-

Breaking Vercel’s Clone URL with a Simple XSS Exploit
During my exploration of Vercel’s platform, I discovered a reflected XSS vulnerability in the “clone project” functionality. This…
-

Bypassing Razer’s WAF for XSS
While testing Razer’s web application, I identified an XSS vulnerability in their /ajax endpoint. The issue arises due…
-

Finding WordPress Vulnerabilities on CarGurus with WPScan
While exploring CarGurus’ bug bounty program, I discovered a reflected XSS vulnerability on their subdomain dealercentre.cargurus.co.uk. This writeup…
-

N45HTCTF2023
N45HTCTF2023 | “Cyber Security and Indonesian History” N45HT held a CTF (Capture the Flag) event to celebrate independence…
-

Stored XSS on Chess24.com
I recently registered on Chess24.com and, after playing a few games, decided to conduct a quick security analysis…
-

XSS: Bypass CloudFront WAF
In this article, we will share how we successfully bypassed the CloudFront WAF (Web Application Firewall) to exploit…
-

Exploiting HTTPStatus.io: An XSS via Protocol Handling
httpstatus.io is a tool that allows you to check HTTP status codes, headers, and redirects. For example, when…
-

Stored XSS on LaporBug.id: Injecting Payloads through Profile Images
LaporBug.id is a Bug Bounty Platform based in Indonesia. If you want to know more about LaporBug.id, visit…
Recent Posts
- We’re Hiring: Python Cybersecurity ExpertN45HT is currently looking for a talented and experienced Python… Read more: We’re Hiring: Python Cybersecurity Expert
- XSSR Pro is Now Available for FreeWe’re excited to announce that XSSR Pro is now available… Read more: XSSR Pro is Now Available for Free
- Drupal CVE-2026-9082 CheckerWe recently created a small Python tool to detect CVE-2026-9082,… Read more: Drupal CVE-2026-9082 Checker
- We’re Hiring: Node.js Cybersecurity ExpertHiring Status: Closed Applications for this position are no longer… Read more: We’re Hiring: Node.js Cybersecurity Expert
- Exposed Production Database Found on Sitemile.comWhile browsing for WordPress themes, I came across sitemile.com. After… Read more: Exposed Production Database Found on Sitemile.com
Social Media
Advertisement
Tags
API Bug Bounty Capture The Flag Command Injection Cross-site Scripting CTF CVE-2026-9082 Drupal ExifTool HTML Information Disclosure JavaScript Markdown Open Redirection PHP SQL Injection VDP WAF Web Application Firewall XSS XSSR XSSRush




