2602 | Exploiting XSS via Markdown on Xiaomi |
XSS |
Xiaomi |
N45HT |
Bug Bounty | 2021-04-27 | 2023-06-13 |
2601 | Reflected DOM-based XSS on DomaiNesia |
XSS |
DomaiNesia |
N45HT |
Bug Bounty | 2021-04-27 | 2023-06-13 |
2587 | Chaining CSRF with XSS to deactivate Mass user accounts by single click |
CSRF
XSS |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-05-02 | 2023-06-13 |
2580 | XSS Through Parameter Pollution |
XSS
HTTP parameter pollution |
NA |
Saajan Bhujel (@saajanbhujel) |
Bug Bounty | 2021-05-05 | 2023-06-13 |
2578 | XSS Through Parameter Pollution |
Open redirect
XSS
HTTP parameter pollution |
NA |
Saajan Bhujel (@saajanbhujel11) |
Bug Bounty | 2021-05-05 | 2023-06-13 |
2572 | Apple Bug bounty writeups XSS(2021) |
XSS |
Apple |
Takashi Suzuki |
Bug Bounty | 2021-05-07 | 2023-06-13 |
2566 | Stored XSS to Organisation Takeover |
Stored XSS |
NA |
Zaid Bhat (@zaidozaid) |
Bug Bounty | 2021-05-10 | 2023-06-13 |
2562 | My story of hacking Dutch Government |
XSS |
Dutch Government |
Tuhin Bose (@tuhin1729_) |
Bug Bounty | 2021-05-12 | 2023-06-13 |
2561 | How I find my first Stored XSS |
Stored XSS |
NA |
Filipe Azevedo (@filipaze_) |
Bug Bounty | 2021-05-13 | 2023-06-13 |
2559 | Blind XSS on Google Internal System |
Blind XSS |
Google |
Kailash (@Corrupted_brain) |
Bug Bounty | 2021-05-13 | 2023-06-13 |
2554 | Edmodo Bug Bounty Writeup |
XSS |
Edmodo |
Pethuraj (@Pethuraj) |
Bug Bounty | 2021-05-16 | 2023-06-13 |
2539 | XSS via postMessage in chat.mozilla.org |
XSS
postMessage |
Mozilla |
Guilherme Keerok (@k33r0k) |
Bug Bounty | 2021-05-20 | 2023-06-13 |
2537 | 13 Nagios Vulnerabilities, #7 will SHOCK you! |
RCE
Local Privilege Escalation
XSS
Security code review |
Nagios |
Samir Ghanem (@sam0x21r) |
Bug Bounty | 2021-05-20 | 2023-06-13 |
2528 | Chaining XSS with authentication issues to turn it into full account takeover |
XSS
Account takeover |
NA |
N1GHTMAR3 (@n1ghtmar3_2421) |
Bug Bounty | 2021-05-24 | 2023-06-13 |
2526 | Stored XSS with two different parameters |
Reflected XSS |
NA |
Joel Cantu (@InfosecRintox) |
Bug Bounty | 2021-05-25 | 2023-06-13 |
2523 | How I hacked a Target again and again… |
OAuth
Account takeover
XSS
Broken Access Control |
NA |
Aditya Verma (@0cirius0) |
Bug Bounty | 2021-05-27 | 2023-06-13 |
2519 | The beauty of chaining client-side bugs |
CRLF injection
XSS
CSP bypass
DoS
CSTI |
NA |
Master SEC (@MasterSEC_AR) |
Bug Bounty | 2021-05-29 | 2023-06-13 |
2507 | XSS in the AWS Console |
XSS
CSP bypass
CSTI |
AWS |
Nick Frichette (@frichette_n) |
Bug Bounty | 2021-06-02 | 2023-06-13 |
2502 | 403 Forbidden Bypass |
OTP bypass
Exposed registration page
XSS |
NA |
th3.d1p4k (@DipakPanchal05) |
Bug Bounty | 2021-06-04 | 2023-06-13 |
2500 | Pop-Ups in a good-world |
XSS |
Imgur |
Guilherme Keerok (@k33r0k) |
Bug Bounty | 2021-06-04 | 2023-06-13 |
2496 | Story of my first cash bounty on hackerone. |
SSRF
XSS |
NA |
Vedant Tekale (@_justYnot) |
Bug Bounty | 2021-06-07 | 2023-06-13 |
2495 | Joomla Password Reset Vulnerability And A Stored XSS For Full Compromise |
Password reset
Stored XSS
Privilege escalation
RCE
Security code review |
NA |
Adrian Tiron (@Adrian__T) |
Bug Bounty | 2021-06-07 | 2023-06-13 |
2477 | How We Are Able To Hack Any Company By Sending Message – $20,000 Bounty [CVE-2021–34506] |
Universal XSS |
Microsoft |
Shivam Kumar Singh (@MrRajputHacker) |
Bug Bounty | 2021-06-15 | 2023-06-13 |
2468 | How We Are Able To Hack Any Company By Sending Message - $20,000 Bounty [CVE-2021–34506] |
Universal XSS |
Microsoft |
Vansh Devgan (@Th3Pr0xyB0y) |
Bug Bounty | 2021-06-18 | 2023-06-13 |
2466 | Account takeover via stored XSS with arbitrary file upload |
Insecure file upload
XSS
Account takeover |
NA |
0xbadb00da (@0xbadb00da) |
Bug Bounty | 2021-06-18 | 2023-06-13 |