Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
754Stored XSS at https://www.tiktok.com/ the name of the attacker’s account carrying XSS payload will be triggered when the victim Send Video Stored XSS TikTok Aidil Arief Bug Bounty2022-11-302023-06-13
685CVE-2022-42710: A journey through XXE to Stored-XSS Stored XSS XXE Security code review Linear Omar Hashem (@OmarHashem666) Bug Bounty2022-12-162023-06-13
682I Hope This Sticks: Analyzing ClipboardEvent Listeners for Stored XSS Stored XSS Self-XSS Zoom Eugene Lim (@spaceraccoonsec) Bug Bounty2022-12-172023-06-13
645Stored XSS vulnerability in Microsoft booking Stored XSS CSP bypass Microsoft Mrtechghost Bug Bounty2022-12-272023-06-13
613Advanced CSRF Exploitation CSRF Stored XSS NA Sandro Einfeldt Bug Bounty2023-01-072023-06-13
561CSRF + Stored XSS Leading to Full Account Takeover Stored XSS CSRF Account takeover NA Fares Walid (@SirBagoza) Bug Bounty2023-01-202023-06-13
544MyBB <= 1.8.31: Remote Code Execution Chain RCE SQL injection Stored XSS MyBB Aleksey Solovev Bug Bounty2023-01-252023-06-13
451Securing Open-Source Solutions: A Study of osTicket Vulnerabilities Stored XSS Reflected XSS SQL injection Session fixation osTicket Miguel Correia Bug Bounty2023-02-142023-06-13
387Interesting Stored XSS in sandboxed environment to Full Account Takeover Stored XSS Account takeover NA Anurag__Verma Bug Bounty2023-02-272023-06-13
329Self XSS To Stored Through IDOR/ IDOR Self-XSS Stored XSS NA Arben Shala (@arbennsh) Bug Bounty2023-03-082023-06-13
266CVE-2023–1410 : Stored XSS in the Graphite Function Description tooltip Stored XSS Grafana Labs Aswin K V (@deep_marketer_) Bug Bounty2023-03-252023-06-13
254It’s a (SNMP) Trap: Gaining Code Execution on LibreNMS RCE Stored XSS Security code review LibreNMS Stefan Schiller (@scryh_) Bug Bounty2023-03-292023-06-13
218Stored Cross-Site Scripting (XSS) in Zimbra version 8.8.15_GA_4059 CVE-2022-41348 Stored XSS Zimbra Guillaume Jacques Bug Bounty2023-04-072023-06-13
211CVE-2023-1767 - Stored XSS on Snyk Advisor service can allow full fabrication of npm packages health score Stored XSS Markdown XSS Supply chain attack Snyk Gal Weizman (@WeizmanGal) Bug Bounty2023-04-102023-06-13
141Bug Bounty Writeup: Stored XSS Vulnerability WAF Bypass Stored XSS WAF bypass NA Rafael Silva "lopseg" Bug Bounty2023-05-012023-06-13
114How a simple Directory Listing leads to PII Data Leakage, Remote Code Execution and many more vulnerabilities on a HR management subdomain RCE Unrestricted file upload Stored XSS Information disclosure Directory listing NA Aayush Vishnoi (@AayushVishnoi10) Bug Bounty2023-05-072023-06-13
25A short white box code audit of avo Stored XSS DoS Avo Paul Werther Bug Bounty2023-06-052023-06-13