2495 | Joomla Password Reset Vulnerability And A Stored XSS For Full Compromise |
Password reset
Stored XSS
Privilege escalation
RCE
Security code review |
NA |
Adrian Tiron (@Adrian__T) |
Bug Bounty | 2021-06-07 | 2023-06-13 |
2466 | Account takeover via stored XSS with arbitrary file upload |
Insecure file upload
XSS
Account takeover |
NA |
0xbadb00da (@0xbadb00da) |
Bug Bounty | 2021-06-18 | 2023-06-13 |
2459 | Stored XSS via Invite leading to Mass Account Takeover at Opera. |
Stored XSS |
Opera |
Samrat Gupta (@Sm4rty_) |
Bug Bounty | 2021-06-20 | 2023-06-13 |
2409 | Stored XSS in Google Doubleclick Studio [Google Research Grant] |
Stored XSS |
Google |
Jasminder Pal Singh (@Singh_Jasminder) |
Bug Bounty | 2021-07-14 | 2023-06-13 |
2394 | Escalating Self-XSS To Stored XSS via Image injection + IDOR |
Self-XSS
Stored XSS
IDOR |
NA |
Demon (@R29k_) |
Bug Bounty | 2021-07-21 | 2023-06-13 |
2368 | Account takeover via stored xss |
Stored XSS |
NA |
vikram naidu (@ImVikram7msd) |
Bug Bounty | 2021-07-30 | 2023-06-13 |
2364 | How I escalate my Self-Stored XSS to Account Takeover with the help of IDOR |
Self-XSS
IDOR
Account takeover |
HackerEarth |
Jefferson Gonzales (@gonzxph) |
Bug Bounty | 2021-07-31 | 2023-06-13 |
2335 | Multiple Vulnerabilities In cPanel/WHM |
XXE
Stored XSS
Privilege escalation
CSRF
Cross-Site WebSocket Hijacking (CSWH) |
cPanel |
Adrian Tiron (@adrian__t) |
Bug Bounty | 2021-08-10 | 2023-06-13 |
2307 | MonkeyType.com Stored Cross-Site Scripting |
Stored XSS
Authentication bypass
IDOR |
MonkeyType.com |
Tyle Butler (@tbutler0x90) |
Bug Bounty | 2021-08-22 | 2023-06-13 |
2241 | Bug Bounty Guest Post: Local File Read via Stored XSS in The Opera Browser |
Stored XSS
Local File Read |
Opera |
Renwa (@RenwaX23) |
Bug Bounty | 2021-09-08 | 2023-06-13 |
2223 | Microsoft Azure Portal – Persistent Cross-Site Scripting |
Stored XSS |
Microsoft |
Christian Becker (@0xchrisb) |
Bug Bounty | 2021-09-15 | 2023-06-13 |
2186 | Zero-Day: Hijacking iCloud Credentials with Apple Airtags (Stored XSS) |
Stored XSS |
Apple |
Bobby Rauch / Bobbyr |
Bug Bounty | 2021-09-28 | 2023-06-13 |
2177 | Privilege Escalation to stored XSS |
Privilege escalation
HTTP response manipulation
Stored XSS |
NA |
Rohit Kumar (Rohit_443) |
Bug Bounty | 2021-10-01 | 2023-06-13 |
2168 | [EN] Stored XSS in the administrator’s panel due to misuse of MarkupSafe |
Stored XSS |
pass Culture |
Aethlios (@AethliosIK) |
Bug Bounty | 2021-10-06 | 2023-06-13 |
2133 | Moodle - Stored XSS and blind SSRF possible via feedback answer text |
Stored XSS
SSRF |
Moodle |
rekter0 (@rekter0) |
Bug Bounty | 2021-10-22 | 2023-06-13 |
2114 | Write Up – XSS Stored In api.media.atlassian.com Via Doc File (iOS) |
Stored XSS |
Atlassian |
Omar Espino (@omespino) |
Bug Bounty | 2021-10-28 | 2023-06-13 |
2012 | Account Takeover via Stored XSS |
Account takeover
Stored XSS |
NA |
Demon (@R29k_) |
Bug Bounty | 2021-12-09 | 2023-06-13 |
2001 | SVG based Stored XSS |
Stored XSS |
NA |
xaonan44 |
Bug Bounty | 2021-12-12 | 2023-06-13 |
1988 | Stored XSS by bypassing signature |
XSS
Unrestricted file upload |
NA |
Abdulrahman Makki (@AMakki1337) |
Bug Bounty | 2021-12-20 | 2023-06-13 |
1955 | Bug Hunting Journey of 2021 |
Stored XSS
Open redirect
Token leak
CSRF
Logic flaw
Information disclosure
IDOR
Account takeover |
NA |
Sudhanshu Rajbhar (@sudhanshur705) |
Bug Bounty | 2021-12-31 | 2023-06-13 |
1878 | How I Made $16,500 Hacking CDN Caching Servers — Part 1 |
Web cache poisoning
Stored XSS
Web cache deception |
NA |
Kevin (@bxmbn) |
Bug Bounty | 2022-01-29 | 2023-06-13 |
1873 | Stored Cross-Site Scripting in MediaWiki |
Stored XSS |
NA |
Nick Berrie (@machevalia) |
Bug Bounty | 2022-01-28 | 2023-06-13 |
1805 | Stored XSS in message.alibaba.com ($2,000) |
Stored XSS |
Alibaba |
R ando (@Rando02355205) |
Bug Bounty | 2022-02-18 | 2023-06-13 |
1770 | CVE-2022-24948: Apache JSPWiki preauth Stored XSS to ATO |
Stored XSS
Account takeover |
Apache |
Paulos Yibelo (@PaulosYibelo) |
Bug Bounty | 2022-03-02 | 2023-06-13 |
1742 | A Tale of Open Redirection to Stored XSS |
Stored XSS
Open redirect |
NA |
Tushar Sharma (@tusharSharma_0) |
Bug Bounty | 2022-03-12 | 2023-06-13 |