3986 | break and bypass verification email |
Open redirect
Email verification bypass
Weak crypto |
Bukalapak |
Abdelhak Kharroubi |
Bug Bounty | 2019-08-07 | 2023-06-13 |
3953 | How i was able to exploit the same endpoint 2 times ( multiple xss & open Redirection on 10 subdomain) |
XSS
Open redirect |
Sanity.io |
Ratnadip Gajbhiye (@scspcommunity) |
Bug Bounty | 2019-08-26 | 2023-06-13 |
3927 | How does my recon win $250 in 15 minutes |
Open redirect |
NA |
Hein Thant Zin (@H3Lowr) |
Bug Bounty | 2019-09-12 | 2023-06-13 |
3909 | Bug or Feature? GitHub Adventure #001 |
OAuth
Open redirect |
NA |
Dominik Opyd (@oad_earth) |
Bug Bounty | 2019-09-21 | 2023-06-13 |
3899 | OnePlus Open/Unvalidated Redirects & Forwards |
Open redirect |
OnePLus |
Mainak Sadhukhan |
Bug Bounty | 2019-09-26 | 2023-06-13 |
3854 | Download this tool and you win |
Open redirect |
NA |
zoid (@z0idsec) |
Bug Bounty | 2019-10-31 | 2023-06-13 |
3811 | CORS Misconfiguration to Account TakeOver [Out of scope to grab items In-Scope] |
CORS misconfiguration
Open redirect
Reflected XSS
Session management issue |
NA |
Mashoud1122 (@mashoud1122) |
Bug Bounty | 2019-11-24 | 2023-06-13 |
3745 | From POST to GET Open redirect |
Open redirect |
NA |
Sourav Sahana (@kernel_rider) |
Bug Bounty | 2019-12-31 | 2023-06-13 |
3738 | Account takeover via HTTP Request Smuggling |
HTTP request smuggling
Account takeover
Open redirect
Internal header disclosure |
NA |
hipotermia (@_hipotermia_) |
Bug Bounty | 2020-01-03 | 2023-06-13 |
3729 | Hunting Good Bugs with only <HTML> |
Open redirect
HTML injection
SSRF |
NA |
Ak1T4 (@akita_zen) |
Bug Bounty | 2020-01-10 | 2023-06-13 |
3687 | Critical Security Flaw Found in WhatsApp Desktop Platform Allowing Cybercriminals Read From The File System Access |
Stored XSS
CSP bypass
Open redirect
RCE |
Meta / Facebook |
Gal Weizman (@WeizmanGal) |
Bug Bounty | 2020-02-04 | 2023-06-13 |
3668 | CVE-2019-18426 - WhatsApp Vulnerabilities Disclosure - Open Redirect + CSP Bypass + Persistent XSS + FS read permissions + potential for RCE |
RCE
Stored XSS
CSP bypass
Arbitrary file read
Open redirect
Security code review |
Meta / Facebook (WhatsApp) |
Gal Weizman (@WeizmanGal) |
Bug Bounty | 2020-02-14 | 2023-06-13 |
3666 | Open-redirect Vulnerability on Facebook |
Open redirect |
Meta / Facebook |
dw1 |
Bug Bounty | 2020-02-16 | 2023-06-13 |
3600 | How I Earned $1750 at Shopify Bug Bounty Program |
XSS
Open redirect |
Shopify |
Ashish Dhone (@ashketchum_16) |
Bug Bounty | 2020-03-16 | 2023-06-13 |
3582 | 1st Bug Bounty Write-Up — Open Redirect Vulnerability on Login Page |
Open redirect |
NA |
Phuriphat Boontanon (@zanezenzane) |
Bug Bounty | 2020-03-27 | 2023-06-13 |
3543 | Strange Redirect (Fixed but no bounty) |
Open redirect |
NA |
Abhishek Yadav (@abhishake100) |
Bug Bounty | 2020-04-17 | 2023-06-13 |
3539 | Abusing HTTP Path Normalization and Cache Poisoning to steal Rocket League accounts |
HTTP cache poisoning
Open redirect |
Rocket League |
Sam Curry (@samwcyo) |
Bug Bounty | 2020-04-19 | 2023-06-13 |
3537 | DOM based open redirect to the leak of a JWT token |
Open redirect
DOM-based open redirect
Token leak |
NA |
Adolphoramirez |
Bug Bounty | 2020-04-20 | 2023-06-13 |
3441 | Weak Cryptography Leads To Open Redirect |
Open redirect |
NA |
DarkLotus (@darklotuskdb) |
Bug Bounty | 2020-05-30 | 2023-06-13 |
3343 | How i got 200$ with an out of the box open redirect vulnerability |
Open redirect
Token leak |
NA |
Tarek Galleze |
Bug Bounty | 2020-07-03 | 2023-06-13 |
3315 | Don’t stop at one bug $$$$ |
Open redirect
XSS
LFI |
NA |
Dheeraj Madhukar (@Dheerajmadhukar) |
Bug Bounty | 2020-07-10 | 2023-06-13 |
3310 | Bug Bounty Experience: Unvalidated Redirection Vulnerability |
Open redirect |
NA |
Simply Secure |
Bug Bounty | 2020-07-12 | 2023-06-13 |
3279 | An unreproducable bug due to the load balancer, an unusual Open Redirect bug |
Open redirect |
NA |
tololovejoi (@tolo7010) |
Bug Bounty | 2020-07-27 | 2023-06-13 |
3276 | CSRF + Open Redirect To Account Takeover |
CSRF
Open redirect
Account takeover |
NA |
R29k (@R29k_) |
Bug Bounty | 2020-07-28 | 2023-06-13 |
3258 | CVE-2020-13379 Unauthenticated Full-Read SSRF in Grafana |
SSRF
Open redirect |
NA |
Justin Gardner (@Rhynorater) |
Bug Bounty | 2020-08-01 | 2023-06-13 |