Top reports from HackerOne program at HackerOne:
- Account takeover via leaked session cookie to HackerOne - 1360 upvotes, $20000
- Confidential data of users and limited metadata of programs and reports accessible via GraphQL to HackerOne - 922 upvotes, $20000
- WannaCrypt “Killswitch” to HackerOne - 780 upvotes, $10000
- Email address of any user can be queried on Report Invitation GraphQL type when username is known to HackerOne - 602 upvotes, $8500
- Customer private program can disclose email any users through invited via username to HackerOne - 480 upvotes, $7500
- profile-picture name parameter with large value lead to DoS for other users and programs on the platform to HackerOne - 442 upvotes, $2500
- How the Bug stole hacking to HackerOne - 428 upvotes, $0
- Partial disclosure of report activity through new "Export as .zip" feature to HackerOne - 327 upvotes, $10000
- Reflected XSS on www.hackerone.com and resources.hackerone.com to HackerOne - 287 upvotes, $500
- Team member with Program permission only can escalate to Admin permission to HackerOne - 252 upvotes, $2500
- Information Disclosure in /skills call to HackerOne - 249 upvotes, $10000
- Internal attachments can be exported via "Export as .zip" feature to HackerOne - 245 upvotes, $12500
- Cross-site Scripting (XSS) on HackerOne careers page to HackerOne - 218 upvotes, $500
- Denial of service via cache poisoning to HackerOne - 215 upvotes, $2500
- Manipulate hacker profile and private program hacktivity to expose your name as researchers who is actively submitting reports with resolve status to HackerOne - 200 upvotes, $500
- Race condition in performing retest allows duplicated payments to HackerOne - 190 upvotes, $2100
- DOM Based XSS in www.hackerone.com via PostMessage to HackerOne - 184 upvotes, $500
- Markdown parsing issue enables insertion of malicious tags and event handlers to HackerOne - 173 upvotes, $5000
- Hacker can bypass 2FA requirement and reporter blacklist through embedded submission form to HackerOne - 171 upvotes, $10000
- Disclosure of
payment_transactions
for programs via GraphQL query to HackerOne - 165 upvotes, $2500 - 404-response contains debug-information with all headers to HackerOne - 155 upvotes, $500
- Total Paid Bounty Paid can be disclose to HackerOne - 154 upvotes, $500
- Web Authentication Endpoint Credentials Brute-Force Vulnerability to HackerOne - 147 upvotes, $1500
- Unreleased CTF Levels are Revealed on /group/user/ID1?user=USERID endpoint to HackerOne - 146 upvotes, $500
- IE only: stored Cross-Site Scripting (XSS) vulnerability through Program Asset identifier to HackerOne - 145 upvotes, $2500
- Hacker.One Subdomain Takeover to HackerOne - 145 upvotes, $1000
- Discrepancy in hacker profile report count may reveal existence of a private program by publishing a report to HackerOne - 140 upvotes, $3000
- SQL injection in GraphQL endpoint through embedded_submission_form_uuid parameter to HackerOne - 138 upvotes, $0
- Banned researcher gets email updates on a private program. to HackerOne - 135 upvotes, $500
- Unauthorized user can obtain
report_sources
attribute through Team GraphQL object to HackerOne - 132 upvotes, $2500 - Stealing contact form data on www.hackerone.com using Marketo Forms XSS with postMessage frame-jumping and jQuery-JSONP to HackerOne - 131 upvotes, $1500
- Client-Side Race Condition using Marketo, allows sending user to data-protocol in Safari when form without onSuccess is submitted on www.hackerone.com to HackerOne - 130 upvotes, $1250
- Disclose any user's private email through API to HackerOne - 127 upvotes, $2000
- Private program disclosure via
vpn_suspended
GraphQL query to HackerOne - 125 upvotes, $2500 - h1-202 leaderboard photo discloses local wifi password to HackerOne - 125 upvotes, $500
- Subdomain takeover at info.hacker.one to HackerOne - 124 upvotes, $1000
