965 | SQL Injection in GraphQL |
SQL injection
GraphQL |
NA |
Ahmed Gad (@0xGAD) |
Bug Bounty | 2022-10-13 | 2023-06-13 |
798 | Header spoofing via a hidden parameter in Facebook Batch GraphQL APIs |
GraphQL
Security misconfiguration |
Meta / Facebook |
David Schütz (@xdavidhu) |
Bug Bounty | 2022-11-21 | 2023-06-13 |
675 | [GraphQL IDOR]Leaking credit card information of 1000s of users |
IDOR
GraphQL |
NA |
Vipul Sahu |
Bug Bounty | 2022-12-20 | 2023-06-13 |
664 | 0 click Facebook Account Takeover and Two-Factor Authentication Bypass |
Authentication bypass
GraphQL
Account takeover
Android
MFA bypass |
Meta / Facebook |
abdellah yaala (@yaalaab) |
Bug Bounty | 2022-12-21 | 2023-06-13 |
513 | An IDOR vulnerability often hides many others |
IDOR
GraphQL |
NA |
Allam Rachid (@blank_cold) |
Bug Bounty | 2023-02-01 | 2023-06-13 |
412 | Insufficient GraphQL API vulnerability due to lack of validation of Authorization Bearer token |
GraphQL
IDOR |
NA |
Int (@intlulz) |
Bug Bounty | 2023-02-22 | 2023-06-13 |
393 | Unauthenticated GraphQL Introspection and API calls |
GraphQL
Missing authentication |
NA |
Osama Avvan (@osamaavvan) |
Bug Bounty | 2023-02-26 | 2023-06-13 |
389 | Using efficient tooling to hunt GraphQL security issues |
GraphQL |
NA |
Nishant Jain (@realArcherL) |
Bug Bounty | 2023-02-26 | 2023-06-13 |
360 | How Your NFTs Could Have Been Stolen in Just One Click |
postMessage
GraphQL |
NA |
PermaSecure (@PermaSecure) |
Bug Bounty | 2023-03-03 | 2023-06-13 |
347 | Exposing Users Table From a Leaky GraphQL Query |
GraphQL
Authorization flaw
Broken Access Control |
NA |
Inderjeet Singh - encodedguy (@3nc0d3dGuY) |
Bug Bounty | 2023-03-06 | 2023-06-13 |
346 | Accessing to Data Sources of any Facebook Business account via IDOR in GraphQL |
IDOR
GraphQL |
Meta / Facebook |
Mukund Bhuva (@MukundBhuva) |
Bug Bounty | 2023-03-06 | 2023-06-13 |
323 | I Earned $3500 and 40 Points for A GraphQL Blind SQL Injection Vulnerability. |
SQL injection
GraphQL |
NA |
nav1n (@nav1n0x) |
Bug Bounty | 2023-03-10 | 2023-06-13 |
252 | CVE-2022-37734: graphql-java Denial-of-Service |
GraphQL
DoS
Security code review |
graphql-java |
Artem Logutov |
Bug Bounty | 2023-03-30 | 2023-06-13 |
61 | From Response To Request, Adding Your Own Variables Inside Of GraphQL Queries For Account Take Over |
GraphQL
IDOR
Mass assignment |
NA |
Tom Neaves |
Bug Bounty | 2023-05-23 | 2023-06-13 |