3497 | DOM XSS Walkthrough |
DOM XSS |
NA |
Youssef Lahouifi (@YLahouifi) |
Bug Bounty | 2020-05-06 | 2023-06-13 |
3495 | DOM-Based XSS at accounts.google.com by Google Voice Extension. |
DOM XSS |
Google |
missoum1307 (@missoum1307) |
Bug Bounty | 2020-05-07 | 2023-06-13 |
3493 | $20000 Facebook DOM XSS |
DOM XSS |
Meta / Facebook |
Vinoth Kumar (@vinodsparrow) |
Bug Bounty | 2020-05-07 | 2023-06-13 |
3349 | Blast from the past: Cross Site Scripting on the AWS Console |
DOM XSS |
Amazon |
Johann Rehberger (wunderwuzzi23) |
Bug Bounty | 2020-07-01 | 2023-06-13 |
3305 | Hunting postMessage Vulnerabilities |
postMessage
DOM XSS |
Apple
Google (Youtube)
Adobe |
Gary O%27Leary-Steele (@garyoleary) |
Bug Bounty | 2020-07-14 | 2023-06-13 |
2772 | Security and Privacy of Social Logins (II): PostMessage Security in Single Sign-On |
DOM XSS
postMessage
DOM XSS |
SAP
The New York Times
CNET |
Louis Jannett (@iphoneintosh) |
Bug Bounty | 2021-02-22 | 2023-06-13 |
2436 | Finding DOM Polyglot XSS in PayPal the Easy Way |
DOM XSS
CSP bypass |
Paypal |
Gareth Heyes (@garethheyes) |
Bug Bounty | 2021-06-30 | 2023-06-13 |
2359 | Multi Domain DOM Cross Site Scripting |
DOM XSS |
NA |
Sam Paredes (@caffeinevulns) |
Bug Bounty | 2021-08-01 | 2023-06-13 |
2243 | 5 Different Vulnerabilities in Google’s Threadit |
DOM XSS
Clickjacking
Privilege escalation
Information disclosure |
Google |
Thomas Orlita (@ThomasOrlita) |
Bug Bounty | 2021-09-07 | 2023-06-13 |
2159 | Stumbling across a DOM XSS on google.com |
DOM XSS |
Google |
tkiela (@svennergr) |
Bug Bounty | 2021-10-10 | 2023-06-13 |
1854 | Solving DOM XSS Puzzles |
DOM XSS |
NA |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2022-02-03 | 2023-06-13 |
1850 | What Bypassing Razer%27s DOM-based XSS Patch Can Teach Us |
DOM XSS |
Razer |
EdOverflow (@EdOverflow) |
Bug Bounty | 2022-02-05 | 2023-06-13 |
1551 | Hacking Swagger-UI - from XSS to account takeovers |
DOM XSS
Account takeover |
Shopify
Paypal
GitLab
Atlassian
Yahoo! / Verizon Media
Microsoft
Jamf |
Dawid Moczadło (@kannthu1) |
Bug Bounty | 2022-05-16 | 2023-06-13 |
1237 | DOM Cross-Site Scripting Via postMessage in AnnounceKit |
DOM XSS |
Announcekit |
Lorenzo Stella (@lorenzostella) |
Bug Bounty | 2022-08-12 | 2023-06-13 |
878 | How I Get 5x Swag From Sony |
DOM XSS
Directory listing
Default credentials
Information disclosure |
Sony |
Naeem Ahmed Sayed (@0xNaeem) |
Bug Bounty | 2022-11-02 | 2023-06-13 |
829 | Winning QR with DOM-Based XSS | Bug Bounty POC |
DOM XSS |
NA |
Haroon Hameed (@HaroonHameed40) |
Bug Bounty | 2022-11-15 | 2023-06-13 |
736 | A $$$ worth of cookies! | Reflected DOM-Based XSS | Bug Bounty POC |
DOM XSS |
NA |
Haroon Hameed (@HaroonHameed40) |
Bug Bounty | 2022-12-03 | 2023-06-13 |
679 | How I was able to steal users credentials via Swagger UI DOM-XSS |
DOM XSS
Old components with known vulnerabilities |
NA |
Mohamed Reda (@M0x0101) |
Bug Bounty | 2022-12-18 | 2023-06-13 |
657 | $350 XSS in 15 minutes |
DOM XSS
JSONP |
NA |
Anton (@therceman) |
Bug Bounty | 2022-12-23 | 2023-06-13 |
622 | Fetch Diversion |
DOM XSS |
NA |
Nicolas Christin (@acut3hack) |
Bug Bounty | 2023-01-03 | 2023-06-13 |
581 | DOM-Based XSS for fun and profit $$$! | Bug Bounty POC |
DOM XSS |
NA |
Haroon Hameed (@HaroonHameed40) |
Bug Bounty | 2023-01-17 | 2023-06-13 |
498 | postMessage DOM XSS vulnerability in Gartner Peer Insights widget |
postMessage
DOM XSS |
Gartner
Gradle
LogRhythm
SentinelOne
Synopsys
Veeam
Vodafone
Black Kite
ReversingLabs
Tata Communications |
Justin Steven (@justinsteven) |
Bug Bounty | 2023-02-04 | 2023-06-13 |
405 | How I found DOM-Based XSS on Microsoft MSRC and How they fixed it |
DOM XSS |
Microsoft |
Supakiad S. (@Supakiad_Mee) |
Bug Bounty | 2023-02-23 | 2023-06-13 |
400 | Microsoft Azure Account Takeover via DOM-based XSS in Cosmos DB Explorer |
Account takeover
DOM XSS |
Microsoft (Azure) |
Ngo Wei Lin (@Creastery) |
Bug Bounty | 2023-02-24 | 2023-06-13 |
264 | My Journey to Nokia Hall of Fame in just 10 minutes |
DOM XSS
Open redirect |
Nokia |
Rajdip |
Bug Bounty | 2023-03-27 | 2023-06-13 |