- Content spoofing and potential Cross-Site Scripting vulnerability on www.hackerone.com to HackerOne - 122 upvotes, $5000
- Searching from Hacktivity returns hits for words in limited disclosure reports that are not visible to HackerOne - 122 upvotes, $2500
- Blind SSRF on errors.hackerone.net due to Sentry misconfiguration to HackerOne - 121 upvotes, $3500
- Unauthorized access to metadata of undisclosed reports that were retested to HackerOne - 116 upvotes, $2500
- Race Condition leads to undeletable group member to HackerOne - 110 upvotes, $500
- Emails of invited collaborators are disclosed in full in payload for report participants to HackerOne - 107 upvotes, $1500
- Account recovery text message is sending a wrong domain to users. to HackerOne - 106 upvotes, $500
- @wearehackerone.com is vulnerable to namespace attacks due to hackerone.com not being RFC2142 compliant. to HackerOne - 99 upvotes, $0
- Race Conditions in Popular reports feature. to HackerOne - 96 upvotes, $500
- [Bypass #645264] Report title disclosure despite the program settings for email notification is set to "No Content" to HackerOne - 96 upvotes, $500
- DOM Based XSS in www.hackerone.com via PostMessage (bypass of #398054) to HackerOne - 94 upvotes, $565
- ActiveStorage throws exception when using whitespace as filename, may lead to denial of service of multiple pages to HackerOne - 93 upvotes, $2500
- Subdomain takeover of resources.hackerone.com to HackerOne - 91 upvotes, $500
- Attacker with an Old account might still be able to DoS ctf.hacker101.com by sending a Crafted request to HackerOne - 91 upvotes, $500
- A user can bypass approval step in Hacker Publishing feature, allowing them to publish reports immediately to HackerOne - 88 upvotes, $2500
- Harvesting all private invites using leave program fast-tracked invitation and security@ email forwarding feature to HackerOne - 86 upvotes, $2500
- Team object in GraphQL disclosed total number of whitelisted hackers to HackerOne - 82 upvotes, $2500
- Reading redacted data via hackbot's answers to HackerOne - 82 upvotes, $1500
- Unauthenticated user can upload an attachment to the last updated report draft to HackerOne - 79 upvotes, $0
- Password not checked when disabling 2FA on HackerOne to HackerOne - 78 upvotes, $500
- Improper UUID validation results in bypass of #419896 to HackerOne - 76 upvotes, $7500
- Subdomain takeover #2 at info.hacker.one to HackerOne - 75 upvotes, $1000
- "Bounties paid in the last 90 days" discloses the undisclosed bounty amount in program statistics to HackerOne - 74 upvotes, $500
- latest_activity_id and latest_activity_at may disclose information about internal activities to unauthorized users to HackerOne - 73 upvotes, $1000
- Private information exposed through GraphQL filters to HackerOne - 72 upvotes, $0
- A HackerOne employee's GitHub personal access token exposed in Travis CI build logs to HackerOne - 69 upvotes, $2000
- Team object in GraphQL discloses team group names and permissions to HackerOne - 68 upvotes, $2500
- The request tells the number of private programs, the new system of authorization /invite/token to HackerOne - 68 upvotes, $2000
- Reporter, external users, collaborators can mark sent swag awarded to reporter as unsent to HackerOne - 67 upvotes, $0
- Homograph fix Bypass to HackerOne - 66 upvotes, $750
- Inline banner on Report page discloses whether organization runs a private program to HackerOne - 66 upvotes, $500
- Deprecated Hacker101 coursework repository mentions Heroku App that is susceptible to takeover to HackerOne - 66 upvotes, $500
- Team object in GraphQL disclosed of private programs via the industry to HackerOne - 66 upvotes, $500
- Race Condition in Flag Submission to HackerOne - 65 upvotes, $500
- Potential stored Cross-Site Scripting vulnerability in Support Backend to HackerOne - 65 upvotes, $0
- Validation message in Bounty award endpoint can be used to determine program balances to HackerOne - 64 upvotes, $1500
