🎯 New Report #3185001: Order More Than Maximum Allowed Quantity
🔺Severity: null
👽 Reporter: blackbird azar
⭐️ Reputation: 102
🛠 State: resolved
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2025-06-09
⏰ Disclosed: 2025-09-02 15:13:03
📝 Summary: The business logic vulnerability allowed users to bypass the product quantity limits (1-20 items) through parameter manipulation. While the user interface enforced these limits, the necessary server-side validation was missing.
📂 Report JSON File: 3185001
@hackeronereports
🔺Severity: null
👽 Reporter: blackbird azar
⭐️ Reputation: 102
🛠 State: resolved
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2025-06-09
⏰ Disclosed: 2025-09-02 15:13:03
📝 Summary: The business logic vulnerability allowed users to bypass the product quantity limits (1-20 items) through parameter manipulation. While the user interface enforced these limits, the necessary server-side validation was missing.
📂 Report JSON File: 3185001
@hackeronereports
🎯 New Report #3228888: Account Takeover in Password Reset Function
🔺Severity: Critical
👽 Reporter: egsec
⭐️ Reputation: 158
🛠 State: resolved
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2025-06-28
⏰ Disclosed: 2025-09-02 15:08:31
📝 Summary: A critical authentication bypass vulnerability was present in the password reset functionality of the website. The vulnerability allowed attackers to take over any user account without requiring access to the victim's phone number or one-time password. The security flaw existed in the implementation of the "Forgot Password" feature, where the system relied on client-side responses to determine the success of OTP verification. An attacker could intercept the server response and manipulate it to bypass the OTP verification step entirely, allowing them to set a new password for the victim's account.
📂 Report JSON File: 3228888
@hackeronereports
🔺Severity: Critical
👽 Reporter: egsec
⭐️ Reputation: 158
🛠 State: resolved
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2025-06-28
⏰ Disclosed: 2025-09-02 15:08:31
📝 Summary: A critical authentication bypass vulnerability was present in the password reset functionality of the website. The vulnerability allowed attackers to take over any user account without requiring access to the victim's phone number or one-time password. The security flaw existed in the implementation of the "Forgot Password" feature, where the system relied on client-side responses to determine the success of OTP verification. An attacker could intercept the server response and manipulate it to bypass the OTP verification step entirely, allowing them to set a new password for the victim's account.
📂 Report JSON File: 3228888
@hackeronereports
🎯 New Report #1452774: Unauthenticated Sensitive Information Disclosure on █████████ CVE-2021-38314
🔺Severity: Medium
👽 Reporter: kuriyama
⭐️ Reputation: 7514
🛠 State: resolved
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2022-01-18
⏰ Disclosed: 2025-09-02 15:43:20
📝 Summary: The Gutenberg Template Library
🔺Severity: Medium
👽 Reporter: kuriyama
⭐️ Reputation: 7514
🛠 State: resolved
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2022-01-18
⏰ Disclosed: 2025-09-02 15:43:20
📝 Summary: The Gutenberg Template Library
🎯 New Report #1851895: Bug Report #23JAN136 (subdomain takeover via shopify )
🔺Severity: High
👽 Reporter: kuriyama
⭐️ Reputation: 7514
🛠 State: resolved
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2023-01-30
⏰ Disclosed: 2025-09-02 15:30:58
📝 Summary: A subdomain takeover vulnerability was identified on the domain █████████, where the subdomain pointed to an unclaimed Shopify instance. The vulnerability was successfully exploited by the researcher, who created a Shopify account, added the custom domain █████████, and demonstrated control over the subdomain by setting up a password-protected page.
📂 Report JSON File: 1851895
@hackeronereports
🔺Severity: High
👽 Reporter: kuriyama
⭐️ Reputation: 7514
🛠 State: resolved
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2023-01-30
⏰ Disclosed: 2025-09-02 15:30:58
📝 Summary: A subdomain takeover vulnerability was identified on the domain █████████, where the subdomain pointed to an unclaimed Shopify instance. The vulnerability was successfully exploited by the researcher, who created a Shopify account, added the custom domain █████████, and demonstrated control over the subdomain by setting up a password-protected page.
📂 Report JSON File: 1851895
@hackeronereports
🎯 New Report #1851886: Bug Report #23JAN135 (subdomain takeover via shopify )
🔺Severity: High
👽 Reporter: kuriyama
⭐️ Reputation: 7514
🛠 State: resolved
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2023-01-30
⏰ Disclosed: 2025-09-02 15:23:47
📝 Summary: The researcher discovered a subdomain takeover vulnerability affecting ██████████, which was pointing to an unclaimed Shopify instance. The researcher successfully demonstrated the takeover by claiming the subdomain and setting up a proof-of-concept storefront.
