3094 | Weaponizing XSS For Fun & Profit |
XSS
CSRF |
NA |
Saad Ahmed (@XSaadAhmedX) |
Bug Bounty | 2020-10-14 | 2023-06-13 |
3074 | Automating xss identification with Dalfox & Paramspider |
Reflected XSS |
NA |
Paras Arora (@parasarora06) |
Bug Bounty | 2020-10-27 | 2023-06-13 |
3040 | Evernote: Universal-XSS, theft of all cookies from all sites, and more |
Universal XSS |
Evernote |
Oversecured (@OversecuredInc) |
Bug Bounty | 2020-11-12 | 2023-06-13 |
3034 | Smuggling an (Un)exploitable XSS |
HTTP Request Smuggling
XSS |
NA |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2020-11-13 | 2023-06-13 |
3027 | Microsoft Bug Bounty Writeup – Stored XSS Vulnerability |
Stored XSS |
Microsoft |
Pethuraj (@Pethuraj) |
Bug Bounty | 2020-11-15 | 2023-06-13 |
3011 | 2 Reflected XSS In Razer |
Reflected XSS |
Razer |
Mostafa |
Bug Bounty | 2020-11-21 | 2023-06-13 |
3010 | Weird (im)possible XSS on error page |
Reflected XSS |
NA |
Rody Shahnazarian (@Komradz86) |
Bug Bounty | 2020-11-21 | 2023-06-13 |
3009 | Escalating XSS to Account Takeover |
Reflected XSS
Account takeover |
NA |
Aditya Verma (@0cirius0) |
Bug Bounty | 2020-11-22 | 2023-06-13 |
3006 | Reflected Cross Site Scripting on REDACTED Program (Bounty: 750$) |
Reflected XSS |
NA |
can1337 (@canmustdie) |
Bug Bounty | 2020-11-23 | 2023-06-13 |
2989 | Cross Site Scripting (XSS) Reflected in one of the subdomains of “General Motors”(Bugbounty) |
Reflected XSS |
General Motors |
- |
Bug Bounty | 2020-12-03 | 2023-06-13 |
2986 | Opera Browser Cross Site Scripting (XSS) |
XSS
Android |
Opera |
Neil Mark Ochea (@nmochea) |
Bug Bounty | 2020-12-05 | 2023-06-13 |
2983 | [CVE-2019-17674 & CVE-2020-11025] Stored XSS through navigation menu item edited in Customizer in Wordpress (Write Up) |
Stored XSS |
WordPress |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2020-12-06 | 2023-06-13 |
2982 | Story of the best vulnerability I’ve found so far… |
Self-XSS
Blind XSS
Account takeover |
NA |
Vedant Tekale (@_justYnot) |
Bug Bounty | 2020-12-07 | 2023-06-13 |
2981 | "Important, Spoofing" - zero-click, wormable, cross-platform remote code execution in Microsoft Teams |
RCE
Stored XSS
CSP bypass
CSTI |
Microsoft |
Oskars Vegeris |
Bug Bounty | 2020-12-07 | 2023-06-13 |
2976 | Content-Security-Policy Bypass to perform XSS using MIME sniffing |
XSS
CSP bypass |
NA |
Kleiton Kurti (@kleiton0x7e) |
Bug Bounty | 2020-12-10 | 2023-06-13 |
2971 | How i got my First Bug Bounty in Intersting Target (LFI to SXSS) |
LFI
Stored XSS |
NA |
Ph.Hitachi |
Bug Bounty | 2020-12-11 | 2023-06-13 |
2969 | Security Study of Service Worker Cross-Site Scripting. |
XSS
Service worker based XSS |
NA |
Phakpoom Chinprutthiwong |
Bug Bounty | 2020-12-11 | 2023-06-13 |
2951 | Cookie Tossing to RCE on Google Cloud JupyterLab |
Self-XSS
DoS
CSRF
RCE |
Google |
s1r1us (@s1r1u5_) |
Bug Bounty | 2020-12-23 | 2023-06-13 |
2948 | EN | Account Takeover via Web Cache Poisoning based Reflected XSS |
Reflected XSS
Web cache poisoning
Account takeover |
NA |
Lütfü Mert Ceylan (@lutfumertceylan) |
Bug Bounty | 2020-12-26 | 2023-06-13 |
2945 | Chaining CORS by Reflected xss to Account takeover #My first Blog |
CORS misconfiguration
Reflected XSS
Account takeover |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2020-12-26 | 2023-06-13 |
2943 | [Google VRP] Hijacking Google Docs Screenshots |
postMessage
XSS |
Google |
Sreeram KL (@kl_sree) |
Bug Bounty | 2020-12-27 | 2023-06-13 |
2920 | Stored XSS on Product Description [HIGH] — $400 |
Stored XSS |
NA |
Emanuel Beni Harijanto |
Bug Bounty | 2021-01-07 | 2023-06-13 |
2915 | Blind XSS in Google Analytics Admin Panel — $3133.70 |
Blind XSS |
Google |
Ashish Dhone (@ashketchum_16) |
Bug Bounty | 2021-01-08 | 2023-06-13 |
2903 | Stealing User Information Via XSS Via Parameter Pollution |
Open redirect
XSS |
NA |
Hamza Avvan (@hamzaavvan) |
Bug Bounty | 2021-01-12 | 2023-06-13 |
2899 | How I managed to trigger a Stored-XSS in an online store with the help of Cache Poisoning |
Web cache poisoning
Stored XSS |
NA |
Schizo! |
Bug Bounty | 2021-01-14 | 2023-06-13 |