🎯 New Report #3250691: 337k users and 1 employee leaked credentials
🔺Severity: High
👽 Reporter: meowsint
⭐️ Reputation: 106
🛠 State: resolved
💼 Team: Khan Academy
💵 Bounty: null
🕐 Submitted: 2025-07-14
⏰ Disclosed: 2025-09-10 14:44:42
📝 Summary: The Khan Academy website experienced a data breach, resulting in the leakage of 337.7k user accounts and one employee account. The leaked credentials, including email addresses and passwords, were discovered on a website called "leakradar.io".
📂 Report JSON File: 3250691
@hackeronereports
🔺Severity: High
👽 Reporter: meowsint
⭐️ Reputation: 106
🛠 State: resolved
💼 Team: Khan Academy
💵 Bounty: null
🕐 Submitted: 2025-07-14
⏰ Disclosed: 2025-09-10 14:44:42
📝 Summary: The Khan Academy website experienced a data breach, resulting in the leakage of 337.7k user accounts and one employee account. The leaked credentials, including email addresses and passwords, were discovered on a website called "leakradar.io".
📂 Report JSON File: 3250691
@hackeronereports
🎯 New Report #3012526: Chained Broken Access Control in TikTok Live Backstage Enables Full Control of Public Leaderboard Activities
🔺Severity: Medium
👽 Reporter: eneri
⭐️ Reputation: 685
🛠 State: resolved
💼 Team: TikTok
💵 Bounty: null
🕐 Submitted: 2025-02-25
⏰ Disclosed: 2025-09-11 01:59:00
📝 Summary: A broken access control vulnerability in TikTok Live Backstage allowed low-privilege users to gain unauthorized control over public leaderboard activities belonging to other organizations.
📂 Report JSON File: 3012526
@hackeronereports
🔺Severity: Medium
👽 Reporter: eneri
⭐️ Reputation: 685
🛠 State: resolved
💼 Team: TikTok
💵 Bounty: null
🕐 Submitted: 2025-02-25
⏰ Disclosed: 2025-09-11 01:59:00
📝 Summary: A broken access control vulnerability in TikTok Live Backstage allowed low-privilege users to gain unauthorized control over public leaderboard activities belonging to other organizations.
📂 Report JSON File: 3012526
@hackeronereports
🎯 New Report #3037447: Stored XSS on TikTok's backend leads to the leakage of highly sensitive administrator data (Cookies, API Keys, Internal Paths, Emails, phone numbers).
🔺Severity: Medium
👽 Reporter: ahmed xyz
⭐️ Reputation: 416
🛠 State: resolved
💼 Team: TikTok
💵 Bounty: null
🕐 Submitted: 2025-03-14
⏰ Disclosed: 2025-09-11 01:57:09
📝 Summary: A stored cross-site scripting vulnerability was discovered in TikTok's contact form backend. Malicious code submitted through the form executed when administrators viewed the submission, exposing sensitive internal data such as cookies, API keys, internal paths, emails, and phone numbers.
📂 Report JSON File: 3037447
@hackeronereports
🔺Severity: Medium
👽 Reporter: ahmed xyz
⭐️ Reputation: 416
🛠 State: resolved
💼 Team: TikTok
💵 Bounty: null
🕐 Submitted: 2025-03-14
⏰ Disclosed: 2025-09-11 01:57:09
📝 Summary: A stored cross-site scripting vulnerability was discovered in TikTok's contact form backend. Malicious code submitted through the form executed when administrators viewed the submission, exposing sensitive internal data such as cookies, API keys, internal paths, emails, and phone numbers.
📂 Report JSON File: 3037447
@hackeronereports
🎯 New Report #2588426: SQL injection in JSONField KeyTransform
🔺Severity: High
👽 Reporter: eyalsec
⭐️ Reputation: 167
🛠 State: resolved
💼 Team: Django
💵 Bounty: null
🕐 Submitted: 2024-07-07
⏰ Disclosed: 2025-09-12 00:28:00
📝 Summary: A vulnerability was discovered in the JSONField KeyTransform functionality of Django. The vulnerability allowed SQL injection attacks by crafting malicious user input for the .values() method. The vulnerability was demonstrated in the Django test suite, where a SQL syntax error was triggered by inputting a specifically crafted string.
