2045 | SEC-596 |
Reflected XSS |
cPanel |
sh1yo (@sh1yo_) |
Bug Bounty | 2021-11-29 | 2023-06-13 |
1840 | SQL Injection, Reflected XSS and Information Disclosure in one subdomain in just 10 minutes |
SQL injection
XSS
Information disclosure |
NA |
Mahmoud Hamed (@7odamo_) |
Bug Bounty | 2022-02-08 | 2023-06-13 |
1813 | My First Reflected XSS Bug Bounty — Google Dork — $xxx |
Reflected XSS |
NA |
Proviesec (@proviesec) |
Bug Bounty | 2022-02-16 | 2023-06-13 |
1672 | Multiple Times I Hacked Duke University With RXSS Vulnerability!!! |
Reflected XSS |
Duke University |
Amit Kumar (@Amitlt2) |
Bug Bounty | 2022-04-02 | 2023-06-13 |
1665 | Hacked Nokia With Reflected Cross-site Scripting Vulnerability…. |
Reflected XSS |
Nokia |
Amit Kumar (@Amitlt2) |
Bug Bounty | 2022-04-04 | 2023-06-13 |
1465 | Automating reflected XSS with burp-suite Intruder |
Reflected XSS |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1369 | From Open Redirect to Reflected XSS manually |
Open redirect
Reflected XSS |
NA |
Rodric |
Bug Bounty | 2022-07-14 | 2023-06-13 |
1366 | Tableau Server Leaks Sensitive Information From Reflected XSS |
Reflected XSS |
Salesforce |
Simon Bouchard (@SimTwisted) |
Bug Bounty | 2022-07-14 | 2023-06-13 |
1259 | Defeat the HttpOnly flag to achieve Account Takeover | RXSS |
Reflected XSS
Account takeover |
NA |
Mohamed Tarek (@timooon107) |
Bug Bounty | 2022-08-10 | 2023-06-13 |
1223 | Five-minute hunting for hidden XSS |
Reflected XSS |
NA |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-08-15 | 2023-06-13 |
1164 | How I found reflected XSS on IDFC Bank with burp-suite Intruder |
Reflected XSS |
IDFC Bank |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2022-08-28 | 2023-06-13 |
1162 | How I bypassed Reflected XSS in well-known platform |
XSS |
NA |
Iori Yagami |
Bug Bounty | 2022-08-29 | 2023-06-13 |
1036 | Escalating SSTI to Reflected XSS using curly braces {} |
SSTI
XSS |
NA |
Sagar Sajeev (@Sagar__Sajeev) |
Bug Bounty | 2022-09-24 | 2023-06-13 |
1019 | CVE-2022-37461: Two Reflected XSS Vulnerabilities in Canon Medical’s Vitrea View |
Reflected XSS |
Canon |
Jordan Hedges |
Bug Bounty | 2022-09-29 | 2023-06-13 |
982 | Reflected cross-site scripting vulnerability in Crealogix EBICS implementation |
Reflected XSS |
CREALOGIX AG |
Tobias Ospelt (@floyd_ch) |
Bug Bounty | 2022-10-10 | 2023-06-13 |
890 | CVE-2022-22241: Juniper SSLVPN / JunOS RCE and Multiple Vulnerabilities |
RCE
Phar deserialization
Reflected XSS
XPATH injection
Path traversal
LFI |
Juniper |
Paulos Yibelo (@PaulosYibelo) |
Bug Bounty | 2022-10-28 | 2023-06-13 |
836 | Finding Reflected XSS In A Strange Way |
XSS |
NA |
Raymond Lind |
Bug Bounty | 2022-11-11 | 2023-06-13 |
759 | Cross-Site Scripting in CodeIgniter version 3.1.13 |
Reflected XSS
Security code review |
CodeIgniter |
Antoine Cervoise |
Bug Bounty | 2022-11-29 | 2023-06-13 |
623 | Vue JS Reflected XSS |
Reflected XSS
Blind XSS
CORS misconfiguration
UI redressing |
NA |
sid0krypt (@Siddhar07949650) |
Bug Bounty | 2023-01-03 | 2023-06-13 |
558 | Bypassing Cloudflare WAF: XSS via SQL Injection |
Reflected XSS
SQL injection
WAF bypass |
NA |
Uku Sõrmus |
Bug Bounty | 2023-01-21 | 2023-06-13 |
557 | How I found XSS on Admin Page without login! |
Reflected XSS |
NA |
Abdelrhman Allam (@sl4x0) |
Bug Bounty | 2023-01-22 | 2023-06-13 |
556 | Reflected XSS Leads to 3,000$ Bug Bounty Rewards from Microsoft Forms |
Reflected XSS |
Microsoft |
Supakiad S. (@Supakiad_Mee) |
Bug Bounty | 2023-01-22 | 2023-06-13 |
503 | Discovering 5 XSS Vulnerabilities In a Simple Way With Xssor.go |
Reflected XSS |
NA |
Fares Walid (@SirBagoza) |
Bug Bounty | 2023-02-02 | 2023-06-13 |
481 | Reflected XSS on Target with tough WAF ( WAF Bypass ) |
Reflected XSS
WAF bypass |
NA |
Eagle_92 |
Bug Bounty | 2023-02-08 | 2023-06-13 |
451 | Securing Open-Source Solutions: A Study of osTicket Vulnerabilities |
Stored XSS
Reflected XSS
SQL injection
Session fixation |
osTicket |
Miguel Correia |
Bug Bounty | 2023-02-14 | 2023-06-13 |