3894 | Stealing login credentials with Reflected XSS |
Reflected XSS |
NA |
mehulpanchal007 (@007_sharky) |
Bug Bounty | 2019-10-01 | 2023-06-13 |
3883 | Bypass Uppercase filters like a PRO (XSS Advanced Methods) |
XSS |
NA |
MasterSEC (@MasterSEC_AR) |
Bug Bounty | 2019-10-11 | 2023-06-13 |
3874 | Hunting for bounties antihack.me case study |
RCE
XSS
Logic flaw
Information disclosure |
AntiHack.me |
0xSha (@0xsha) |
Bug Bounty | 2019-10-20 | 2023-06-13 |
3872 | How PayPal helped me to generate XSS |
Reflected XSS |
Paypal |
Pflash Punk (@PflashPunk) |
Bug Bounty | 2019-10-20 | 2023-06-13 |
3859 | XSS to Account Takeover |
XSS
CSRF |
NA |
Tomi (@noobe_io) |
Bug Bounty | 2019-10-29 | 2023-06-13 |
3857 | 5,000 USD XSS Issue at Avast Desktop AntiVirus for Windows (Yes, Desktop!) |
Reflected XSS |
Avast |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2019-10-29 | 2023-06-13 |
3852 | XSS will never die |
XSS |
NA |
Oleksandr Opanasiuk (@Lekssik2) |
Bug Bounty | 2019-11-02 | 2023-06-13 |
3845 | DOM-Based XSS | Bug Bounty Writeup |
DOM XSS |
NA |
HacknPentest (@HacknPentest) |
Bug Bounty | 2019-11-10 | 2023-06-13 |
3830 | Privilege Escalation with simple recon |
Privilege escalation
Blind XSS |
NA |
Mayur Gupta (@RisingHunter_) |
Bug Bounty | 2019-11-16 | 2023-06-13 |
3826 | XSS in GMail’s AMP4Email via DOM Clobbering |
XSS
DOM Clobbering |
Google |
Michał Bentkowski (@SecurityMB) |
Bug Bounty | 2019-11-18 | 2023-06-13 |
3825 | Million Users PII Leak Data Leak |
Information disclosure
Blind XSS |
NA |
Shivbihari Pandey (@ninja_pandit_) |
Bug Bounty | 2019-11-18 | 2023-06-13 |
3820 | How I paid 2$ for a 1054$ XSS bug + 20 chars blind XSS payloads |
XSS |
NA |
Mohamed Daher (@DaherMohamed4) |
Bug Bounty | 2019-11-20 | 2023-06-13 |
3812 | The AccountTakeOver Killing Chain |
Account takeover
CSRF
Self-XSS |
NA |
أنس روبي (@xhzeem) |
Bug Bounty | 2019-11-23 | 2023-06-13 |
3811 | CORS Misconfiguration to Account TakeOver [Out of scope to grab items In-Scope] |
CORS misconfiguration
Open redirect
Reflected XSS
Session management issue |
NA |
Mashoud1122 (@mashoud1122) |
Bug Bounty | 2019-11-24 | 2023-06-13 |
3806 | Reflected XSS in graph.facebook.com leads to account takeover in IE/Edge |
Reflected XSS
Account takeover |
Meta / Facebook |
Youssef Sammouda (@samm0uda) |
Bug Bounty | 2019-11-27 | 2023-06-13 |
3805 | XSS Stored On [ Outlook Web — Outlook Android App ] |
Stored XSS |
Microsoft |
ElMahdi Mrhassel (@ElMrhassel) |
Bug Bounty | 2019-11-28 | 2023-06-13 |
3803 | How I turned Self XSS to Stored via CSRF |
Self-XSS
CSRF |
NA |
Abhishek Yadav (@abhishake100) |
Bug Bounty | 2019-11-29 | 2023-06-13 |
3800 | XSS like a Pro |
XSS |
NA |
Anas Mahmood (@AnasIsHere) |
Bug Bounty | 2019-12-05 | 2023-06-13 |
3797 | $150 XSS at Error Page of Respository Code |
Reflected XSS |
NA |
Navneet (@na5n33t) |
Bug Bounty | 2019-12-07 | 2023-06-13 |
3796 | HTML Injection to XSS bypass in [REDACTED.com] |
Reflected XSS |
NA |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2019-12-07 | 2023-06-13 |
3788 | Blind XSS (A mind game to win the battle) |
Blind XSS |
NA |
Dirtycoder (@dirtycoder0124) |
Bug Bounty | 2019-12-11 | 2023-06-13 |
3762 | Bugbounty | A DOM XSS |
DOM XSS |
NA |
Jinone (@jinonehk) |
Bug Bounty | 2019-12-24 | 2023-06-13 |
3757 | Microsoft Edge (Chromium) - EoP via XSS to Potential RCE |
XSS
RCE |
Microsoft |
Abdulrahman Alqabandi (@Qab) |
Bug Bounty | 2019-12-24 | 2023-06-13 |
3756 | BugBounty | A Dom Xss |
DOM XSS |
NA |
Jinone (@jinonehk) |
Bug Bounty | 2019-12-24 | 2023-06-13 |
3755 | XSS Is Love <3 ! |
XSS |
NA |
Nirmal Dahal (@TheNittam) |
Bug Bounty | 2019-12-26 | 2023-06-13 |