3752 | Effortlessly finding Cross Site Script Inclusion (XSSI) & JSONP for bug bounty |
XSSI |
NA |
Omkar Bhagwat (@th3_hidd3n_mist) |
Bug Bounty | 2019-12-27 | 2023-06-13 |
3751 | Drop the mic?! no! Drop the connection ;) |
DOM XSS |
Google |
Sasi Levi (@sasi2103) |
Bug Bounty | 2019-12-29 | 2023-06-13 |
3748 | How did I earn $3133.70 from Google Translator? |
XSS |
Google |
Beri Bey (@uppmen) |
Bug Bounty | 2019-12-30 | 2023-06-13 |
3747 | Exploiting a Self Stored XSS with an IDOR |
Self-XSS
Stored XSS
IDOR |
NA |
Shuaib Oladigbolu (@_sawzeeyy) |
Bug Bounty | 2019-12-31 | 2023-06-13 |
3746 | Bug Hunting Journey of 2019 |
XSS
Privilege escalation
Information disclosure |
Alibaba
Yahoo! / Verizon Media |
Sudhanshu Rajbhar (@sudhanshur705) |
Bug Bounty | 2019-12-31 | 2023-06-13 |
3736 | XSS on Sony subdomain |
Reflected XSS |
Sony |
Gökhan Güzelkokar (@gkhck_) |
Bug Bounty | 2020-01-06 | 2023-06-13 |
3731 | The Bug That Exposed Your PayPal Password |
XSSI |
Paypal |
Alex Birsan (@alxbrsn) |
Bug Bounty | 2020-01-08 | 2023-06-13 |
3701 | Escalating reflected XSS with HTTP Smuggling |
Reflected XSS
HTTP request smuggling |
NA |
Hazana (@HazanaSec) |
Bug Bounty | 2020-01-27 | 2023-06-13 |
3692 | Tumblr Bug Bounty ( $200) |
Unrestricted file upload
XSS
Authorization flaw |
Automattic |
Myo Min Thu (@myominthu1337) |
Bug Bounty | 2020-02-02 | 2023-06-13 |
3687 | Critical Security Flaw Found in WhatsApp Desktop Platform Allowing Cybercriminals Read From The File System Access |
Stored XSS
CSP bypass
Open redirect
RCE |
Meta / Facebook |
Gal Weizman (@WeizmanGal) |
Bug Bounty | 2020-02-04 | 2023-06-13 |
3686 | Arbitary File Upload too Stored XSS - Bug Bounty |
Arbitrary file upload
Stored XSS |
NA |
m0chan (@m0chan98) |
Bug Bounty | 2020-02-04 | 2023-06-13 |
3677 | Popping Alerts in Mixmax Chrome Extension (Write Up) |
XSS |
Mixmax |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2020-02-06 | 2023-06-13 |
3668 | CVE-2019-18426 - WhatsApp Vulnerabilities Disclosure - Open Redirect + CSP Bypass + Persistent XSS + FS read permissions + potential for RCE |
RCE
Stored XSS
CSP bypass
Arbitrary file read
Open redirect
Security code review |
Meta / Facebook (WhatsApp) |
Gal Weizman (@WeizmanGal) |
Bug Bounty | 2020-02-14 | 2023-06-13 |
3662 | Exploiting WebSocket [Application Wide XSS / CSRF] |
XSS
CSRF |
NA |
Osama Avvan (@osamaavvan) |
Bug Bounty | 2020-02-17 | 2023-06-13 |
3660 | How We Found Another XSS in Google with Acunetix |
XSS |
Google |
Andrey Leonov (@4lemon) |
Bug Bounty | 2020-02-17 | 2023-06-13 |
3659 | My First Bounty From Google. |
Self-XSS
HTML injection |
Google |
Syahri Ramadan (@adonkidz7) |
Bug Bounty | 2020-02-18 | 2023-06-13 |
3652 | Reflected XSS In AT&T |
Reflected XSS |
AT&T |
Myo Min Thu (@myominthu1337) |
Bug Bounty | 2020-02-23 | 2023-06-13 |
3651 | Blind XSS against a Googler |
Blind XSS |
Google |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2020-02-23 | 2023-06-13 |
3649 | Stored-XSS-on-groups-google-com |
Stored XSS |
Google |
Alessandro Rumampuk (@Rando02355205) |
Bug Bounty | 2020-02-25 | 2023-06-13 |
3641 | The Tricky XSS |
XSS |
NA |
Smaran Chand (@smaranchand) |
Bug Bounty | 2020-02-28 | 2023-06-13 |
3624 | Google Ads Self-XSS & Html Injection $5000 |
Self-XSS
HTML injection |
Google |
Syahri Ramadan (@adonkidz7) |
Bug Bounty | 2020-03-07 | 2023-06-13 |
3602 | Using Vulnerability Analytics Feature Like a Boss |
SSRF
Reflected XSS
Authentication bypass |
NA |
Ozgur Alp (@ozgur_bbh) |
Bug Bounty | 2020-03-15 | 2023-06-13 |
3600 | How I Earned $1750 at Shopify Bug Bounty Program |
XSS
Open redirect |
Shopify |
Ashish Dhone (@ashketchum_16) |
Bug Bounty | 2020-03-16 | 2023-06-13 |
3597 | Where is my Train : Tracking to Hacking ! |
Reflected XSS
SQL injection |
Google |
Anil Tom (mr_4nk) |
Bug Bounty | 2020-03-17 | 2023-06-13 |
3594 | Reflected XSS on microsoft.com subdomains |
Reflected XSS |
Microsoft |
Raimonds Liepins (@lv_linkers) |
Bug Bounty | 2020-03-19 | 2023-06-13 |