Loading HuntDB...

Automattic - HackerOne Reports

View on HackerOne
131
Total Reports
9
Critical
28
High
53
Medium
22
Low
Weakness: Information Disclosure
Weakness: Cross-site Scripting (XSS) - Generic

Follow Button XSS

Reported by: bobrov | Disclosed:
Weakness: Cross-site Scripting (XSS) - Generic
Weakness: Cross-Site Request Forgery (CSRF)
Weakness: Violation of Secure Design Principles
Weakness: Insecure Direct Object Reference (IDOR)
Weakness: Cross-Site Request Forgery (CSRF)
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: Path Traversal
Weakness: Business Logic Errors
Weakness: Cross-site Scripting (XSS) - Reflected
Weakness: Insecure Direct Object Reference (IDOR)
Weakness: Cross-site Scripting (XSS) - Stored
High
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: UI Redressing (Clickjacking)
Previous Page 3 of 7 Next