📂 Report JSON File: 2588426
@hackeronereports
🔺Severity: High
👽 Reporter: eyalsec
⭐️ Reputation: 167
🛠 State: resolved
💼 Team: Django
💵 Bounty: null
🕐 Submitted: 2024-07-07
⏰ Disclosed: 2025-09-12 00:28:00
📝 Summary: A vulnerability was discovered in the JSONField KeyTransform functionality of Django. The vulnerability allowed SQL injection attacks by crafting malicious user input for the .values() method. The vulnerability was demonstrated in the Django test suite, where a SQL syntax error was triggered by inputting a specifically crafted string.
📂 Report JSON File: 2588426
@hackeronereports
🎯 New Report #2999394: Pivilege escalation of any new user to Keymaster caused by CSRF
🔺Severity: Medium
👽 Reporter: maxbr3n404
⭐️ Reputation: 117
🛠 State: resolved
💼 Team: WordPress
💵 Bounty: null
🕐 Submitted: 2025-02-18
⏰ Disclosed: 2025-09-13 16:36:36
📝 Summary: A vulnerability in the bbPress plugin allowed an attacker to escalate a newly registered user's forum role to bbp keymaster without proper authentication. This occurred because bbPress failed to implement adequate CSRF protections when assigning forum roles, allowing an attacker to craft a malicious request that upgraded a targeted user's forum privileges upon registration.
📂 Report JSON File: 2999394
@hackeronereports
🔺Severity: Medium
👽 Reporter: maxbr3n404
⭐️ Reputation: 117
🛠 State: resolved
💼 Team: WordPress
💵 Bounty: null
🕐 Submitted: 2025-02-18
⏰ Disclosed: 2025-09-13 16:36:36
📝 Summary: A vulnerability in the bbPress plugin allowed an attacker to escalate a newly registered user's forum role to bbp keymaster without proper authentication. This occurred because bbPress failed to implement adequate CSRF protections when assigning forum roles, allowing an attacker to craft a malicious request that upgraded a targeted user's forum privileges upon registration.
📂 Report JSON File: 2999394
@hackeronereports
🎯 New Report #1073725: DOM XSS on www.omnipod.com/freedom/birthdate-confirmation and www.omnipod.com/pif/thanks-freedom
🔺Severity: Medium
👽 Reporter: mechatech84
⭐️ Reputation: 107
🛠 State: resolved
💼 Team: Insulet Corporation
💵 Bounty: null
🕐 Submitted: 2021-01-07
⏰ Disclosed: 2025-09-13 20:19:33
📝 Summary: The DOM-based XSS vulnerability was found on the www.omnipod.com/freedom/birthdate-confirmation and www.omnipod.com/pif/thanks-freedom pages. The vulnerability was triggered by crafting a URL with malicious code in the query parameters, which was then executed by the vulnerable script on the page.
📂 Report JSON File: 1073725
@hackeronereports
🔺Severity: Medium
👽 Reporter: mechatech84
⭐️ Reputation: 107
🛠 State: resolved
💼 Team: Insulet Corporation
💵 Bounty: null
🕐 Submitted: 2021-01-07
⏰ Disclosed: 2025-09-13 20:19:33
📝 Summary: The DOM-based XSS vulnerability was found on the www.omnipod.com/freedom/birthdate-confirmation and www.omnipod.com/pif/thanks-freedom pages. The vulnerability was triggered by crafting a URL with malicious code in the query parameters, which was then executed by the vulnerable script on the page.
