3825 | Million Users PII Leak Data Leak |
Information disclosure
Blind XSS |
NA |
Shivbihari Pandey (@ninja_pandit_) |
Bug Bounty | 2019-11-18 | 2023-06-13 |
3820 | How I paid 2$ for a 1054$ XSS bug + 20 chars blind XSS payloads |
XSS |
NA |
Mohamed Daher (@DaherMohamed4) |
Bug Bounty | 2019-11-20 | 2023-06-13 |
3788 | Blind XSS (A mind game to win the battle) |
Blind XSS |
NA |
Dirtycoder (@dirtycoder0124) |
Bug Bounty | 2019-12-11 | 2023-06-13 |
3651 | Blind XSS against a Googler |
Blind XSS |
Google |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2020-02-23 | 2023-06-13 |
3533 | From P5 to P2, from nothing to 1000+$ |
Race condition
Self-XSS
Blind XSS |
NA |
Mohamed Daher (@DaherMohamed4) |
Bug Bounty | 2020-04-22 | 2023-06-13 |
3132 | Chains on Chains: Chaining multiple low-level vulns into a Critical. |
Blind XSS
CSP bypass
Lack of rate limiting
Exposed JWT generation endpoint
JWT |
NA |
Daniel Marte (@Masonhck3571) |
Bug Bounty | 2020-09-26 | 2023-06-13 |
3109 | We Hacked Apple for 3 Months: Here’s What We Found |
RCE
Authentication bypass
Authorization bypass
SSRF
XXE
Blind XSS
IDOR
OS command injection
SQL injection |
Apple |
Sam Curry (@samwcyo) |
Bug Bounty | 2020-10-07 | 2023-06-13 |
2982 | Story of the best vulnerability I’ve found so far… |
Self-XSS
Blind XSS
Account takeover |
NA |
Vedant Tekale (@_justYnot) |
Bug Bounty | 2020-12-07 | 2023-06-13 |
2915 | Blind XSS in Google Analytics Admin Panel — $3133.70 |
Blind XSS |
Google |
Ashish Dhone (@ashketchum_16) |
Bug Bounty | 2021-01-08 | 2023-06-13 |
2723 | [Google VRP] How I Get Blind XSS At Google With Dork (First Bounty and HOF ) |
Blind XSS |
Google |
Rio Mulyadi (@riomulyadi_) |
Bug Bounty | 2021-03-11 | 2023-06-13 |
2708 | Chaining bugs for the greater good |
Blind XSS
CSRF |
NA |
mohamad mahmoudi (@Lotus_619) |
Bug Bounty | 2021-03-18 | 2023-06-13 |
2654 | (CRITICAL) Blind Storage XSS — My first Bug Bounty 💰 |
Blind XSS |
CS Money |
Benjamin Walter |
Bug Bounty | 2021-04-08 | 2023-06-13 |
2559 | Blind XSS on Google Internal System |
Blind XSS |
Google |
Kailash (@Corrupted_brain) |
Bug Bounty | 2021-05-13 | 2023-06-13 |
2432 | Blind XSS in Apple School- Enrollment Data Disclosure |
Blind XSS |
Apple |
hackrzvijay (@hackrzvijay) |
Bug Bounty | 2021-07-05 | 2023-06-13 |
1208 | N/a to $750 bounty for a Blind XSS. |
Blind XSS |
NA |
Dirtycoder (@dirtycoder0124) |
Bug Bounty | 2022-08-18 | 2023-06-13 |
1111 | $900 Blind XSS |
Blind XSS |
NA |
ѕнín (@shinchina_) |
Bug Bounty | 2022-09-07 | 2023-06-13 |
1087 | Blind XSS and Time-Based SQL Injection to Admin Panel Control and Database Takeover |
Blind XSS
SQL injection |
NA |
Cyberali |
Bug Bounty | 2022-09-13 | 2023-06-13 |
1037 | Blind XSS on Admin Portal Leads to Information Disclosure |
Blind XSS |
NA |
Rohit Kumar (Rohit_443) |
Bug Bounty | 2022-09-24 | 2023-06-13 |
914 | 5000$ for Apple Stored Xss And Another Blind Xss Still under review |
Blind XSS |
Apple |
Abdelkader Mouaz (@hamzadzworm) |
Bug Bounty | 2022-10-24 | 2023-06-13 |
871 | Get Blind XSS within 5 Minutes — $100 |
Blind XSS |
NA |
Narayanan M |
Bug Bounty | 2022-11-03 | 2023-06-13 |
805 | Russian roulette XSS |
Blind XSS |
NA |
Splintersec (@splint3rsec) |
Bug Bounty | 2022-11-19 | 2023-06-13 |
633 | How I took over an admin panel and got $500 |
Blind XSS
Account takeover |
NA |
Muhammed Mubarak |
Bug Bounty | 2023-01-01 | 2023-06-13 |
623 | Vue JS Reflected XSS |
Reflected XSS
Blind XSS
CORS misconfiguration
UI redressing |
NA |
sid0krypt (@Siddhar07949650) |
Bug Bounty | 2023-01-03 | 2023-06-13 |
617 | Blind XSS in Email Field; 1000$ bounty |
Blind XSS |
NA |
Yaseen Zubair |
Bug Bounty | 2023-01-05 | 2023-06-13 |
606 | Hacking Hackers for fun and profit |
Self-XSS
Blind XSS |
NA |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2023-01-09 | 2023-06-13 |