Latest updates about disclosure bug bounty reports: tech details, impacts, bounties📣Rate👇https://cutt.ly/bugpoint_rateFeedback👇https://cutt.ly/bugpoint_feedback#️⃣bug bounty disclosed reports#️⃣bug bounty write-ups#️⃣bug bounty teleg
This channel is part of the discussion
bugpoint appears in 11 event pages on TGScopePre-authentication Stored XSS in Essity Customer-Service Pipeline via ContactApi (reCAPTCHA bypass + no rate limit) 🔹 Severity: Critical 🔹 Weakness: Cross-site Scripting (XSS) - Stored 🔹 Reported To: Essity 🔹 Reported By: matty69v 🔹 State: 🟢 Resolved 🔹 Disclosed: August…
HTTP Request Smuggling via Silent Header Truncation in Node.js HTTP Parser 🔹 Severity: Low 🔹 Weakness: HTTP Request Smuggling 🔹 Reported To: Node.js 🔹 Reported By: yushengchen 🔹 State: 🟢 Resolved 🔹 Disclosed: August 28, 2026, 2:16pm (UTC) 🐞 Source: HackerOne A flaw in…
Author → stored XSS in wp-admin: unescaped sub-size filename from attachment metadata breaks out of the `src` attribute in `get_media_item()` 🔹 Severity: Critical 🔹 Weakness: Cross-site Scripting (XSS) - Stored 🔹 Reported To: WordPress 🔹 Reported By: jakubk 🔹 State: 🟢…
Unauthorized vertical privilege escalation vulnerability found on ibm.com endpoint 🔹 Severity: No Rating 🔹 Weakness: Improper Access Control - Generic 🔹 Reported To: IBM 🔹 Reported By: inventor0x01 🔹 State: 🟢 Resolved 🔹 Disclosed: August 28, 2026, 6:20pm (UTC) 🐞 Source:…
Unauthenticated Disclosure of Unpublished / Embargoed 🔹 Severity: Informational 🔹 Reported To: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program 🔹 Reported By: 0xPewPew 🔹 State: 🟢 Resolved 🔹 Disclosed: August 27, 2026 🐞 Source:…
Author → stored XSS in wp-admin: unescaped sub-size filename from attachment metadata breaks out of the `src` attribute in `get_media_item()` 🔹 Severity: Critical 🔹 Weakness: Cross-site Scripting (XSS) - Stored 🔹 Reported To: WordPress 🔹 Reported By: jakubk 🔹 State: 🟢…