📂 Report JSON File: 1073725
@hackeronereports
🎯 New Report #3292573: SQL Injection when using FilteredRelation
🔺Severity: Critical
👽 Reporter: eyalsec
⭐️ Reputation: 167
🛠 State: resolved
💼 Team: Django
💵 Bounty: null
🕐 Submitted: 2025-08-09
⏰ Disclosed: 2025-09-15 14:01:21
📝 Summary: A SQL injection vulnerability was discovered in the Django framework when using the FilteredRelation feature. The vulnerability was located in the tests/filtered relation/tests.py file. The vulnerability allowed an attacker to inject malicious SQL code through the user data parameter used in the FilteredRelation and select related functions.
📂 Report JSON File: 3292573
@hackeronereports
🔺Severity: Critical
👽 Reporter: eyalsec
⭐️ Reputation: 167
🛠 State: resolved
💼 Team: Django
💵 Bounty: null
🕐 Submitted: 2025-08-09
⏰ Disclosed: 2025-09-15 14:01:21
📝 Summary: A SQL injection vulnerability was discovered in the Django framework when using the FilteredRelation feature. The vulnerability was located in the tests/filtered relation/tests.py file. The vulnerability allowed an attacker to inject malicious SQL code through the user data parameter used in the FilteredRelation and select related functions.
📂 Report JSON File: 3292573
@hackeronereports
🎯 New Report #2886723: GraphQL Introspection Enabled on Shopify API Endpoint (Intended Behavior)
🔺Severity: None
👽 Reporter: ahmednasr1
⭐️ Reputation: 94
🛠 State: informative
💼 Team: Shopify
💵 Bounty: null
🕐 Submitted: 2024-12-07
⏰ Disclosed: 2025-09-17 14:59:23
📝 Summary: null
📂 Report JSON File: 2886723
@hackeronereports
🔺Severity: None
👽 Reporter: ahmednasr1
⭐️ Reputation: 94
🛠 State: informative
💼 Team: Shopify
💵 Bounty: null
🕐 Submitted: 2024-12-07
⏰ Disclosed: 2025-09-17 14:59:23
📝 Summary: null
📂 Report JSON File: 2886723
@hackeronereports
🎯 New Report #1737358: URL Scheme Validation Bypass in Shopify Mobile App Allows Javascript Execution
🔺Severity: Low
👽 Reporter: fr4via
⭐️ Reputation: 10817
🛠 State: resolved
💼 Team: Shopify
💵 Bounty: null
🕐 Submitted: 2022-10-17
⏰ Disclosed: 2025-09-17 15:23:43
📝 Summary: A vulnerability in the Shopify mobile application allowed bypassing URL scheme validation in the NavigationActivity component. Attackers could craft malicious URLs using
📂 Report JSON File: 1737358
@hackeronereports
🔺Severity: Low
👽 Reporter: fr4via
⭐️ Reputation: 10817
🛠 State: resolved
💼 Team: Shopify
💵 Bounty: null
🕐 Submitted: 2022-10-17
⏰ Disclosed: 2025-09-17 15:23:43
📝 Summary: A vulnerability in the Shopify mobile application allowed bypassing URL scheme validation in the NavigationActivity component. Attackers could craft malicious URLs using
data: or javascript: schemes to execute JavaScript code within the app's webview context.📂 Report JSON File: 1737358
@hackeronereports
🎯 New Report #3228011: Critical Information Disclosure via /talos/api/v1/files/upload
🔺Severity: Critical
👽 Reporter: sameer ali
⭐️ Reputation: 417
🛠 State: resolved
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2025-06-27
⏰ Disclosed: 2025-09-17 19:09:12
📝 Summary: A vulnerability was discovered in the file upload functionality, where uploaded files were first stored on the server before being sent to S3. Due to a configuration flaw, memory chunks from the server were included in some uploaded files. This issue was classified as critical and was addressed as a priority.
📂 Report JSON File: 3228011
@hackeronereports
🔺Severity: Critical
👽 Reporter: sameer ali
⭐️ Reputation: 417
🛠 State: resolved
💼 Team: Bykea
💵 Bounty: null
🕐 Submitted: 2025-06-27
⏰ Disclosed: 2025-09-17 19:09:12
📝 Summary: A vulnerability was discovered in the file upload functionality, where uploaded files were first stored on the server before being sent to S3. Due to a configuration flaw, memory chunks from the server were included in some uploaded files. This issue was classified as critical and was addressed as a priority.
