Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
1606Open Redirection into Bentley System XSS Bentley Systems Amit Kumar (@Amitlt2) Bug Bounty2022-04-212023-06-13
1605Smashing the Modern Web Tech Stack — Part 1: The Evolving Threat Landscape in 2022 and DOM-based XSS in Cloud-Native React Apps. Open redirect XSS NA MalwareJoe Bug Bounty2022-04-212023-06-13
1596[EN] Privileged account creation via Mass Assignment towards a full compromise using a Stored XSS Stored XSS Mass assignment Security code review pass Culture Aethlios (@AethliosIK) Bug Bounty2022-04-262023-06-13
1588Sensitive Data Exfiltration through XSS ($450) Token leak NA Zulfi Al-Farizi Bug Bounty2022-04-302023-06-13
1575Chained Bug: XML File Upload to XSS to CSRF to Full Account Take Over (ATO) XSS CSRF Account takeover NA Zulfi Al-Farizi Bug Bounty2022-05-062023-06-13
1567How I Paid For My Holiday With Bug Bounty XSS Broken Access Control IDOR Unrestricted file upload NA Tobydavenn Bug Bounty2022-05-082023-06-13
1563ResolveURI RXSS Imperva Waf Bypass XSS NA Ahsan Shahid (@hunter0x8) Bug Bounty2022-05-102023-06-13
1562The Underrated Bugs, Clickjacking, CSS Injection, Drag-Drop XSS, Cookie Bomb, Login+Logout CSRF… CSS injection Clickjacking Account takeover XSS Cookie bomb Self-XSS CSRF NA Renwa (@RenwaX23) Bug Bounty2022-05-102023-06-13
1551Hacking Swagger-UI - from XSS to account takeovers DOM XSS Account takeover Shopify Paypal GitLab Atlassian Yahoo! / Verizon Media Microsoft Jamf Dawid Moczadło (@kannthu1) Bug Bounty2022-05-162023-06-13
1550Bypassing WAF to Weaponize a Stored XSS Stored XSS NA ne555 Bug Bounty2022-05-172023-06-13
1539Research: Auditing WordPress Plugins SQL injection LFI XSS RCE NA cy//ective (@cyllective) Bug Bounty2022-05-202023-06-13
1523How I made it into the United Nations hall of fame as I slept XSS United Nations Vikaran (@vikaran101) Bug Bounty2022-05-252023-06-13
15202nd RCE and XSS in Apache Struts before 2.5.30 RCE Double OGNL evaluation XSS Apache Struts Chris (@mc_0wn) Bug Bounty2022-05-252023-06-13
1516Bygone Vulnerabilities - Remote Code Execution in IBM Lotus SameTime Clients (CVE-2013-0553) XSS RCE IBM Brian (@hoyahaxa) Bug Bounty2022-05-272023-06-13
1495An unusual way to find XSS injection in one minute CSTI XSS TimeWeb Andrey Onishchenko Bug Bounty2022-06-072023-06-13
1477Hacking 6.5+ million websites => CVE-2022-29455 (Elementor) XSS NA Rotem Bar (@rotembar) Bug Bounty2022-06-122023-06-13
1465Automating reflected XSS with burp-suite Intruder Reflected XSS NA Santosh Kumar Sha (@killmongar1996) Bug Bounty2022-06-142023-06-13
1457XSS Blind Stored at Asset Domain Android Apps TikTok Stored XSS TikTok Aidil Arief Bug Bounty2022-06-162023-06-13
1447Every XSS is different XSS NA Leonardo Bug Bounty2022-06-202023-06-13
1444XSS Vulnerability in IBM Content Navigator (CVE-2020-4757) XSS IBM Olivier Laflamme (@olivier_boschko) Bug Bounty2022-06-212023-06-13
1438Filesatck Upload Advisory Summary XSS Filestack Carlos Yanez Bug Bounty2022-06-232023-06-13
1412XSS Blind Stored at 2 Assets TikTok XSS TikTok Aidil Arief Bug Bounty2022-06-292023-06-13
1410Bypassing Firefox%27s HTML Sanitizer API XSS Mozilla Gareth Heyes (@garethheyes) Bug Bounty2022-06-292023-06-13
1409Visual Studio Code - Remote Code Execution in Restricted Mode (CVE-2021-43908) RCE XSS Microsoft s1r1us (@s1r1u5_) Bug Bounty2022-06-292023-06-13
1400We Hacked Larksuite For 1 month and Here is what we found XSS IDOR Privilege escalation Broken Access Control CSRF 40x bypass Lark Technologies Snap Sec (@snap_sec) Bug Bounty2022-07-042023-06-13