📂 Report JSON File: 1851886
@hackeronereports
🔺Severity: High
👽 Reporter: kuriyama
⭐️ Reputation: 7514
🛠 State: resolved
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2023-01-30
⏰ Disclosed: 2025-09-02 15:23:47
📝 Summary: The researcher discovered a subdomain takeover vulnerability affecting ██████████, which was pointing to an unclaimed Shopify instance. The researcher successfully demonstrated the takeover by claiming the subdomain and setting up a proof-of-concept storefront.
📂 Report JSON File: 1851886
@hackeronereports
🎯 New Report #3255473: Business Logic Error – Bypass of OTP Verification During Signup on hover.com
🔺Severity: Medium
👽 Reporter: c0rvuz
⭐️ Reputation: 113
🛠 State: resolved
💼 Team: Tucows (VDP)
💵 Bounty: null
🕐 Submitted: 2025-07-16
⏰ Disclosed: 2025-09-02 18:24:16
📝 Summary: The Business Logic Error – Bypass of OTP Verification During Signup on hover.com was a vulnerability that allowed an attacker to register an account on www.hover.com using any email address without passing the required OTP verification. The vulnerability was caused by the ability to omit the code parameter entirely from the signup request, which resulted in the backend completing the registration and returning a valid session, effectively bypassing the OTP verification mechanism.
📂 Report JSON File: 3255473
@hackeronereports
🔺Severity: Medium
👽 Reporter: c0rvuz
⭐️ Reputation: 113
🛠 State: resolved
💼 Team: Tucows (VDP)
💵 Bounty: null
🕐 Submitted: 2025-07-16
⏰ Disclosed: 2025-09-02 18:24:16
📝 Summary: The Business Logic Error – Bypass of OTP Verification During Signup on hover.com was a vulnerability that allowed an attacker to register an account on www.hover.com using any email address without passing the required OTP verification. The vulnerability was caused by the ability to omit the code parameter entirely from the signup request, which resulted in the backend completing the registration and returning a valid session, effectively bypassing the OTP verification mechanism.
📂 Report JSON File: 3255473
@hackeronereports
🎯 New Report #2189797: RXSS on stores on *█████████/visitorRegistration.pml via destination parameter
🔺Severity: Medium
👽 Reporter: kuriyama
⭐️ Reputation: 7514
🛠 State: resolved
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2023-10-02
⏰ Disclosed: 2025-09-02 15:18:10
📝 Summary: The vulnerability involved a reflected XSS in the destination parameter of the visitorRegistration.pml endpoint across all stores under ██████████. A working proof of concept was provided demonstrating JavaScript execution via URL parameter injection.
📂 Report JSON File: 2189797
@hackeronereports
🔺Severity: Medium
👽 Reporter: kuriyama
⭐️ Reputation: 7514
🛠 State: resolved
💼 Team: Mars
💵 Bounty: null
🕐 Submitted: 2023-10-02
⏰ Disclosed: 2025-09-02 15:18:10
📝 Summary: The vulnerability involved a reflected XSS in the destination parameter of the visitorRegistration.pml endpoint across all stores under ██████████. A working proof of concept was provided demonstrating JavaScript execution via URL parameter injection.
