3074 | Automating xss identification with Dalfox & Paramspider |
Reflected XSS |
NA |
Paras Arora (@parasarora06) |
Bug Bounty | 2020-10-27 | 2023-06-13 |
3011 | 2 Reflected XSS In Razer |
Reflected XSS |
Razer |
Mostafa |
Bug Bounty | 2020-11-21 | 2023-06-13 |
3010 | Weird (im)possible XSS on error page |
Reflected XSS |
NA |
Rody Shahnazarian (@Komradz86) |
Bug Bounty | 2020-11-21 | 2023-06-13 |
3009 | Escalating XSS to Account Takeover |
Reflected XSS
Account takeover |
NA |
Aditya Verma (@0cirius0) |
Bug Bounty | 2020-11-22 | 2023-06-13 |
3006 | Reflected Cross Site Scripting on REDACTED Program (Bounty: 750$) |
Reflected XSS |
NA |
can1337 (@canmustdie) |
Bug Bounty | 2020-11-23 | 2023-06-13 |
2989 | Cross Site Scripting (XSS) Reflected in one of the subdomains of “General Motors”(Bugbounty) |
Reflected XSS |
General Motors |
- |
Bug Bounty | 2020-12-03 | 2023-06-13 |
2948 | EN | Account Takeover via Web Cache Poisoning based Reflected XSS |
Reflected XSS
Web cache poisoning
Account takeover |
NA |
Lütfü Mert Ceylan (@lutfumertceylan) |
Bug Bounty | 2020-12-26 | 2023-06-13 |
2945 | Chaining CORS by Reflected xss to Account takeover #My first Blog |
CORS misconfiguration
Reflected XSS
Account takeover |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2020-12-26 | 2023-06-13 |
2869 | Chaining a self XSS to Account Takeover |
Self-XSS
Reflected XSS
Account takeover |
NA |
Arman Sameer (@ArmanSameer95) |
Bug Bounty | 2021-01-25 | 2023-06-13 |
2836 | Redwood Report2Web XSS and Frame injection |
Reflected XSS
Frame injection |
NA |
vict0ni (@vict0ni) |
Bug Bounty | 2021-02-04 | 2023-06-13 |
2830 | Reflected XSS on a Public Program |
Reflected XSS |
NA |
Naveen J (@thevillagehackr) |
Bug Bounty | 2021-02-08 | 2023-06-13 |
2825 | Self-XSS to rXSS via Uploaded File Name |
Self-XSS
Reflected XSS |
NA |
P4nda (@InfoSecP4nda) |
Bug Bounty | 2021-02-09 | 2023-06-13 |
2818 | Hacking Chess.com and Accessing 50 Million Customer Records |
Reflected XSS
Information disclosure
Account takeover |
Chess.com |
Sam Curry (@samwcyo) |
Bug Bounty | 2021-02-11 | 2023-06-13 |
2726 | Chain of Low Level Bugs and Misconfigurations Leads to Account Takeover |
Reflected XSS
Clickjacking
Account takeover |
NA |
pleorqy (@pleorqy) |
Bug Bounty | 2021-03-10 | 2023-06-13 |
2683 | A weird XSS |
Reflected XSS |
NA |
gato the wizard |
Bug Bounty | 2021-03-30 | 2023-06-13 |
2606 | Reflected XSS on Microsoft |
Reflected XSS |
Microsoft |
N45HT |
Bug Bounty | 2021-04-25 | 2023-06-13 |
2526 | Stored XSS with two different parameters |
Reflected XSS |
NA |
Joel Cantu (@InfosecRintox) |
Bug Bounty | 2021-05-25 | 2023-06-13 |
2421 | Reflected XSS Through Insecure Dynamic Loading |
XSS |
NA |
Greg Gibson |
Bug Bounty | 2021-07-11 | 2023-06-13 |
2396 | XSS-Through-Fuzzing-Default-IIS |
Reflected XSS |
NA |
0xdln (@0xdln) |
Bug Bounty | 2021-07-20 | 2023-06-13 |
2389 | How I Found Multiple Bugs On FaceBook In 1 Month And a Part For My Methodology & Tools |
SSTI
SQL injection
Authentication bypass
Privilege escalation
Reflected XSS |
Meta / Facebook |
Orwa Atyat (@GodfatherOrwa) |
Bug Bounty | 2021-07-23 | 2023-06-13 |
2383 | Mattermost Server v5.32 > v5.36 Reflected XSS in OAuth flow |
Reflected XSS
OAuth |
Mattermost |
zi0Black (@zi0Black) |
Bug Bounty | 2021-07-26 | 2023-06-13 |
2356 | Tale of XSS in Angular |
Reflected XSS |
NA |
Sicksec (@OriginalSicksec) |
Bug Bounty | 2021-08-02 | 2023-06-13 |
2291 | Reflective XSS via search box [Bypassing Cloudflare WAF]. |
Reflected XSS |
NA |
Friendly (@SkeletorKeys) |
Bug Bounty | 2021-08-26 | 2023-06-13 |
2217 | Weaponizing Reflected XSS to Account Takeover |
XSS
Account takeover |
NA |
Hassan Shahid (@pwnsauc3) |
Bug Bounty | 2021-09-16 | 2023-06-13 |
2073 | Diving into Open-source LMS Codebases |
Insecure file upload
Insecure deserialization
RCE
CSRF
SQL injection
Reflected XSS |
Moodle
Chamilo LMS |
Poh Jia Hao (@Chocologicall) |
Bug Bounty | 2021-11-16 | 2023-06-13 |