4156 | Stored XSS on Techprofile Microsoft |
Stored XSS |
Microsoft |
Mohammad Ali Syarief |
Bug Bounty | 2019-05-09 | 2023-06-13 |
4154 | Is MIME Sniffing XSS a real thing? [The story of weird Google bug bounties] |
Stored XSS
MIME sniffing |
Google |
Komodo Security |
Bug Bounty | 2019-05-15 | 2023-06-13 |
4131 | Stored XSS on Edmodo |
Stored XSS |
Edmodo |
Rohit Verma (@rv0x00) |
Bug Bounty | 2019-05-28 | 2023-06-13 |
4130 | Exploiting File Uploads Pt. 1 – MIME Sniffing to Stored XSS #bugbounty |
Stored XSS
MIME sniffing |
NA |
HackerOn2Wheels (@HackerOn2Wheels) |
Bug Bounty | 2019-05-30 | 2023-06-13 |
4067 | Stored XSS on Indeed |
Stored XSS |
Indeed |
Tirtha Mandal (@tirtha_mandal) |
Bug Bounty | 2019-06-30 | 2023-06-13 |
4062 | Yeah! I got P2 in 1 minute - Stored XSS via Markdown Editor |
Stored XSS |
NA |
Schopath |
Bug Bounty | 2019-07-02 | 2023-06-13 |
4060 | Story of a stored xss to full account takeover vulnerability(N/A to accepted) |
Stored XSS |
NA |
Jatin Aesthetic (@techyfreakk) |
Bug Bounty | 2019-07-04 | 2023-06-13 |
4037 | What do Netcat, SMTP and self XSS have in common? Stored XSS |
Stored XSS |
NA |
Plenum (@plenumlab) |
Bug Bounty | 2019-07-16 | 2023-06-13 |
4010 | Chaining Cache Poisoning To Stored XSS |
Web cache poisoning
Stored XSS |
NA |
Rohan aggarwal (@nahoragg) |
Bug Bounty | 2019-07-28 | 2023-06-13 |
4003 | Reposted [2017]: LinkedIn Hacker’s Experience |
Stored XSS |
LinkedIn |
Alexandru Coltuneac (@dekeeu) |
Bug Bounty | 2019-07-30 | 2023-06-13 |
3991 | Stored XSS on LaporBug.id |
Stored XSS |
LaporBug.id |
rizal (@sayadarijawa) |
Bug Bounty | 2019-08-05 | 2023-06-13 |
3988 | self XSS to stored XSS [ think out the box] |
Self-XSS
Stored XSS |
TIBCO |
Abdelhak Kharroubi |
Bug Bounty | 2019-08-06 | 2023-06-13 |
3984 | Writing my Medium blog to complete account takeover |
Stored XSS
Account takeover |
Medium |
Rotem Reiss (@rotem_reiss) |
Bug Bounty | 2019-08-09 | 2023-06-13 |
3975 | BugBounty WriteUp — take attention and get Stored XSS |
Stored XSS |
NA |
Oleksandr Opanasiuk (@Lekssik2) |
Bug Bounty | 2019-08-14 | 2023-06-13 |
3931 | H1-4420: From Quiz to Admin - Chaining Two 0-Days to Compromise An Uber Wordpress |
Stored XSS
SQL injection |
Uber |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2019-09-10 | 2023-06-13 |
3910 | Stored XSS on Zendesk via Macro’s PART 2 |
Stored XSS |
Zendesk |
Hariharan.s (@DJHARIZ1) |
Bug Bounty | 2019-09-20 | 2023-06-13 |
3805 | XSS Stored On [ Outlook Web — Outlook Android App ] |
Stored XSS |
Microsoft |
ElMahdi Mrhassel (@ElMrhassel) |
Bug Bounty | 2019-11-28 | 2023-06-13 |
3747 | Exploiting a Self Stored XSS with an IDOR |
Self-XSS
Stored XSS
IDOR |
NA |
Shuaib Oladigbolu (@_sawzeeyy) |
Bug Bounty | 2019-12-31 | 2023-06-13 |
3687 | Critical Security Flaw Found in WhatsApp Desktop Platform Allowing Cybercriminals Read From The File System Access |
Stored XSS
CSP bypass
Open redirect
RCE |
Meta / Facebook |
Gal Weizman (@WeizmanGal) |
Bug Bounty | 2020-02-04 | 2023-06-13 |
3686 | Arbitary File Upload too Stored XSS - Bug Bounty |
Arbitrary file upload
Stored XSS |
NA |
m0chan (@m0chan98) |
Bug Bounty | 2020-02-04 | 2023-06-13 |
3668 | CVE-2019-18426 - WhatsApp Vulnerabilities Disclosure - Open Redirect + CSP Bypass + Persistent XSS + FS read permissions + potential for RCE |
RCE
Stored XSS
CSP bypass
Arbitrary file read
Open redirect
Security code review |
Meta / Facebook (WhatsApp) |
Gal Weizman (@WeizmanGal) |
Bug Bounty | 2020-02-14 | 2023-06-13 |
3649 | Stored-XSS-on-groups-google-com |
Stored XSS |
Google |
Alessandro Rumampuk (@Rando02355205) |
Bug Bounty | 2020-02-25 | 2023-06-13 |
3586 | Pentesting Cisco SD-WAN Part 1: Attacking vManage |
Cypher injection
Stored XSS |
Cisco |
Julien Legras (@Julien_Legras) |
Bug Bounty | 2020-03-25 | 2023-06-13 |
3556 | Stored XSS in Google Nest |
Stored XSS |
Google |
Harikrishnan Chandraganesan (@hari_cybex) |
Bug Bounty | 2020-04-07 | 2023-06-13 |
3540 | CSRF to RCE bug chain in Prestashop v1.7.6.4 and below |
RCE
CSRF
Stored XSS
Unrestricted file upload |
PrestaShop |
Sivanesh Ashok (@sivaneshashok) |
Bug Bounty | 2020-04-18 | 2023-06-13 |