- Query parameter reordering causes redirect page to render unsafe URL to HackerOne - 61 upvotes, $1500
- HTTP Parameter Pollution using semicolons in iframe element at hackerone.com/careers allows loading external Greenhouse forms to HackerOne - 61 upvotes, $500
- Program metrics disclosed response_efficiency_percentage via /program_name json response despite the team decided not to show on their profile to HackerOne - 59 upvotes, $2500
- An invite-only's program submission state is accessible to users no longer part of the program to HackerOne - 59 upvotes, $500
- Disclosure of Email title report in quick award paypout email (no content mode) to HackerOne - 58 upvotes, $500
- Report Private Links Leaks to Google Analytics via Query String Param to HackerOne - 58 upvotes, $0
- Team object exposes amount of participants in a private program to non-invited users to HackerOne - 57 upvotes, $5000
- Race condition leads to duplicate payouts to HackerOne - 57 upvotes, $750
- TeamProfile exposes partially sensitive information through GraphQL to HackerOne - 57 upvotes, $500
- Subdomain takeover #3 at info.hacker.one to HackerOne - 56 upvotes, $1000
- Invalid Host detection at https://hackerone.com/redirect to HackerOne - 56 upvotes, $500
- Any user with access to program can resume and suspend HackerOne Gateway to HackerOne - 56 upvotes, $0
- Unauthenticated users can obtain information about Checklist objects with unclaimed ChecklistCheck objects to HackerOne - 56 upvotes, $0
- Private program policy page still accessible after user left the program to HackerOne - 52 upvotes, $2500
- Extra program metrics disclosed via /PROGRAM_NAME json response to HackerOne - 51 upvotes, $500
- IDOR in Report CSV export discloses the IDs of Custom Field Attributes of Programs to HackerOne - 51 upvotes, $0
- Websites opened from reports can change url of report page to HackerOne - 50 upvotes, $500
- Open Redirection in index.php page to HackerOne - 50 upvotes, $250
- Bypass rate limiting on /users/password (possibly site-wide rate limit bypass?) to HackerOne - 49 upvotes, $500
- Subdomain takeover #4 at info.hacker.one to HackerOne - 49 upvotes, $500
- Email Forwarding invitations for Drafts are not marked as accepted, allowing multiple users to join a program after disabling Email Forwarding to HackerOne - 49 upvotes, $500
- Total bounties paid amount is disclosed because of redesign of the Program Profiles to HackerOne - 47 upvotes, $500
- View HackerOne challenge scope before challenge begins to HackerOne - 46 upvotes, $500
- IDOR on HackerOne Feedback Review to HackerOne - 46 upvotes, $0
- Hogging up all the resources on hackerone.com to HackerOne - 44 upvotes, $500
- Embedded submission form UUIDs can be enumerated through GraphQL node interface, exposing sensitive program details to HackerOne - 44 upvotes, $0
- Custom Field Attributes may be created and updated for customers with Custom Field Trial enabled to HackerOne - 44 upvotes, $0
- Content Security Policy not applied to error pages at multiple HackerOne endpoints to HackerOne - 43 upvotes, $500
- Adding or removing a new non-preferred payout method does not trigger an e-mail or account notification to HackerOne - 42 upvotes, $500
- Domain spoofing in redirect page using RTLO to HackerOne - 42 upvotes, $500
- HackerOne support disclosing report state without checking user identity to HackerOne - 42 upvotes, $500
- Disclosing a private program in an external link if program is paused to HackerOne - 42 upvotes, $500
- Disclosure of the name of a program that has a private part with an external link to HackerOne - 42 upvotes, $500
- API Last Request Date/Time Not Updating to HackerOne - 42 upvotes, $0
- Response program can display "eligible for bounty" in scope area in program policy to HackerOne - 41 upvotes, $500
- Repeated mediation requests and multiple emails possible on a report. to HackerOne - 41 upvotes, $500
