2896 | Insertion Of Malicious Links For Execution In Profile Picture - Unvalidated User Input In MS Sharepoint 2019 (CVE-2020-1456) |
XSS |
Microsoft |
David (@slashcrypto) |
Bug Bounty | 2021-01-15 | 2023-06-13 |
2885 | How I was rewarded a $1000 bounty after abusing File Upload functionality to Stored XSS Vulnerability leading to credential theft of a vistor in a website. |
Unrestricted file upload
Stored XSS |
NA |
Kunal Khubchandani (@iamkun4l) |
Bug Bounty | 2021-01-18 | 2023-06-13 |
2879 | Story Behind Sweet SSRF. |
SSRF
XSS |
NA |
Rohit Soni (@streetofhacker) |
Bug Bounty | 2021-01-21 | 2023-06-13 |
2869 | Chaining a self XSS to Account Takeover |
Self-XSS
Reflected XSS
Account takeover |
NA |
Arman Sameer (@ArmanSameer95) |
Bug Bounty | 2021-01-25 | 2023-06-13 |
2862 | Bragging Rights(Part 1): Short story of a bug wave |
IDOR
Stored XSS
SSRF
Subdomain takeover
Hardcoded credentials |
NA |
Manas Harsh (@ManasH4rsh) |
Bug Bounty | 2021-01-27 | 2023-06-13 |
2854 | Destroying Armies and Villages through Cross-Site Scripting - Bug Bounty Write-up |
Stored XSS |
InnoGames |
Fábio Freitas (@0xfabiof) |
Bug Bounty | 2021-01-29 | 2023-06-13 |
2853 | Broken Access Control & Stored XSS - Easy Hunt |
Stored XSS
IDOR |
NA |
Kabeer (@iTheKabeer) |
Bug Bounty | 2021-01-29 | 2023-06-13 |
2840 | How I was able to Turn a XSS into a Account Takeover |
Web cache poisoning
Stored XSS
Account takeover
OAuth
Logic flaw |
NA |
Josh Fam (@Pullerze) |
Bug Bounty | 2021-02-03 | 2023-06-13 |
2836 | Redwood Report2Web XSS and Frame injection |
Reflected XSS
Frame injection |
NA |
vict0ni (@vict0ni) |
Bug Bounty | 2021-02-04 | 2023-06-13 |
2830 | Reflected XSS on a Public Program |
Reflected XSS |
NA |
Naveen J (@thevillagehackr) |
Bug Bounty | 2021-02-08 | 2023-06-13 |
2825 | Self-XSS to rXSS via Uploaded File Name |
Self-XSS
Reflected XSS |
NA |
P4nda (@InfoSecP4nda) |
Bug Bounty | 2021-02-09 | 2023-06-13 |
2820 | An Accidental XSS on uu.nl |
XSS |
Utrecht University |
Santosh Bobade (@Santosh88267387) |
Bug Bounty | 2021-02-11 | 2023-06-13 |
2818 | Hacking Chess.com and Accessing 50 Million Customer Records |
Reflected XSS
Information disclosure
Account takeover |
Chess.com |
Sam Curry (@samwcyo) |
Bug Bounty | 2021-02-11 | 2023-06-13 |
2808 | My first bounty (stored-xss) |
Stored XSS |
NA |
Karan sharma (@karansh491) |
Bug Bounty | 2021-02-14 | 2023-06-13 |
2807 | Stored XSS in icloud.com — $5000 |
Stored XSS |
NA |
Vishal Bharad |
Bug Bounty | 2021-02-14 | 2023-06-13 |
2794 | Story of a very lethal IDOR. |
XSS
IDOR
Account takeover |
NA |
Vedant Tekale (@_justYnot) |
Bug Bounty | 2021-02-17 | 2023-06-13 |
2781 | Build Pipeline Security |
RCE |
AWS |
xssfox (@xssfox) |
Bug Bounty | 2021-02-18 | 2023-06-13 |
2772 | Security and Privacy of Social Logins (II): PostMessage Security in Single Sign-On |
DOM XSS
postMessage
DOM XSS |
SAP
The New York Times
CNET |
Louis Jannett (@iphoneintosh) |
Bug Bounty | 2021-02-22 | 2023-06-13 |
2769 | Poisoning your Cache for 1000$ - Approach to Exploitation Walkthrough |
Web cache poisoning
Stored XSS |
NA |
Gal Nagli (@naglinagli) |
Bug Bounty | 2021-02-25 | 2023-06-13 |
2755 | Bragging Rights: Killing File Uploads softly |
Unrestricted file upload
Stored XSS |
NA |
Manas Harsh (@ManasH4rsh) |
Bug Bounty | 2021-02-28 | 2023-06-13 |
2742 | Stored XSS at Trello.com |
Stored XSS |
Trello |
Maor Dayan (@mord1234) |
Bug Bounty | 2021-03-04 | 2023-06-13 |
2740 | Leveraging Template injection to takeover an account. |
CSTI
XSS |
NA |
Akash Methani (@0xAkash) |
Bug Bounty | 2021-03-04 | 2023-06-13 |
2734 | Stored XSS in Google Ads Android Application— $3133.70 |
Stored XSS
HTML injection |
Google |
Ashish Dhone (@ashketchum_16) |
Bug Bounty | 2021-03-07 | 2023-06-13 |
2729 | Exploiting HTTP Request Smuggling (TE.CL)— XSS to website takeover |
HTTP request smuggling
XSS |
NA |
Kleiton Kurti (@kleiton0x7e) |
Bug Bounty | 2021-03-09 | 2023-06-13 |
2726 | Chain of Low Level Bugs and Misconfigurations Leads to Account Takeover |
Reflected XSS
Clickjacking
Account takeover |
NA |
pleorqy (@pleorqy) |
Bug Bounty | 2021-03-10 | 2023-06-13 |