5286 | Google.com cross site scripting and privilege escalation in Consumer Surveys |
Stored XSS
Authorization flaw |
Google |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2013-01-03 | 2023-06-13 |
5279 | Overwriting Banner Images on Etsy |
Authorization flaw |
Etsy |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-05-21 | 2023-06-13 |
5278 | Hijacking a Facebook Account with SMS |
Authorization flaw
Account takeover |
Meta / Facebook |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-06-26 | 2023-06-13 |
5271 | Removing Covers Images on Friendship Pages, on Facebook |
Authorization flaw |
Meta / Facebook |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-09-25 | 2023-06-13 |
5218 | Bypass ad account roles vulnerability 2015 |
Authorization flaw |
Meta / Facebook |
Pouya Darabi (@Pouyadarabi) |
Bug Bounty | 2015-05-15 | 2023-06-13 |
5212 | Hacking Facebook Pages |
Authorization flaw
Privilege escalation
Broken Access Control |
Meta / Facebook |
Laxman Muthiyah (@LaxmanMuthiyah) |
Bug Bounty | 2015-08-26 | 2023-06-13 |
5188 | How I Could Compromise 4% (Locked) Instagram Accounts |
IDOR
DoS
Authorization flaw |
Meta / Facebook |
Arne Swinnen (@ArneSwinnen) |
Bug Bounty | 2016-03-27 | 2023-06-13 |
5187 | Watch Paint Dry: How I got a game on the Steam Store without anyone from Valve ever looking at it. |
Authorization flaw
Logic flaw |
Valve |
Ruby Nealon (@_ruby) |
Bug Bounty | 2016-03-29 | 2023-06-13 |
5126 | Leak Private Videos [Vimeo Bug Bounty] |
Logic flaw
Authorization flaw |
Vimeo |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2016-10-23 | 2023-06-13 |
5111 | I got emails - G Suite Vulnerability |
Logic flaw
Authorization flaw |
Google
Meta / Facebook
Yelp |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2017-02-02 | 2023-06-13 |
5108 | Facebook Groups Hack |
Authorization flaw
Logic flaw |
Meta / Facebook |
Zahid Ali |
Bug Bounty | 2017-02-04 | 2023-06-13 |
5106 | Bypassed Facebook Phone Number Security |
Authorization flaw
Logic flaw
Information disclosure |
Meta / Facebook |
Zahid Ali |
Bug Bounty | 2017-02-10 | 2023-06-13 |
5104 | Vulnerabilities in Facebook Login Approval Form |
Authorization flaw
Logic flaw |
Meta / Facebook |
Zahid Ali |
Bug Bounty | 2017-02-14 | 2023-06-13 |
5050 | Road to (unauthenticated) recovery: downloading GitHub SSO bypass codes |
Authorization flaw |
GitHub |
Yasin Soliman (@SecurityYasin) |
Bug Bounty | 2017-06-25 | 2023-06-13 |
5047 | Posting on groups as people whenever their email was known by an attacker |
Authorization flaw |
Meta / Facebook |
Zahid Ali |
Bug Bounty | 2017-06-29 | 2023-06-13 |
5036 | Fabric.io API permission apocalypse – Privilege Escalations |
Authorization flaw
Account takeover |
Twitter |
WeSecureApp (@wesecureapp) |
Bug Bounty | 2017-07-10 | 2023-06-13 |
5024 | Missing Authorization check in Facebook Pages Manager |
Authorization flaw |
Meta / Facebook |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-07-20 | 2023-06-13 |
5018 | Disabling New Emails From Facebook Without Email Owner Interaction |
Logic flaw
Authorization flaw |
Meta / Facebook |
Zahid Ali |
Bug Bounty | 2017-07-26 | 2023-06-13 |
5009 | $10k host header |
Authorization flaw |
Google |
Ezequiel Pereira (@epereiralopez) |
Bug Bounty | 2017-08-10 | 2023-06-13 |
4985 | Bypassing Facebook Profile Picture Guard Security. |
Authorization flaw |
Meta / Facebook |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2017-09-09 | 2023-06-13 |
4974 | Luminate Internal Privilege Escalation — Admin to Owner |
Authorization flaw |
Yahoo! / Verizon Media |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2017-09-21 | 2023-06-13 |
4968 | Device Authorization Bypass! |
Authorization flaw |
NA |
Hassan Khan Yusufzai |
Bug Bounty | 2017-09-25 | 2023-06-13 |
4916 | Using App Ads Helper as an Analytic User |
Authorization flaw |
Meta / Facebook |
Joshua Regio |
Bug Bounty | 2017-12-09 | 2023-06-13 |
4909 | Account Takeover Due to Misconfigured Login with Facebook/Google |
Account takeover
Authorization flaw |
Google
Meta / Facebook |
Bhavuk Jain (@bhavukjain1) |
Bug Bounty | 2017-12-20 | 2023-06-13 |
4881 | [Yahoo Bug Bounty] Unauthorized Access to Unisphere Management Server Debugging Facility on https://bf1-uaddbcx-002.data.bf1.yahoo.com/Debug/ |
Authorization flaw |
Yahoo! / Verizon Media |
Peerzada Fawaz Ahmad Qureshi |
Bug Bounty | 2018-01-25 | 2023-06-13 |