📂 Report JSON File: 2189797
@hackeronereports
🎯 New Report #3324190: Heap-buffer-overflow (Out-of-Bounds Read) in DoH hostname encoding
🔺Severity: None
👽 Reporter: reporascal 1
⭐️ Reputation: 131
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-09-02
⏰ Disclosed: 2025-09-04 06:10:43
📝 Summary: null
📂 Report JSON File: 3324190
@hackeronereports
🔺Severity: None
👽 Reporter: reporascal 1
⭐️ Reputation: 131
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-09-02
⏰ Disclosed: 2025-09-04 06:10:43
📝 Summary: null
📂 Report JSON File: 3324190
@hackeronereports
🎯 New Report #3161827: Session Persistence Designed to Keep Users Logged In Across Multiple Devices (Intended Behaviour)
🔺Severity: None
👽 Reporter: naveenventure
⭐️ Reputation: 52
🛠 State: informative
💼 Team: Shopify
💵 Bounty: null
🕐 Submitted: 2025-05-25
⏰ Disclosed: 2025-09-04 20:18:24
📝 Summary: null
📂 Report JSON File: 3161827
@hackeronereports
🔺Severity: None
👽 Reporter: naveenventure
⭐️ Reputation: 52
🛠 State: informative
💼 Team: Shopify
💵 Bounty: null
🕐 Submitted: 2025-05-25
⏰ Disclosed: 2025-09-04 20:18:24
📝 Summary: null
📂 Report JSON File: 3161827
@hackeronereports
🎯 New Report #3294999: CVE-2025-9086: Out of bounds read for cookie path
🔺Severity: Low
👽 Reporter: bigsleep
⭐️ Reputation: 107
🛠 State: resolved
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-08-11
⏰ Disclosed: 2025-09-10 06:05:13
📝 Summary: null
📂 Report JSON File: 3294999
@hackeronereports
🔺Severity: Low
👽 Reporter: bigsleep
⭐️ Reputation: 107
🛠 State: resolved
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-08-11
⏰ Disclosed: 2025-09-10 06:05:13
📝 Summary: null
📂 Report JSON File: 3294999
@hackeronereports
🎯 New Report #3330839: CVE-2025-10148: predictable WebSocket mask
🔺Severity: Low
👽 Reporter: cruocco
⭐️ Reputation: 107
🛠 State: resolved
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-09-08
⏰ Disclosed: 2025-09-10 06:05:01
📝 Summary: null
📂 Report JSON File: 3330839
@hackeronereports
🔺Severity: Low
👽 Reporter: cruocco
⭐️ Reputation: 107
🛠 State: resolved
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-09-08
⏰ Disclosed: 2025-09-10 06:05:01
📝 Summary: null
📂 Report JSON File: 3330839
@hackeronereports
🎯 New Report #3250691: 337k users and 1 employee leaked credentials
🔺Severity: High
👽 Reporter: meowsint
⭐️ Reputation: 106
🛠 State: resolved
💼 Team: Khan Academy
💵 Bounty: null
🕐 Submitted: 2025-07-14
⏰ Disclosed: 2025-09-10 14:44:42
📝 Summary: The Khan Academy website experienced a data breach, resulting in the leakage of 337.7k user accounts and one employee account. The leaked credentials, including email addresses and passwords, were discovered on a website called "leakradar.io".
📂 Report JSON File: 3250691
@hackeronereports
🔺Severity: High
👽 Reporter: meowsint
⭐️ Reputation: 106
🛠 State: resolved
💼 Team: Khan Academy
💵 Bounty: null
🕐 Submitted: 2025-07-14
⏰ Disclosed: 2025-09-10 14:44:42
📝 Summary: The Khan Academy website experienced a data breach, resulting in the leakage of 337.7k user accounts and one employee account. The leaked credentials, including email addresses and passwords, were discovered on a website called "leakradar.io".
📂 Report JSON File: 3250691
@hackeronereports
🎯 New Report #3012526: Chained Broken Access Control in TikTok Live Backstage Enables Full Control of Public Leaderboard Activities
🔺Severity: Medium
👽 Reporter: eneri
⭐️ Reputation: 685
🛠 State: resolved
💼 Team: TikTok
💵 Bounty: null
🕐 Submitted: 2025-02-25
⏰ Disclosed: 2025-09-11 01:59:00
📝 Summary: A broken access control vulnerability in TikTok Live Backstage allowed low-privilege users to gain unauthorized control over public leaderboard activities belonging to other organizations.
📂 Report JSON File: 3012526
@hackeronereports
🔺Severity: Medium
👽 Reporter: eneri
⭐️ Reputation: 685
🛠 State: resolved
💼 Team: TikTok
💵 Bounty: null
🕐 Submitted: 2025-02-25
⏰ Disclosed: 2025-09-11 01:59:00
📝 Summary: A broken access control vulnerability in TikTok Live Backstage allowed low-privilege users to gain unauthorized control over public leaderboard activities belonging to other organizations.
📂 Report JSON File: 3012526
@hackeronereports
🎯 New Report #3037447: Stored XSS on TikTok's backend leads to the leakage of highly sensitive administrator data (Cookies, API Keys, Internal Paths, Emails, phone numbers).
🔺Severity: Medium
👽 Reporter: ahmed xyz
⭐️ Reputation: 416
🛠 State: resolved
💼 Team: TikTok
💵 Bounty: null
🕐 Submitted: 2025-03-14
⏰ Disclosed: 2025-09-11 01:57:09
📝 Summary: A stored cross-site scripting vulnerability was discovered in TikTok's contact form backend. Malicious code submitted through the form executed when administrators viewed the submission, exposing sensitive internal data such as cookies, API keys, internal paths, emails, and phone numbers.
