5316 | Stored Cross-Site Scripting (XSS) via DNS Record Poisoning |
XSS
Stored XSS |
Rengine |
Touhid M Shaikh |
Bug Bounty | 2024-08-23 | 2024-08-27 |
5286 | Google.com cross site scripting and privilege escalation in Consumer Surveys |
Stored XSS
Authorization flaw |
Google |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2013-01-03 | 2023-06-13 |
5249 | A Tale of 7 Vulnerabilities |
Stored XSS
Reflected XSS
Default credentials
Privilege escalation |
Paypal |
Patrik Fehrenbach (@ITSecurityguard) |
Bug Bounty | 2014-04-20 | 2023-06-13 |
5244 | Facebook – Stored Cross-Site Scripting (XSS) – Badges |
Stored XSS |
Meta / Facebook |
Brett Buerhaus (@bbuerhaus) |
Bug Bounty | 2014-06-16 | 2023-06-13 |
5236 | Paypal stored XSS + Security bypass |
Stored XSS |
Paypal |
Patrik Fehrenbach (@ITSecurityguard) |
Bug Bounty | 2014-11-11 | 2023-06-13 |
5204 | Arbitary File Upload Vulnerability in Google Nest (Write Up) |
Unrestricted file upload
Stored XSS |
Google |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2015-12-21 | 2023-06-13 |
5173 | Sleeping stored Google XSS Awakens a $5000 Bounty |
Stored XSS |
Google |
Patrik Fehrenbach (@ITSecurityguard) |
Bug Bounty | 2016-05-17 | 2023-06-13 |
5169 | RunKeeper Stored XSS Vulnerability – Where worms are able to run too! |
Stored XSS
CSRF |
RunKeeper |
Mohamed A. Baset |
Bug Bounty | 2016-06-06 | 2023-06-13 |
5134 | Persisting on Pornhub |
Stored XSS |
PornHub |
Andy Gill (@ZephrFish) |
Bug Bounty | 2016-09-23 | 2023-06-13 |
5123 | Stored XSS in UniFi v4.8.12 Controller |
Stored XSS |
Ubiquity Networks |
Shubham Gupta (@hackerspider1) |
Bug Bounty | 2016-11-12 | 2023-06-13 |
5122 | Svg XSS in Unifi v5.0.2 |
Stored XSS |
Ubiquity Networks |
Shubham Gupta (@hackerspider1) |
Bug Bounty | 2016-11-13 | 2023-06-13 |
5103 | Lightweight markup: a trio of persistent XSS in GitLab |
Stored XSS |
GitLab |
Yasin Soliman (@SecurityYasin) |
Bug Bounty | 2017-02-15 | 2023-06-13 |
5096 | One company: 262 bugs, 100% acceptance, 2.57 priority, millions of user details saved. |
Stored XSS
Blind XSS
CSRF
Account takeover
IDOR |
NA |
Zseano (@zseano) |
Bug Bounty | 2017-02-25 | 2023-06-13 |
5074 | A pair of Plotly bugs: Stored XSS and AWS Metadata SSRF |
Stored XSS
SSRF |
Plotly |
Yasin Soliman (@SecurityYasin) |
Bug Bounty | 2017-05-25 | 2023-06-13 |
5072 | XSS on Google{5.000$}-Google Vulnerability Reward Program (VRP) |
Stored XSS |
Google |
- |
Bug Bounty | 2017-05-30 | 2023-06-13 |
5065 | Stored XSS, CSRF And Clickjacking Vulnerabilities in Opera |
Stored XSS
CSRF
Clickjacking |
Opera |
Rafay Baloch (@rafaybaloch) |
Bug Bounty | 2017-06-01 | 2023-06-13 |
5052 | Stored XSS in the heart of the Russian email provider giant (Mail.ru) |
Stored XSS |
Mail.ru |
Seif Elsallamy (@seifelsallamy) |
Bug Bounty | 2017-06-24 | 2023-06-13 |
5045 | Stored XSS in Bandcamp |
Stored XSS |
Bandcamp |
Corben Leo (@hacker_) |
Bug Bounty | 2017-06-30 | 2023-06-13 |
5041 | Medium Content Spoofing Leads to XSS |
Content spoofing
Stored XSS |
Medium |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2017-07-08 | 2023-06-13 |
5037 | How we tookover shopify accounts with one single click |
Stored XSS |
Shopify |
WeSecureApp (@wesecureapp) |
Bug Bounty | 2017-07-10 | 2023-06-13 |
5028 | That Escalated Quickly : From partial CSRF to reflected XSS to complete CSRF to Stored XSS |
CSRF
Reflected XSS
Stored XSS |
NA |
Mandeep Jadon (@1337tr0lls) |
Bug Bounty | 2017-07-19 | 2023-06-13 |
5020 | Stored XSS on Rockstar Game |
XSS |
Rockstar Games |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-07-26 | 2023-06-13 |
4982 | Stored XSS] with arbitrary cookie installation |
XSS |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-09-17 | 2023-06-13 |
4979 | Exploiting a Single Request for Multiple Vulnerabilities |
Stored XSS
Reflected XSS
SSRF
OS command injection |
NA |
Osama Ansari (@AnsariOsama10) |
Bug Bounty | 2017-09-19 | 2023-06-13 |
4973 | Stored XSS to Full Information disclosure |
Stored XSS |
Terapeak |
Shubham Gupta (@hackerspider1) |
Bug Bounty | 2017-09-21 | 2023-06-13 |