2981 | "Important, Spoofing" - zero-click, wormable, cross-platform remote code execution in Microsoft Teams |
RCE
Stored XSS
CSP bypass
CSTI |
Microsoft |
Oskars Vegeris |
Bug Bounty | 2020-12-07 | 2023-06-13 |
2971 | How i got my First Bug Bounty in Intersting Target (LFI to SXSS) |
LFI
Stored XSS |
NA |
Ph.Hitachi |
Bug Bounty | 2020-12-11 | 2023-06-13 |
2920 | Stored XSS on Product Description [HIGH] — $400 |
Stored XSS |
NA |
Emanuel Beni Harijanto |
Bug Bounty | 2021-01-07 | 2023-06-13 |
2899 | How I managed to trigger a Stored-XSS in an online store with the help of Cache Poisoning |
Web cache poisoning
Stored XSS |
NA |
Schizo! |
Bug Bounty | 2021-01-14 | 2023-06-13 |
2885 | How I was rewarded a $1000 bounty after abusing File Upload functionality to Stored XSS Vulnerability leading to credential theft of a vistor in a website. |
Unrestricted file upload
Stored XSS |
NA |
Kunal Khubchandani (@iamkun4l) |
Bug Bounty | 2021-01-18 | 2023-06-13 |
2862 | Bragging Rights(Part 1): Short story of a bug wave |
IDOR
Stored XSS
SSRF
Subdomain takeover
Hardcoded credentials |
NA |
Manas Harsh (@ManasH4rsh) |
Bug Bounty | 2021-01-27 | 2023-06-13 |
2854 | Destroying Armies and Villages through Cross-Site Scripting - Bug Bounty Write-up |
Stored XSS |
InnoGames |
Fábio Freitas (@0xfabiof) |
Bug Bounty | 2021-01-29 | 2023-06-13 |
2853 | Broken Access Control & Stored XSS - Easy Hunt |
Stored XSS
IDOR |
NA |
Kabeer (@iTheKabeer) |
Bug Bounty | 2021-01-29 | 2023-06-13 |
2840 | How I was able to Turn a XSS into a Account Takeover |
Web cache poisoning
Stored XSS
Account takeover
OAuth
Logic flaw |
NA |
Josh Fam (@Pullerze) |
Bug Bounty | 2021-02-03 | 2023-06-13 |
2808 | My first bounty (stored-xss) |
Stored XSS |
NA |
Karan sharma (@karansh491) |
Bug Bounty | 2021-02-14 | 2023-06-13 |
2807 | Stored XSS in icloud.com — $5000 |
Stored XSS |
NA |
Vishal Bharad |
Bug Bounty | 2021-02-14 | 2023-06-13 |
2769 | Poisoning your Cache for 1000$ - Approach to Exploitation Walkthrough |
Web cache poisoning
Stored XSS |
NA |
Gal Nagli (@naglinagli) |
Bug Bounty | 2021-02-25 | 2023-06-13 |
2755 | Bragging Rights: Killing File Uploads softly |
Unrestricted file upload
Stored XSS |
NA |
Manas Harsh (@ManasH4rsh) |
Bug Bounty | 2021-02-28 | 2023-06-13 |
2742 | Stored XSS at Trello.com |
Stored XSS |
Trello |
Maor Dayan (@mord1234) |
Bug Bounty | 2021-03-04 | 2023-06-13 |
2734 | Stored XSS in Google Ads Android Application— $3133.70 |
Stored XSS
HTML injection |
Google |
Ashish Dhone (@ashketchum_16) |
Bug Bounty | 2021-03-07 | 2023-06-13 |
2721 | Finding keys under the door |
Stored XSS
Unrestricted file upload |
Paytm |
Naveen Prakaasham K S V |
Bug Bounty | 2021-03-12 | 2023-06-13 |
2691 | Encrypted Payload -> Decrypted Execution ($600) : Stored XSS |
Stored XSS |
NA |
Shrirang Diwakar |
Bug Bounty | 2021-03-25 | 2023-06-13 |
2669 | Automate Cache Poisoning Vulnerability - Nuclei |
Web cache poisoning
Stored XSS |
NA |
Mohamed Elbadry (@_melbadry9) |
Bug Bounty | 2021-04-02 | 2023-06-13 |
2638 | How I earned $$$$ through Stored XSS |
Stored XSS
CSTI |
NA |
Harish |
Bug Bounty | 2021-04-16 | 2023-06-13 |
2633 | XSS via Exif Data - The P2 Elevator |
Stored XSS |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2021-04-18 | 2023-06-13 |
2631 | Pwning your assignments: Stored XSS via GraphQL endpoint |
Stored XSS
GraphQL |
NA |
Kartik Sharma (@dominat0r98) |
Bug Bounty | 2021-04-18 | 2023-06-13 |
2621 | DMCA.COM Hack, Full Disclosure (With Proof-of-Concept) |
Privilege escalation
Client-side enforcement of server-side security
Stored XSS
Broken Access Control |
DMCA |
Joël Aviad Ossi |
Bug Bounty | 2021-04-21 | 2023-06-13 |
2566 | Stored XSS to Organisation Takeover |
Stored XSS |
NA |
Zaid Bhat (@zaidozaid) |
Bug Bounty | 2021-05-10 | 2023-06-13 |
2561 | How I find my first Stored XSS |
Stored XSS |
NA |
Filipe Azevedo (@filipaze_) |
Bug Bounty | 2021-05-13 | 2023-06-13 |
2526 | Stored XSS with two different parameters |
Reflected XSS |
NA |
Joel Cantu (@InfosecRintox) |
Bug Bounty | 2021-05-25 | 2023-06-13 |