Loading HuntDB...

WordPress - HackerOne Reports

View on HackerOne
82
Total Reports
4
Critical
18
High
31
Medium
19
Low
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: Cross-site Scripting (XSS) - Generic
Weakness: UI Redressing (Clickjacking)
Weakness: Improper Access Control - Generic
Weakness: Cross-Site Request Forgery (CSRF)

CSRF on comment post

Reported by: lamscun | Disclosed:
Medium
Weakness: Cross-Site Request Forgery (CSRF)
Weakness: Cross-site Scripting (XSS) - Reflected
Weakness: Cross-Site Request Forgery (CSRF)
Weakness: Cross-site Scripting (XSS) - Generic
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: Information Disclosure
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: Cross-site Scripting (XSS) - Reflected

wp-embed XSS on Safari

Reported by: zoczus | Disclosed:
Medium
Weakness: Cross-site Scripting (XSS) - DOM

xss - reflected

Reported by: arunthelegion | Disclosed:
Low
Weakness: Cross-site Scripting (XSS) - Reflected

Authenticated XXE

Reported by: sonarsource | Disclosed:
Medium
Weakness: XML External Entities (XXE)
Previous Page 2 of 5 Next