📂 Report JSON File: 3228011
@hackeronereports
🎯 New Report #3341476: int overflow in krb5 read data() leads to (possible) massive `recv()` write
🔺Severity: Low
👽 Reporter: smiliesandco
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-09-16
⏰ Disclosed: 2025-09-18 09:33:13
📝 Summary: null
📂 Report JSON File: 3341476
@hackeronereports
🔺Severity: Low
👽 Reporter: smiliesandco
⭐️ Reputation: 100
🛠 State: informative
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-09-16
⏰ Disclosed: 2025-09-18 09:33:13
📝 Summary: null
📂 Report JSON File: 3341476
@hackeronereports
🎯 New Report #1597271: Stored XSS in Email Notifcation
🔺Severity: Medium
👽 Reporter: khaledx
⭐️ Reputation: 1558
🛠 State: resolved
💼 Team: Insightly
💵 Bounty: null
🕐 Submitted: 2022-06-10
⏰ Disclosed: 2025-09-19 06:37:55
📝 Summary: A stored XSS vulnerability was discovered in the email notification feature of the crm.na1.insightly.com platform. The vulnerability allowed an attacker to inject malicious code into the email subject, which was then executed when users viewed the notification. The vulnerability was caused by insufficient input sanitization.
📂 Report JSON File: 1597271
@hackeronereports
🔺Severity: Medium
👽 Reporter: khaledx
⭐️ Reputation: 1558
🛠 State: resolved
💼 Team: Insightly
💵 Bounty: null
🕐 Submitted: 2022-06-10
⏰ Disclosed: 2025-09-19 06:37:55
📝 Summary: A stored XSS vulnerability was discovered in the email notification feature of the crm.na1.insightly.com platform. The vulnerability allowed an attacker to inject malicious code into the email subject, which was then executed when users viewed the notification. The vulnerability was caused by insufficient input sanitization.
📂 Report JSON File: 1597271
@hackeronereports
🎯 New Report #1668489: CSRF vulnerability allows disabling Gmail contacts link for user referrals
🔺Severity: Medium
👽 Reporter: khaledx
⭐️ Reputation: 1558
🛠 State: resolved
💼 Team: Insightly
💵 Bounty: null
🕐 Submitted: 2022-08-13
⏰ Disclosed: 2025-09-19 06:36:34
📝 Summary: The CSRF vulnerability allowed users to disable Gmail contacts link for user referrals. The vulnerable endpoint did not sufficiently verify that the requests were intentionally performed by the user, allowing an attacker to generate a PoC that could be used to disable the victim's linked account.
📂 Report JSON File: 1668489
@hackeronereports
🔺Severity: Medium
👽 Reporter: khaledx
⭐️ Reputation: 1558
🛠 State: resolved
💼 Team: Insightly
💵 Bounty: null
🕐 Submitted: 2022-08-13
⏰ Disclosed: 2025-09-19 06:36:34
📝 Summary: The CSRF vulnerability allowed users to disable Gmail contacts link for user referrals. The vulnerable endpoint did not sufficiently verify that the requests were intentionally performed by the user, allowing an attacker to generate a PoC that could be used to disable the victim's linked account.
📂 Report JSON File: 1668489
@hackeronereports
🎯 New Report #1387366: elections.k8s.io uses weak session secret key, may place elections at risk
🔺Severity: High
👽 Reporter: ian
⭐️ Reputation: 6661
🛠 State: resolved
💼 Team: Kubernetes
💵 Bounty: 250
🕐 Submitted: 2021-11-01
⏰ Disclosed: 2025-09-19 20:54:04
📝 Summary: The elections.k8s.io application used a weak Flask SECRET KEY, the string "N/A", to sign authentication cookies. This allowed the complete compromise of the application, as the session could be manipulated.
