5290 | Facebook XSS via Cross-Origin Resource Sharing |
XSS |
Meta / Facebook |
Matt Austin (@mattaustin) |
Bug Bounty | 2010-07-06 | 2023-06-13 |
5289 | Hacking Facebook with FBML and DOM |
XSS |
Meta / Facebook |
Matt Austin (@mattaustin) |
Bug Bounty | 2010-07-18 | 2023-06-13 |
5288 | Facebook FBML DOM Traversal (Information Disclosure) |
Information disclosure |
Meta / Facebook |
Matt Austin (@mattaustin) |
Bug Bounty | 2011-08-23 | 2023-06-13 |
5259 | Flickr XSS (Stored / DOM XSS) |
XSS |
Flickr |
Matt Austin (@mattaustin) |
Bug Bounty | 2013-12-18 | 2023-06-13 |
5247 | Google Docs %27ClickJacking%27 (Information Disclosure) |
Clickjacking |
Google |
Matt Austin (@mattaustin) |
Bug Bounty | 2014-05-13 | 2023-06-13 |
5245 | ebay bug bounty |
Reflected XSS |
Ebay |
Matthew Bryant (@IAmMandatory) |
Bug Bounty | 2014-06-06 | 2023-06-13 |
5207 | XSS to RCE in Atlassian Hipchat |
XSS
RCE |
Atlassian |
Matt Austin (@mattaustin) |
Bug Bounty | 2015-11-15 | 2023-06-13 |
5178 | Poisoning the Well – Compromising GoDaddy Customer Support With Blind XSS |
Blind XSS |
GoDaddy |
Matthew Bryant (@IAmMandatory) |
Bug Bounty | 2016-05-08 | 2023-06-13 |
5146 | Floating Domains – Taking Over 20K DigitalOcean Domains via a Lax Domain Import System |
Subdomain takeover |
DigitalOcean |
Matthew Bryant (@IAmMandatory) |
Bug Bounty | 2016-08-25 | 2023-06-13 |
5118 | The Orphaned Internet – Taking Over 120K Domains via a DNS Vulnerability in AWS, Google Cloud, Rackspace and Digital Ocean |
Domain takeover |
Google
Amazon
Rackspace
DigitalOcean |
Matthew Bryant (@IAmMandatory) |
Bug Bounty | 2016-12-05 | 2023-06-13 |
5056 | How I hacked 23.900.000 tumblr domains at once :) |
IDOR |
Automattic |
Ak1T4 (@akita_zen) |
Bug Bounty | 2017-06-19 | 2023-06-13 |
4967 | Craft CMS – Why case matters |
Reflected XSS
Content injection |
Craft CMS |
Markus Krell (@MarkusKrell) |
Bug Bounty | 2017-10-01 | 2023-06-13 |
4926 | Taking note: XSS to RCE in the Simplenote Electron client |
XSS
RCE |
Automattic |
Yasin Soliman (@SecurityYasin) |
Bug Bounty | 2017-11-22 | 2023-06-13 |
4740 | Reading Your Emails With A Read&Write Chrome Extension Same Origin Policy Bypass (~8 Million Users Affected) |
SOP bypass
Browser extension hacking |
NA |
Matthew Bryant (@IAmMandatory) |
Bug Bounty | 2018-06-05 | 2023-06-13 |
4733 | Steam, Fire, and Paste – A Story of UXSS via DOM-XSS & Clickjacking in Steam Inventory Helper |
DOM XSS
Universal XSS
Clickjacking
Browser extension hacking |
NA |
Matthew Bryant (@IAmMandatory) |
Bug Bounty | 2018-06-08 | 2023-06-13 |
4706 | https://leigh-annegalloway.com/tumblr/ |
Captcha bypass
Username enumeration
Information disclosure |
Automattic |
Leigh-Anne Galloway (@L_AGalloway) |
Bug Bounty | 2018-06-29 | 2023-06-13 |
4600 | Stored XSS Vulnerability in Tumblr |
Stored XSS |
Automattic |
Anas Mahmood (@AnasIsHere) |
Bug Bounty | 2018-09-08 | 2023-06-13 |
4586 | How I hijacked your account when you opened my cat picture |
Logout CSRF |
NA |
Matti Bijnens (@MattiBijnens) |
Bug Bounty | 2018-09-14 | 2023-06-13 |
4490 | WordPress Design Flaw Leads to WooCommerce RCE |
RCE |
Automattic (WooCommerce) |
Simon Scannell (@scannell_simon) |
Bug Bounty | 2018-11-06 | 2023-06-13 |
4166 | Remote code execution On Microsoft edge using URL Protocol |
RCE |
Microsoft |
Matt harr0ey (@harr0ey) |
Bug Bounty | 2019-05-01 | 2023-06-13 |
4110 | How spending our Saturday hacking earned us 20k |
IDOR |
NA |
Matti Bijnens (@MattiBijnens) |
Bug Bounty | 2019-06-14 | 2023-06-13 |
3843 | Keylogging users via Slack themes |
CSS injection |
Slack |
Matt Langlois (@fletchto99) |
Bug Bounty | 2019-11-11 | 2023-06-13 |
3694 | OK Google: bypass the authentication! |
Authentication bypass |
Google |
Mattia Vinci |
Bug Bounty | 2020-01-31 | 2023-06-13 |
3692 | Tumblr Bug Bounty ( $200) |
Unrestricted file upload
XSS
Authorization flaw |
Automattic |
Myo Min Thu (@myominthu1337) |
Bug Bounty | 2020-02-02 | 2023-06-13 |
3650 | Discord DoS with a single message |
DoS |
Discord |
DarkMatterMatt |
Bug Bounty | 2020-02-24 | 2023-06-13 |