5128 | Exploiting CORS misconfigurations for Bitcoins and bounties |
CORS misconfiguration |
NA |
James Kettle (@albinowax) |
Bug Bounty | 2016-10-12 | 2023-06-13 |
5030 | Exploiting Misconfigured CORS on popular BTC Site |
CORS misconfiguration |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-07-19 | 2023-06-13 |
5000 | Pre-domain wildcard CORS Exploitation |
CORS misconfiguration |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-08-26 | 2023-06-13 |
4962 | Exploiting Insecure Cross Origin Resource Sharing ( CORS ) | api.artsy.net |
CORS misconfiguration |
Artsy |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2017-10-10 | 2023-06-13 |
4923 | Tricky CORS Bypass in Yahoo! View |
CORS misconfiguration |
Yahoo! / Verizon Media |
Corben Leo (@hacker_) |
Bug Bounty | 2017-11-27 | 2023-06-13 |
4905 | Stealing $10,000 Yahoo Cookies! |
CORS misconfiguration |
Yahoo! / Verizon Media |
Tabahi (@_tabahi) |
Bug Bounty | 2017-12-30 | 2023-06-13 |
4897 | Chaining Bugs to Steal Yahoo Contacts! |
CORS misconfiguration
XSS |
Yahoo! / Verizon Media |
Corben Leo (@hacker_) |
Bug Bounty | 2018-01-11 | 2023-06-13 |
4880 | Full Account Takeover through CORS with connection Sockets |
CORS misconfiguration
Account takeover |
NA |
Samuel (@saamux) |
Bug Bounty | 2018-01-25 | 2023-06-13 |
4856 | Exploiting CORS Miss configuration using XSS |
CORS misconfiguration |
NA |
Noman Shaikh (@nomanali181) |
Bug Bounty | 2018-02-18 | 2023-06-13 |
4803 | #SecurityBreach — "How I was able to book hotel room for 1.50₹!" |
CORS misconfiguration |
NA |
Hariom Vashisth |
Bug Bounty | 2018-04-15 | 2023-06-13 |
4358 | A Simple CORS Misconfig Leaked Private Post Of Twitter, Facebook & Instagram |
CORS misconfiguration |
NA |
Rohan aggarwal (@nahoragg) |
Bug Bounty | 2019-01-20 | 2023-06-13 |
4155 | Think Outside the Scope: Advanced CORS Exploitation Techniques |
CORS misconfiguration |
NA |
Ayoub (@sandh0t) |
Bug Bounty | 2019-05-14 | 2023-06-13 |
4132 | An unexploited CORS misconfiguration reflecting further issues. |
CORS misconfiguration |
NA |
Smaran Chand (@smaranchand) |
Bug Bounty | 2019-05-27 | 2023-06-13 |
4128 | Edmodo Account Deactivation Vulnerability |
CORS misconfiguration |
Edmodo |
Shankar R |
Bug Bounty | 2019-06-01 | 2023-06-13 |
4074 | CORS To CSRF Attack |
CORS misconfiguration
CSRF |
NA |
Osama Avvan (@osamaavvan) |
Bug Bounty | 2019-06-27 | 2023-06-13 |
4039 | The Bugs Are Out There, Hiding in Plain Sight |
IDOR
SSRF
Information disclosure
CORS misconfiguration |
NA |
A Bug’z Life (@abugzlife1) |
Bug Bounty | 2019-07-15 | 2023-06-13 |
4001 | Bypassing CORS |
CORS misconfiguration |
NA |
Saad Ahmed (@XSaadAhmedX) |
Bug Bounty | 2019-08-01 | 2023-06-13 |
3811 | CORS Misconfiguration to Account TakeOver [Out of scope to grab items In-Scope] |
CORS misconfiguration
Open redirect
Reflected XSS
Session management issue |
NA |
Mashoud1122 (@mashoud1122) |
Bug Bounty | 2019-11-24 | 2023-06-13 |
3710 | CORS Misconfiguration leading to Private Information Disclosure |
CORS misconfiguration |
NA |
Virus0X01 (@Virus0X01) |
Bug Bounty | 2020-01-23 | 2023-06-13 |
3620 | Broke limited scope with a chain of bugs (tips for every rider CORS) |
CORS misconfiguration
RCE |
NA |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2020-03-09 | 2023-06-13 |
3536 | CORS bug on GOOGLE’s 404 page REWARDED!!! |
CORS misconfiguration |
Google |
Jayateertha Guruprasad (@JayateerthaG) |
Bug Bounty | 2020-04-21 | 2023-06-13 |
3534 | The Secret sauce of bug bounty |
CSTI
Stored XSS
CORS misconfiguration |
NA |
Mohamed Slamat (@oxxy37) |
Bug Bounty | 2020-04-22 | 2023-06-13 |
3525 | Fun With CORS Misconfiguration — II |
CORS misconfiguration
XSS |
NA |
Aman Gupta (@gupt4j1) |
Bug Bounty | 2020-04-25 | 2023-06-13 |
3474 | Cors Blimey: The power of chaining CORS |
CORS misconfiguration
Stored XSS
CSRF |
NA |
Hazana (@hazanasec) |
Bug Bounty | 2020-05-17 | 2023-06-13 |
3338 | EN | Account Takeover and Sensitive Data Leakage via CORS Misconfiguration |
CORS misconfiguration
CSRF
Account takeover |
NA |
Lütfü Mert Ceylan (@lutfumertceylan) |
Bug Bounty | 2020-07-04 | 2023-06-13 |