📂 Report JSON File: 3037447
@hackeronereports
🔺Severity: Medium
👽 Reporter: ahmed xyz
⭐️ Reputation: 416
🛠 State: resolved
💼 Team: TikTok
💵 Bounty: null
🕐 Submitted: 2025-03-14
⏰ Disclosed: 2025-09-11 01:57:09
📝 Summary: A stored cross-site scripting vulnerability was discovered in TikTok's contact form backend. Malicious code submitted through the form executed when administrators viewed the submission, exposing sensitive internal data such as cookies, API keys, internal paths, emails, and phone numbers.
📂 Report JSON File: 3037447
@hackeronereports
🎯 New Report #2588426: SQL injection in JSONField KeyTransform
🔺Severity: High
👽 Reporter: eyalsec
⭐️ Reputation: 167
🛠 State: resolved
💼 Team: Django
💵 Bounty: null
🕐 Submitted: 2024-07-07
⏰ Disclosed: 2025-09-12 00:28:00
📝 Summary: A vulnerability was discovered in the JSONField KeyTransform functionality of Django. The vulnerability allowed SQL injection attacks by crafting malicious user input for the .values() method. The vulnerability was demonstrated in the Django test suite, where a SQL syntax error was triggered by inputting a specifically crafted string.
📂 Report JSON File: 2588426
@hackeronereports
🔺Severity: High
👽 Reporter: eyalsec
⭐️ Reputation: 167
🛠 State: resolved
💼 Team: Django
💵 Bounty: null
🕐 Submitted: 2024-07-07
⏰ Disclosed: 2025-09-12 00:28:00
📝 Summary: A vulnerability was discovered in the JSONField KeyTransform functionality of Django. The vulnerability allowed SQL injection attacks by crafting malicious user input for the .values() method. The vulnerability was demonstrated in the Django test suite, where a SQL syntax error was triggered by inputting a specifically crafted string.
📂 Report JSON File: 2588426
@hackeronereports
🎯 New Report #2999394: Pivilege escalation of any new user to Keymaster caused by CSRF
🔺Severity: Medium
👽 Reporter: maxbr3n404
⭐️ Reputation: 117
🛠 State: resolved
💼 Team: WordPress
💵 Bounty: null
🕐 Submitted: 2025-02-18
⏰ Disclosed: 2025-09-13 16:36:36
📝 Summary: A vulnerability in the bbPress plugin allowed an attacker to escalate a newly registered user's forum role to bbp keymaster without proper authentication. This occurred because bbPress failed to implement adequate CSRF protections when assigning forum roles, allowing an attacker to craft a malicious request that upgraded a targeted user's forum privileges upon registration.
📂 Report JSON File: 2999394
@hackeronereports
🔺Severity: Medium
👽 Reporter: maxbr3n404
⭐️ Reputation: 117
🛠 State: resolved
💼 Team: WordPress
💵 Bounty: null
🕐 Submitted: 2025-02-18
⏰ Disclosed: 2025-09-13 16:36:36
📝 Summary: A vulnerability in the bbPress plugin allowed an attacker to escalate a newly registered user's forum role to bbp keymaster without proper authentication. This occurred because bbPress failed to implement adequate CSRF protections when assigning forum roles, allowing an attacker to craft a malicious request that upgraded a targeted user's forum privileges upon registration.
📂 Report JSON File: 2999394
@hackeronereports
🎯 New Report #1073725: DOM XSS on www.omnipod.com/freedom/birthdate-confirmation and www.omnipod.com/pif/thanks-freedom
🔺Severity: Medium
👽 Reporter: mechatech84
⭐️ Reputation: 107
🛠 State: resolved
💼 Team: Insulet Corporation
💵 Bounty: null
🕐 Submitted: 2021-01-07
⏰ Disclosed: 2025-09-13 20:19:33
📝 Summary: The DOM-based XSS vulnerability was found on the www.omnipod.com/freedom/birthdate-confirmation and www.omnipod.com/pif/thanks-freedom pages. The vulnerability was triggered by crafting a URL with malicious code in the query parameters, which was then executed by the vulnerable script on the page.
📂 Report JSON File: 1073725
@hackeronereports
🔺Severity: Medium
👽 Reporter: mechatech84
⭐️ Reputation: 107
🛠 State: resolved
💼 Team: Insulet Corporation
💵 Bounty: null
🕐 Submitted: 2021-01-07
⏰ Disclosed: 2025-09-13 20:19:33
📝 Summary: The DOM-based XSS vulnerability was found on the www.omnipod.com/freedom/birthdate-confirmation and www.omnipod.com/pif/thanks-freedom pages. The vulnerability was triggered by crafting a URL with malicious code in the query parameters, which was then executed by the vulnerable script on the page.
