1732 | My First Bug on VDP & BBP - Bug Bounty |
Stored XSS |
NA |
Aditya Singh / rook1337 (@imrook1337) |
Bug Bounty | 2022-03-15 | 2023-06-13 |
1729 | How I managed to trigger XSS automatically to get critical account takeover |
Stored XSS |
NA |
c4rrilat0r (@c4rrilat0r) |
Bug Bounty | 2022-03-15 | 2023-06-13 |
1676 | Small bugs are more dangerous than you think |
Self-XSS
Stored XSS
Open redirect
CSRF |
NA |
Liv Matan (@terminatorLM) |
Bug Bounty | 2022-04-01 | 2023-06-13 |
1596 | [EN] Privileged account creation via Mass Assignment towards a full compromise using a Stored XSS |
Stored XSS
Mass assignment
Security code review |
pass Culture |
Aethlios (@AethliosIK) |
Bug Bounty | 2022-04-26 | 2023-06-13 |
1550 | Bypassing WAF to Weaponize a Stored XSS |
Stored XSS |
NA |
ne555 |
Bug Bounty | 2022-05-17 | 2023-06-13 |
1457 | XSS Blind Stored at Asset Domain Android Apps TikTok |
Stored XSS |
TikTok |
Aidil Arief |
Bug Bounty | 2022-06-16 | 2023-06-13 |
1389 | stored XSS and stored HTML Injection in United Nations Website |
XSS
HTML injection |
United Nations |
Ahmed Hassan |
Bug Bounty | 2022-07-08 | 2023-06-13 |
1288 | Stored XSS to Account Takeover : Going beyond document.cookie | Stealing Session Data from IndexedDB |
Stored XSS
Account takeover |
NA |
Syed Mushfik Hasan Tahsin (@SMHTahsin33) |
Bug Bounty | 2022-08-02 | 2023-06-13 |
1269 | Stored XSS in app.gitbook.com |
Stored XSS |
GitBook |
Mohammad Alfin Hidayatullah (@Alpinbrainsec) |
Bug Bounty | 2022-08-08 | 2023-06-13 |
1225 | URL filter bypass, RFI and XSS |
Stored XSS
RFI |
NA |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-08-14 | 2023-06-13 |
1035 | Stored XSS in Nvidia via Angular JS template injection |
CSTI
Stored XSS |
Nvidia |
Mohamed Abdelhady |
Bug Bounty | 2022-09-25 | 2023-06-13 |
1010 | Zoneminder – Web App Testing – Oct 2022 |
DoS
Log injection
CSRF
Stored XSS |
ZoneMinder |
Trenches of IT (@TrenchesofIT) |
Bug Bounty | 2022-09-30 | 2023-06-13 |
939 | Vulnerabilities in Tenda%27s W15Ev2 AC1200 Router |
OS command injection
Buffer Overflow
Memory corruption
Stored XSS
Authorization flaw
Information disclosure |
Tenda |
Olivier Laflamme (@olivier_boschko) |
Bug Bounty | 2022-10-19 | 2023-06-13 |
934 | FabriXss (CVE-2022-35829): How We Managed to Abuse a Custom Role User Using CSTI and Stored XSS in Azure Fabric Explorer |
CSTI
Stored XSS |
Microsoft |
Lidor Ben Shitrit |
Bug Bounty | 2022-10-19 | 2023-06-13 |
916 | How I Found A Simple Stored XSS |
Stored XSS |
NA |
Raymond Lind |
Bug Bounty | 2022-10-24 | 2023-06-13 |
914 | 5000$ for Apple Stored Xss And Another Blind Xss Still under review |
Blind XSS |
Apple |
Abdelkader Mouaz (@hamzadzworm) |
Bug Bounty | 2022-10-24 | 2023-06-13 |
906 | GL.iNET GL-MT300N-V2 Router Vulnerabilities and Hardware Teardown |
OS command injection
Arbitrary file read
Information disclosure
Account takeover
Stored XSS
Lack of rate limiting
Weak credentials
Password policy bypass |
GL.iNet |
Olivier Laflamme (@olivier_boschko) |
Bug Bounty | 2022-10-26 | 2023-06-13 |
905 | Stored XSS To Cookie Exfiltration |
Stored XSS |
NA |
Raymond Lind |
Bug Bounty | 2022-10-26 | 2023-06-13 |
868 | Case of Admin Bypass for RCE, XSS, and Information Disclosure |
RCE
Unrestricted file upload
Stored XSS
Information disclosure |
NA |
Sam Paredes (@caffeinevulns) |
Bug Bounty | 2022-11-03 | 2023-06-13 |
864 | PENTEST TALES: EXIF Data Manipulation |
Unrestricted file upload
Stored XSS |
NA |
Armand Jasharaj |
Bug Bounty | 2022-11-05 | 2023-06-13 |
803 | How i found 29 stored XSS in modern framework |
Stored XSS |
NA |
Dewanand Vishal (@dewcode91) |
Bug Bounty | 2022-11-20 | 2023-06-13 |
794 | Interesting Stored XSS via meta data |
Stored XSS |
NA |
Veshraj Ghimire (@GhimireVeshraj) |
Bug Bounty | 2022-11-22 | 2023-06-13 |
791 | CVE-2021-40662 Chamilo LMS 1.11.14 RCE |
Stored XSS
CSRF
RCE |
Chamilo LMS |
Febin |
Bug Bounty | 2021-11-23 | 2023-06-13 |
790 | XSS Vulnerability Found in ConnectWise Remote Access Platform With Great Potential For Misuse by Scammers |
Stored XSS |
ConnectWise |
Nati Tal |
Bug Bounty | 2022-11-23 | 2023-06-13 |
772 | A great weekend hack(worth $8k) |
SQL injection
IDOR
Stored XSS |
NA |
Manas Harsh (@ManasH4rsh) |
Bug Bounty | 2022-11-26 | 2023-06-13 |