📂 Report JSON File: 1387366
@hackeronereports
🔺Severity: High
👽 Reporter: ian
⭐️ Reputation: 6661
🛠 State: resolved
💼 Team: Kubernetes
💵 Bounty: 250
🕐 Submitted: 2021-11-01
⏰ Disclosed: 2025-09-19 20:54:04
📝 Summary: The elections.k8s.io application used a weak Flask SECRET KEY, the string "N/A", to sign authentication cookies. This allowed the complete compromise of the application, as the session could be manipulated.
📂 Report JSON File: 1387366
@hackeronereports
🎯 New Report #1392262: Stored XSS via LINK Name.
🔺Severity: High
👽 Reporter: xploiterr
⭐️ Reputation: 34724
🛠 State: resolved
💼 Team: Insightly
💵 Bounty: null
🕐 Submitted: 2021-11-05
⏰ Disclosed: 2025-09-23 12:17:34
📝 Summary: The LINK NAME was not properly escaped at the Templates page, leading to Stored XSS. The name was reflected in the <script> tag, and due to lack of sanitization, the user could break out of the tag and execute the XSS.
📂 Report JSON File: 1392262
@hackeronereports
🔺Severity: High
👽 Reporter: xploiterr
⭐️ Reputation: 34724
🛠 State: resolved
💼 Team: Insightly
💵 Bounty: null
🕐 Submitted: 2021-11-05
⏰ Disclosed: 2025-09-23 12:17:34
📝 Summary: The LINK NAME was not properly escaped at the Templates page, leading to Stored XSS. The name was reflected in the <script> tag, and due to lack of sanitization, the user could break out of the tag and execute the XSS.
📂 Report JSON File: 1392262
@hackeronereports
🎯 New Report #3124517: Arbitrary Read of Another Users private repository without Authorization
🔺Severity: High
👽 Reporter: furbreeze
⭐️ Reputation: 164
🛠 State: resolved
💼 Team: GitHub
💵 Bounty: 10000
🕐 Submitted: 2025-05-03
⏰ Disclosed: 2025-09-23 22:18:14
📝 Summary: An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to any repository to retrieve limited code content from another repository by creating a diff between the repositories. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.18, and was fixed in versions 3.14.17, 3.15.12, 3.16.8 and 3.17.5.
📂 Report JSON File: 3124517
@hackeronereports
🔺Severity: High
👽 Reporter: furbreeze
⭐️ Reputation: 164
🛠 State: resolved
💼 Team: GitHub
💵 Bounty: 10000
🕐 Submitted: 2025-05-03
⏰ Disclosed: 2025-09-23 22:18:14
📝 Summary: An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to any repository to retrieve limited code content from another repository by creating a diff between the repositories. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.18, and was fixed in versions 3.14.17, 3.15.12, 3.16.8 and 3.17.5.
📂 Report JSON File: 3124517
@hackeronereports
🎯 New Report #2919216: XSS1
🔺Severity: None
👽 Reporter: admin097
⭐️ Reputation: 525
🛠 State: resolved
💼 Team: Informatica
💵 Bounty: null
🕐 Submitted: 2025-01-01
⏰ Disclosed: 2025-09-24 16:49:59
📝 Summary: The XSS vulnerability was discovered in the search functionality of the Informatica website. The vulnerability allowed an attacker to inject arbitrary JavaScript code into the search results, which could be executed by the user's browser.
📂 Report JSON File: 2919216
@hackeronereports
🔺Severity: None
👽 Reporter: admin097
⭐️ Reputation: 525
🛠 State: resolved
💼 Team: Informatica
💵 Bounty: null
🕐 Submitted: 2025-01-01
⏰ Disclosed: 2025-09-24 16:49:59
📝 Summary: The XSS vulnerability was discovered in the search functionality of the Informatica website. The vulnerability allowed an attacker to inject arbitrary JavaScript code into the search results, which could be executed by the user's browser.
