Takeover with the help of IDOR |
Self-XSS
IDOR
Account takeover |
HackerEarth |
Jefferson Gonzales (@gonzxph) |
Bug Bounty | 2021-07-31 | 2023-06-13 |
2264 | chaining bugs from self XSS to account takeover |
Self-XSS
WAF bypass
CSRF
Account takeover |
NA |
Behnam Yazdanpanah (@abhiunix) |
Bug Bounty | 2021-09-02 | 2023-06-13 |
2030 | AWS SageMaker Jupyter Notebook Instance Takeover |
Self-XSS
CSRF
RCE |
AWS |
Gafnit Amiga (@gafnitav) |
Bug Bounty | 2021-12-02 | 2023-06-13 |
1860 | My first bounty, IDOR + Self XSS [€3000] |
Self-XSS
IDOR |
Intigriti |
Ladecruze (@ladecruze) |
Bug Bounty | 2022-02-02 | 2023-06-13 |
1823 | How i made 15k$ from Remote Code Execution Vulnerability |
Code injection
RCE
Self-XSS |
NA |
Abdulrahman Makki (@AMakki1337) |
Bug Bounty | 2022-02-13 | 2023-06-13 |