- Race condition in claiming program credentials to HackerOne - 41 upvotes, $500
- IE 11 Self-XSS on Jira Integration Preview Base Link to HackerOne - 40 upvotes, $750
- Google Analytics could be used as CSP bypass for data exfiltration on hackerone.com to HackerOne - 40 upvotes, $500
- ImageMagick GIF coder vulnerability leading to memory disclosure to HackerOne - 40 upvotes, $500
- User with privilege to maintain External Programs can update certain churned HackerOne programs to HackerOne - 40 upvotes, $500
- Proper verification is not done before sending invitations to researchers for certain private programs with rules e.g. "Participants must be US-based" to HackerOne - 39 upvotes, $2500
- Disclosure of Program email Title Report when being removed as contributor. Bypass for Report #645264 to HackerOne - 39 upvotes, $500
- (HackerOne SSO-SAML) Login CSRF, Open Redirect, and Self-XSS Possible Exploitation to HackerOne - 39 upvotes, $0
- Open redirect vulnerability in index.php to HackerOne - 38 upvotes, $0
- GraphQL node interface for ActiveResource models lacks encoding for resource identifier, enabling parameter injection in Payments backend to HackerOne - 38 upvotes, $0
- Hacktivity of a private program visible to banned user if he gets invited to a program by hackbot to HackerOne - 37 upvotes, $500
- Disclosure of top 10 vulnerability types for programs that haven't enabled the Insights feature to HackerOne - 37 upvotes, $500
- Path traversal leading to limited CSRF on GET requests on two endpoints to HackerOne - 37 upvotes, $500
- Common response suggestion is sent to Google Analytics when user accepts duplicate comment Genius suggestion to HackerOne - 36 upvotes, $500
- Revoking user session in https://hackerone.com/settings/sessions does not revoke the GraphQL query session to HackerOne - 36 upvotes, $500
- Private program email forwarding response invitation not expire after first use. to HackerOne - 36 upvotes, $0
- Team object in GraphQL that have a published external program may expose existence of a private program to HackerOne - 36 upvotes, $0
- Report invitation links not restricted to any existing user to HackerOne - 34 upvotes, $500
- Updating payout preference to CurrencyCloud doesn't notify user via email to HackerOne - 34 upvotes, $500
- HackerOne Integrations Design Issue to HackerOne - 34 upvotes, $500
- Invitation token leaks to https://bat.bing.com to HackerOne - 33 upvotes, $500
- HackerOne customer submitted sensitive link to VirusTotal, exposing confidential information to HackerOne - 33 upvotes, $350
- HackerOne reports escalation to JIRA is CSRF vulnerable to HackerOne - 32 upvotes, $500
- Accidental Access to Programs Information via SAML Login to HackerOne - 32 upvotes, $0
- Open Redirection in [https://www.hackerone.com/index.php] to HackerOne - 32 upvotes, $0
- Changing Victim's JIRA Integration Settings Through Multiple Bugs to HackerOne - 31 upvotes, $1000
- View Any Program's Team Members through GET https://hackerone.com/invitations/ to HackerOne - 31 upvotes, $1000
- Information leakage of private program to HackerOne - 31 upvotes, $500
- User login page doesn't implement any form of rate limiting to HackerOne - 31 upvotes, $500
- Parameter pollution in social sharing buttons to HackerOne - 30 upvotes, $500
- CSRF at [Apply to this program] that lead to submit your request automatic with out any validations to HackerOne - 30 upvotes, $500
- Internal usage of AdBlockPlus may expose PoC URLs to unknown third-parties to HackerOne - 30 upvotes, $0
- Information leakage via CSV when content is valid JavaScript to HackerOne - 29 upvotes, $750
- Pixel flood attack to HackerOne - 29 upvotes, $500
- Non-secure requests are not automatically upgraded to HTTPS to HackerOne - 29 upvotes, $500
- Program Email Nofication settings ignored when being added as an external contributor to HackerOne - 29 upvotes, $500