📂 Report JSON File: 2919216
@hackeronereports
🎯 New Report #2311179: Information Exposure Through Directory Listing
🔺Severity: Medium
👽 Reporter: farhad0x1
⭐️ Reputation: 133
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2024-01-10
⏰ Disclosed: 2025-09-29 15:53:50
📝 Summary: The web server was configured to display a list of files contained in the directory. This is not recommended as the directory may have contained files that were not normally exposed through links on the website.
📂 Report JSON File: 2311179
@hackeronereports
🔺Severity: Medium
👽 Reporter: farhad0x1
⭐️ Reputation: 133
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2024-01-10
⏰ Disclosed: 2025-09-29 15:53:50
📝 Summary: The web server was configured to display a list of files contained in the directory. This is not recommended as the directory may have contained files that were not normally exposed through links on the website.
📂 Report JSON File: 2311179
@hackeronereports
🎯 New Report #2305880: Email not verified when changing afterwards on apps.nextcloud.com
🔺Severity: Low
👽 Reporter: farhad0x1
⭐️ Reputation: 133
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2024-01-06
⏰ Disclosed: 2025-09-29 15:50:37
📝 Summary: The email verification bypass vulnerability was discovered in the web application apps.nextcloud.com. The vulnerability allowed attackers to create accounts with any email address without verification, effectively taking over victim accounts.
📂 Report JSON File: 2305880
@hackeronereports
🔺Severity: Low
👽 Reporter: farhad0x1
⭐️ Reputation: 133
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2024-01-06
⏰ Disclosed: 2025-09-29 15:50:37
📝 Summary: The email verification bypass vulnerability was discovered in the web application apps.nextcloud.com. The vulnerability allowed attackers to create accounts with any email address without verification, effectively taking over victim accounts.
📂 Report JSON File: 2305880
@hackeronereports
🎯 New Report #2778441: Exposing debug.log file leads to server full path disclosure
🔺Severity: Medium
👽 Reporter: farhad0x1
⭐️ Reputation: 133
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2024-10-12
⏰ Disclosed: 2025-09-29 15:50:22
📝 Summary: The debug.log file on the nextcloud.com website was publicly accessible and contained sensitive information, including the server's full directory path. This type of information disclosure could have assisted attackers in understanding the internal structure of the server.
📂 Report JSON File: 2778441
@hackeronereports
🔺Severity: Medium
👽 Reporter: farhad0x1
⭐️ Reputation: 133
🛠 State: resolved
💼 Team: Nextcloud
💵 Bounty: null
🕐 Submitted: 2024-10-12
⏰ Disclosed: 2025-09-29 15:50:22
📝 Summary: The debug.log file on the nextcloud.com website was publicly accessible and contained sensitive information, including the server's full directory path. This type of information disclosure could have assisted attackers in understanding the internal structure of the server.
📂 Report JSON File: 2778441
@hackeronereports
🎯 New Report #3211031: `use-mcp`'s oauth2 process uses a window.open call with untrusted mcp server provided data allowing for code execution under the page using it
🔺Severity: Medium
👽 Reporter: null smashmaster0045
⭐️ Reputation: 225
🛠 State: resolved
💼 Team: Cloudflare Public Bug Bounty
💵 Bounty: 550
🕐 Submitted: 2025-06-19
⏰ Disclosed: 2025-09-30 08:15:45
📝 Summary: The
📂 Report JSON File: 3211031
@hackeronereports
🔺Severity: Medium
👽 Reporter: null smashmaster0045
⭐️ Reputation: 225
🛠 State: resolved
💼 Team: Cloudflare Public Bug Bounty
💵 Bounty: 550
🕐 Submitted: 2025-06-19
⏰ Disclosed: 2025-09-30 08:15:45
📝 Summary: The
authorizeEndpoint parameter from use-mcp version was susceptible to XSS. Sanitization of that parameter was added in version 0.0.10 of use-mcp. A skilled attacker was able to turn this XSS into code execution on the client.📂 Report JSON File: 3211031
@hackeronereports