1676 | Small bugs are more dangerous than you think |
Self-XSS
Stored XSS
Open redirect
CSRF |
NA |
Liv Matan (@terminatorLM) |
Bug Bounty | 2022-04-01 | 2023-06-13 |
1575 | Chained Bug: XML File Upload to XSS to CSRF to Full Account Take Over (ATO) |
XSS
CSRF
Account takeover |
NA |
Zulfi Al-Farizi |
Bug Bounty | 2022-05-06 | 2023-06-13 |
1562 | The Underrated Bugs, Clickjacking, CSS Injection, Drag-Drop XSS, Cookie Bomb, Login+Logout CSRF… |
CSS injection
Clickjacking
Account takeover
XSS
Cookie bomb
Self-XSS
CSRF |
NA |
Renwa (@RenwaX23) |
Bug Bounty | 2022-05-10 | 2023-06-13 |
1549 | Stealing Google Drive OAuth tokens from Dropbox |
CSRF
SSRF
Account takeover |
Dropbox |
Sivanesh Ashok (@sivaneshashok) |
Bug Bounty | 2022-05-17 | 2023-06-13 |
1531 | 2FA Bypass on private bug bounty program due to CSRF token misconfiguration |
MFA bypass |
NA |
Sharat Kaikolamthuruthil (@sharp488) |
Bug Bounty | 2022-05-22 | 2023-06-13 |
1499 | If It’s a Feature!!! Let’s Abuse It for $750 |
CSRF |
NA |
Shakti Mohanty (@3ncryptSaan) |
Bug Bounty | 2022-06-05 | 2023-06-13 |
1454 | CSRF leads to account takeover in Yahoo! |
CSRF
Account takeover |
Yahoo! / Verizon Media |
Retr02332 (@Retr02332) |
Bug Bounty | 2022-06-16 | 2023-06-13 |
1400 | We Hacked Larksuite For 1 month and Here is what we found |
XSS
IDOR
Privilege escalation
Broken Access Control
CSRF
40x bypass |
Lark Technologies |
Snap Sec (@snap_sec) |
Bug Bounty | 2022-07-04 | 2023-06-13 |
1381 | How we have pwned Root-Me in 2022 |
XSS
CSRF
RCE |
SPIP |
SpawnZii (@SpawnZii) |
Bug Bounty | 2022-07-12 | 2023-06-13 |
1379 | How a Simple IDOR Led Me to Delete Any Account |
IDOR
CSRF |
NA |
rajesh.r (@_rajesh_ranjan_) |
Bug Bounty | 2022-07-12 | 2023-06-13 |
1248 | My Experience on Hacking the Dutch Government |
XSS
Open redirect
CSRF
Account takeover |
Dutch Government |
Jefferson Gonzales (@gonzxph) |
Bug Bounty | 2022-08-11 | 2023-06-13 |
1245 | IAM Whoever I Say IAM :: Infiltrating VMWare Workspace ONE Access Using a 0-Click Exploit |
Authentication bypass
Information disclosure
CSRF
RCE
Local Privilege Escalation |
VMware |
Steven Seeley (@steventseeley) |
Bug Bounty | 2022-08-11 | 2023-06-13 |
1213 | CSRF leads to Account Takeover | Samsung |
CSRF
Account takeover |
Samsung |
R ando (@Rando02355205) |
Bug Bounty | 2022-08-16 | 2023-06-13 |
1166 | CSRF Vulnerability In The NodeJS Ecosystem |
CSRF |
Node.js third-party modules (csurf) |
Adrian Tiron (@adrian__t) |
Bug Bounty | 2022-08-28 | 2023-06-13 |
1092 | Bug Bounty - Cross-site request forgery is a thing |
CSRF
XSS |
NA |
Patrick Hener (@C1sc01) |
Bug Bounty | 2022-09-12 | 2023-06-13 |
1059 | Apollo Router Security Audit Report (Q2 2022) |
DoS
CSRF |
Apollo GraphQL |
Norbert Szetei (@73696e65) |
Bug Bounty | 2022-09-20 | 2023-06-13 |
1010 | Zoneminder – Web App Testing – Oct 2022 |
DoS
Log injection
CSRF
Stored XSS |
ZoneMinder |
Trenches of IT (@TrenchesofIT) |
Bug Bounty | 2022-09-30 | 2023-06-13 |
1005 | CSRF Attack — 0 click account delete - 1st write-up |
CSRF
HTML injection |
NA |
Deepak (@bug_vs_me) |
Bug Bounty | 2022-10-03 | 2023-06-13 |
993 | Mr. Robot: Self Xss from Informative to high 1200$ ,csrf, open redirect,self xss to stored |
Self-XSS
CSRF |
NA |
Ahmad A Abdulla (@lu3ky13) |
Bug Bounty | 2022-10-06 | 2023-06-13 |
949 | Facebook SMS Captcha Was Vulnerable to CSRF Attack |
CSRF |
Meta / Facebook |
Lokesh Kumar (@lokeshdlk77) |
Bug Bounty | 2022-10-17 | 2023-06-13 |
908 | Chaining multiple vulnerabilities for credential stealing |
CSRF
Self-XSS
XSS |
NA |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-10-25 | 2023-06-13 |
866 | CSRF Leads to Delete User Account |
CSRF |
NA |
Omarbakrey |
Bug Bounty | 2022-11-04 | 2023-06-13 |
854 | Compromising Plesk Via Its REST API |
CORS misconfiguration
CSRF |
Plesk |
Adrian Tiron (@Adrian__T) |
Bug Bounty | 2022-11-08 | 2023-06-13 |
821 | CVE-2022-41622 and CVE-2022-41800 (FIXED): F5 BIG-IP and iControl REST Vulnerabilities and Exposures |
CSRF
RCE
RPM Spec Injection |
F5 |
Ron Bowes (@iagox86) |
Bug Bounty | 2022-11-16 | 2023-06-13 |
791 | CVE-2021-40662 Chamilo LMS 1.11.14 RCE |
Stored XSS
CSRF
RCE |
Chamilo LMS |
Febin |
Bug Bounty | 2021-11-23 | 2023-06-13 |