📂 Report JSON File: 1073725
@hackeronereports
🎯 New Report #3292573: SQL Injection when using FilteredRelation
🔺Severity: Critical
👽 Reporter: eyalsec
⭐️ Reputation: 167
🛠 State: resolved
💼 Team: Django
💵 Bounty: null
🕐 Submitted: 2025-08-09
⏰ Disclosed: 2025-09-15 14:01:21
📝 Summary: A SQL injection vulnerability was discovered in the Django framework when using the FilteredRelation feature. The vulnerability was located in the tests/filtered relation/tests.py file. The vulnerability allowed an attacker to inject malicious SQL code through the user data parameter used in the FilteredRelation and select related functions.
📂 Report JSON File: 3292573
@hackeronereports
🔺Severity: Critical
👽 Reporter: eyalsec
⭐️ Reputation: 167
🛠 State: resolved
💼 Team: Django
💵 Bounty: null
🕐 Submitted: 2025-08-09
⏰ Disclosed: 2025-09-15 14:01:21
📝 Summary: A SQL injection vulnerability was discovered in the Django framework when using the FilteredRelation feature. The vulnerability was located in the tests/filtered relation/tests.py file. The vulnerability allowed an attacker to inject malicious SQL code through the user data parameter used in the FilteredRelation and select related functions.
📂 Report JSON File: 3292573
@hackeronereports
🎯 New Report #2886723: GraphQL Introspection Enabled on Shopify API Endpoint (Intended Behavior)
🔺Severity: None
👽 Reporter: ahmednasr1
⭐️ Reputation: 94
🛠 State: informative
💼 Team: Shopify
💵 Bounty: null
🕐 Submitted: 2024-12-07
⏰ Disclosed: 2025-09-17 14:59:23
📝 Summary: null
📂 Report JSON File: 2886723
@hackeronereports
🔺Severity: None
👽 Reporter: ahmednasr1
⭐️ Reputation: 94
🛠 State: informative
💼 Team: Shopify
💵 Bounty: null
🕐 Submitted: 2024-12-07
⏰ Disclosed: 2025-09-17 14:59:23
📝 Summary: null
📂 Report JSON File: 2886723
@hackeronereports
🎯 New Report #1737358: URL Scheme Validation Bypass in Shopify Mobile App Allows Javascript Execution
🔺Severity: Low
👽 Reporter: fr4via
⭐️ Reputation: 10817
🛠 State: resolved
💼 Team: Shopify
💵 Bounty: null
🕐 Submitted: 2022-10-17
⏰ Disclosed: 2025-09-17 15:23:43
📝 Summary: A vulnerability in the Shopify mobile application allowed bypassing URL scheme validation in the NavigationActivity component. Attackers could craft malicious URLs using
📂 Report JSON File: 1737358
@hackeronereports
🔺Severity: Low
👽 Reporter: fr4via
⭐️ Reputation: 10817
🛠 State: resolved
💼 Team: Shopify
💵 Bounty: null
🕐 Submitted: 2022-10-17
⏰ Disclosed: 2025-09-17 15:23:43
📝 Summary: A vulnerability in the Shopify mobile application allowed bypassing URL scheme validation in the NavigationActivity component. Attackers could craft malicious URLs using
data: or javascript: schemes to execute JavaScript code within the app's webview context.📂 Report JSON File: 1737358
@hackeronereports
🎯 New Report #3228011: Critical Information Disclosure via /talos/api/v1/files/upload
🔺Severity: Critical
👽 Reporter: sameer ali
⭐️ Reputation: 417
🛠 State: resolved
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2025-06-27
⏰ Disclosed: 2025-09-17 19:09:12
📝 Summary: A vulnerability was discovered in the file upload functionality, where uploaded files were first stored on the server before being sent to S3. Due to a configuration flaw, memory chunks from the server were included in some uploaded files. This issue was classified as critical and was addressed as a priority.
📂 Report JSON File: 3228011
@hackeronereports
🔺Severity: Critical
👽 Reporter: sameer ali
⭐️ Reputation: 417
🛠 State: resolved
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2025-06-27
⏰ Disclosed: 2025-09-17 19:09:12
📝 Summary: A vulnerability was discovered in the file upload functionality, where uploaded files were first stored on the server before being sent to S3. Due to a configuration flaw, memory chunks from the server were included in some uploaded files. This issue was classified as critical and was addressed as a priority.
📂 Report JSON File: 3228011
@hackeronereports