5178 | Poisoning the Well – Compromising GoDaddy Customer Support With Blind XSS |
Blind XSS |
GoDaddy |
Matthew Bryant (@IAmMandatory) |
Bug Bounty | 2016-05-08 | 2023-06-13 |
5158 | Blind XSS in Spotify%27s Salesforce Integration |
Blind XSS
Salesforce |
Spotify |
Mohammed Diaa (@mhmdiaa) |
Bug Bounty | 2016-07-19 | 2023-06-13 |
5096 | One company: 262 bugs, 100% acceptance, 2.57 priority, millions of user details saved. |
Stored XSS
Blind XSS
CSRF
Account takeover
IDOR |
NA |
Zseano (@zseano) |
Bug Bounty | 2017-02-25 | 2023-06-13 |
5073 | Pivoting from blind SSRF to RCE with HashiCorp Consul |
Blind XSS
RCE |
NA |
Peter Adkins (@darkarnium) |
Bug Bounty | 2017-05-29 | 2023-06-13 |
4937 | How I Pwned a company using IDOR & Blind XSS |
IDOR
Blind XSS |
NA |
Osama Ansari (@AnsariOsama10) |
Bug Bounty | 2017-11-15 | 2023-06-13 |
4877 | How I got 22000$ worth ethereum |
Blind XSS |
NA |
Shubham Gupta (@hackerspider1) |
Bug Bounty | 2018-01-26 | 2023-06-13 |
4823 | How I hacked one cryptocurrency service |
Blind XSS
Reflected XSS
CSRF |
PayKassa |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2018-03-31 | 2023-06-13 |
4808 | Please email me your password |
Blind XSS
Blind SQL injection
SMTP injection
Account takeover |
NA |
Jasmin Laundry (@JR0ch17) |
Bug Bounty | 2018-04-11 | 2023-06-13 |
4748 | Account Takeover and Blind XSS! Go Pro, get Bugs! |
IDOR
Stored XSS
Account takeover
Blind XSS |
NA |
Tabahi (@_tabahi) |
Bug Bounty | 2018-05-30 | 2023-06-13 |
4722 | How i found blind XSS in Apple |
Blind XSS |
Apple |
Taha Smily (@tahakhantaha) |
Bug Bounty | 2018-06-18 | 2023-06-13 |
4692 | WRITE UP – TELEGRAM BUG BOUNTY – WHATSAPP N/A [“Blind” XSS Stored iOS in messengers twins, who really care about your security?] |
Blind XSS |
Meta / Facebook |
Omar Espino (@omespino) |
Bug Bounty | 2018-07-16 | 2023-06-13 |
4661 | Blind-XSS in Chrome Experiments - Google (Write Up) |
Blind XSS |
Google |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2018-08-03 | 2023-06-13 |
4659 | Blind-XSS in Chrome Experiments - Google (Write Up) |
Blind XSS |
Google |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2018-08-03 | 2023-06-13 |
4656 | Self XSS leads to blind XSS and reflected XSS. |
Blind XSS
Reflected XSS |
NA |
Friendly (@SkeletorKeys) |
Bug Bounty | 2018-08-06 | 2023-06-13 |
4568 | Weaponizing XSS Attacking Internal System |
Blind XSS |
NA |
Rahul R |
Bug Bounty | 2018-09-25 | 2023-06-13 |
4531 | [Bug bounty | mail.ru] Access to the admin panel of the partner site and data disclosure of 2 million users |
Authentication bypass
Blind XSS |
Mail.ru |
Max (@iSecMax) |
Bug Bounty | 2018-10-12 | 2023-06-13 |
4471 | HackenProof Customer Story: Uklon |
XSS
IDOR
Blind XSS
Account takeover |
Uklon |
HackenProof (@hackenproof) |
Bug Bounty | 2018-11-16 | 2023-06-13 |
4343 | Antihack.me Blind XSS To PHP File Upload Vulnerability |
Blind XSS |
AntiHack.me |
SayCure (@SaycureIO) |
Bug Bounty | 2019-01-24 | 2023-06-13 |
4291 | Multiple Stored XSS On Tokopedia |
Stored XSS
Blind XSS |
Tokopedia |
apapedulimu / Nosa Shandy (@LocalHost31337) |
Bug Bounty | 2019-02-19 | 2023-06-13 |
4256 | How I found Blind XSS Vulnerability in redacted.com |
Blind XSS |
NA |
ssid (@newp_th) |
Bug Bounty | 2019-03-12 | 2023-06-13 |
4255 | Hack Your Form-New vector for Blind XSS |
Blind XSS
Stored XSS |
NA |
Youssef A. Mohamed (@GeneralEG64) |
Bug Bounty | 2019-03-13 | 2023-06-13 |
4118 | How I was able to get private ticket response panel and FortiGate web panel via blind XSS |
Blind XSS |
NA |
Bijan Murmu (@0xBijan) |
Bug Bounty | 2019-06-06 | 2023-06-13 |
4106 | XSSing Google Employees — Blind XSS on googleplex.com |
Blind XSS |
Google |
Thomas Orlita (@ThomasOrlita) |
Bug Bounty | 2019-06-15 | 2023-06-13 |
4044 | Cracking my windshield and earning $10,000 on the Tesla Bug Bounty Program |
Blind XSS |
Tesla |
Sam Curry (@samwcyo) |
Bug Bounty | 2019-07-14 | 2023-06-13 |
3830 | Privilege Escalation with simple recon |
Privilege escalation
Blind XSS |
NA |
Mayur Gupta (@RisingHunter_) |
Bug Bounty | 2019-11-16 | 2023-06-13 |