1354 | Going beyond Alert with XSS |
XSS
Account takeover |
NA |
pipsh |
Bug Bounty | 2022-07-16 | 2023-06-13 |
1337 | React debug.keystore key was trusted by Meta(Facebook) which caused to Instagram account takeover by malicious apps. |
Account takeover
Android |
Meta / Facebook |
Dzmitry Lukyanenka (@vulnano) |
Bug Bounty | 2022-07-19 | 2023-06-13 |
1328 | WordPress Transposh: Exploiting a Blind SQL Injection via XSS - RCE Security |
SQL injection
XSS
Account takeover |
WordPress |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2022-07-22 | 2023-06-13 |
1291 | How I get Full Account Takeover via stealing action’s login form | XSS |
XSS
Account takeover |
NA |
Mohamed Tarek (@timooon107) |
Bug Bounty | 2022-08-01 | 2023-06-13 |
1288 | Stored XSS to Account Takeover : Going beyond document.cookie | Stealing Session Data from IndexedDB |
Stored XSS
Account takeover |
NA |
Syed Mushfik Hasan Tahsin (@SMHTahsin33) |
Bug Bounty | 2022-08-02 | 2023-06-13 |
1271 | 2FA Bypass via Google Identity & OAuth Login |
MFA bypass
Account takeover |
NA |
Sharat Kaikolamthuruthil (@sharp488) |
Bug Bounty | 2022-08-07 | 2023-06-13 |
1259 | Defeat the HttpOnly flag to achieve Account Takeover | RXSS |
Reflected XSS
Account takeover |
NA |
Mohamed Tarek (@timooon107) |
Bug Bounty | 2022-08-10 | 2023-06-13 |
1248 | My Experience on Hacking the Dutch Government |
XSS
Open redirect
CSRF
Account takeover |
Dutch Government |
Jefferson Gonzales (@gonzxph) |
Bug Bounty | 2022-08-11 | 2023-06-13 |
1243 | Amazon Cognito misconfiguration lead to account takeover |
Account takeover |
NA |
Hossam Ahmed (@iknowhatodo0x01) |
Bug Bounty | 2022-08-12 | 2023-06-13 |
1236 | UN United Nations Host Header Injection leads to any Full Account Takeover (ATO) |
Host header injection
Password reset
Account takeover |
United Nations |
Ahmed Hassan |
Bug Bounty | 2022-08-13 | 2023-06-13 |
1219 | We discovered major vulnerabilities in Control Web Panel. Here’s how we found them. |
Path traversal
RCE
Weak crypto
Password reset
Account takeover |
Centos Web Panel (CWP) |
Immersive Labs (@immersivelabs) |
Bug Bounty | 2022-08-15 | 2023-06-13 |
1213 | CSRF leads to Account Takeover | Samsung |
CSRF
Account takeover |
Samsung |
R ando (@Rando02355205) |
Bug Bounty | 2022-08-16 | 2023-06-13 |
1199 | Account takeover worth $1000 |
Account takeover
Authentication bypass
Information disclosure
Password reset |
NA |
Faique (@imfaiqu3) |
Bug Bounty | 2022-08-19 | 2023-06-13 |
1198 | Never underestimate the power of open redirect, a story of a full account takeover |
Open redirect
Account takeover
Token leak |
NA |
Ibrahim Auwal (@ibrahimatix0x01) |
Bug Bounty | 2022-08-20 | 2023-06-13 |
1124 | Turning cookie based XSS into account takeover |
XSS
Account takeover |
Terrahost |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-09-06 | 2023-06-13 |
1078 | HTTP Desync Attack (Request Smuggling) - Mass Account Takeover at a Cryptocurrency based asset and 121 other websites |
HTTP Request Smuggling
Desync attack |
NA |
Ankit Singh (@AnkitCuriosity) |
Bug Bounty | 2022-09-14 | 2023-06-13 |
1067 | Android Application Forgot Password Token Leakage Leading to Account Takeover |
Information disclosure
Password reset
Account takeover
Android |
NA |
Cyberali |
Bug Bounty | 2022-09-19 | 2023-06-13 |
1055 | Mass Assignment Leading to Pre Account Takeover |
Mass assignment |
NA |
Cyberali |
Bug Bounty | 2022-09-21 | 2023-06-13 |
1032 | Blind account takeover |
Account takeover |
NA |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-09-25 | 2023-06-13 |
1006 | Using Default Credential to Admin Account Takeover |
Weak credentials |
NA |
Rohit Kumar (Rohit_443) |
Bug Bounty | 2022-10-02 | 2023-06-13 |
1003 | Bugcrowd — Tale of multiple misconfigurations!! ❌ |
Account takeover
OAuth
OTP bypass
Password reset |
NA |
Vaibhav Lakhani |
Bug Bounty | 2022-10-04 | 2023-06-13 |
975 | In GUID We Trust |
IDOR
Password reset
Race condition
Account takeover |
NA |
Daniel Thatcher (@_danielthatcher) |
Bug Bounty | 2022-10-11 | 2023-06-13 |
968 | The story of a [P5] that lead me to a [P3] find |
Pre-account takeover |
NA |
JAI NIRESH J |
Bug Bounty | 2022-10-13 | 2023-06-13 |
964 | Code flaws leads to Org/Admin Account Takeover |
Privilege escalation
Account takeover |
NA |
Saransh Saraf (@mr23r0) |
Bug Bounty | 2022-10-13 | 2023-06-13 |
962 | Fall account takeover via Amazon Cognito misconfiguration |
IDOR
Account takeover |
NA |
Hossam Ahmed (@iknowhatodo0x01) |
Bug Bounty | 2022-10-13 | 2023-06-13 |