- Attacker can claim credentials for private program that has a published external program to HackerOne - 29 upvotes, $0
- Timing attack towards endpoints on the web without CSRF to HackerOne - 29 upvotes, $0
- A small set of users were assigned someone else's payout preference to HackerOne - 29 upvotes, $0
- AWS S3 bucket writeable for authenticated aws users to HackerOne - 28 upvotes, $2500
- Invitation tokens leak to Google Analytics to HackerOne - 28 upvotes, $0
- HackerOne Pentesters can access any structured scope object through GraphQL node interface to HackerOne - 28 upvotes, $0
- Program profile metrics endpoint contains mean time to triage, even when turned off to HackerOne - 27 upvotes, $500
- Disclosure of h1 challenges name through the calendar to HackerOne - 27 upvotes, $500
- Blind SSRF in "Integrations" by abusing a bug in Ruby's native resolver. to HackerOne - 27 upvotes, $0
- RCE in profile picture upload to HackerOne - 26 upvotes, $2500
- Missing SPF for hackerone.com to HackerOne - 26 upvotes, $500
- Program profile_metrics.json contains time to triage for deptofdefense even it's turned off to HackerOne - 26 upvotes, $250
- Report redaction doesn't apply to report title update activities to HackerOne - 26 upvotes, $0
- Upload profile photo from URL to HackerOne - 25 upvotes, $500
- resolved bugs in a program are public despite the program settings to HackerOne - 25 upvotes, $500
- Submitting report through Embedded Submission form gives user indefinite access to a profile to HackerOne - 25 upvotes, $500
- Unicorn worker pool exhaustion by continuously updating payout preferences to HackerOne - 25 upvotes, $0
- Transitioning a Private Program to Public Does Not Clear Previously Private Updates to Hackers to HackerOne - 24 upvotes, $500
- Response program can create bounty table to HackerOne - 24 upvotes, $500
- Able To Check The Exact Bounty Balance of any Bug Bounty Program to HackerOne - 24 upvotes, $0
- People who interviewed for HackerOne security analyst position can be enumerated and their personal email address may be exposed to HackerOne - 23 upvotes, $500
- Can read features from any user to HackerOne - 23 upvotes, $250
- Ability to enumerate private programs using SAML to HackerOne - 23 upvotes, $0
- User object in GraphQL exposes number of trial reports for External Programs that also have a Private Program to HackerOne - 23 upvotes, $0
- IDOR in Bugs overview enables attacker to determine the date range a hackathon was active to HackerOne - 23 upvotes, $0
- Lack of input sanitization in Marketo form leads to execution of HTML in lead emails to HackerOne - 22 upvotes, $500
- A user can request a report to be retested even though the program has not been verified by HackerOne to HackerOne - 22 upvotes, $500
- Disabled account can still use GraphQL endpoint to HackerOne - 22 upvotes, $500
- program_analytics_benchmarks query shows information not visible in public to HackerOne - 21 upvotes, $500
- Hackerone Email Addresses Enumeration to HackerOne - 21 upvotes, $0
- Self DOM-Based XSS in www.hackerone.com to HackerOne - 21 upvotes, $0
- Read-only team members can read all properties of webhooks to HackerOne - 21 upvotes, $0
- A team member of the program with Report rights can ban the Admin to HackerOne - 21 upvotes, $0
- HackerOne is still prone to Internet Explorer UXSS to HackerOne - 20 upvotes, $0
- Information Disclosure when /invitations/<token>.json is not yet accepted to HackerOne - 20 upvotes, $0
- Know undisclosed Bounty Amount when Bounty Statistics are enabled. to HackerOne - 19 upvotes, $500
- Hacker can request mediation for published reports to HackerOne - 19 upvotes, $500
- Notifications sent due to "Transfer report" functionality may be sent to users who are no longer authorized to see the report to HackerOne - 19 upvotes, $500
- Email spoofing to HackerOne - 19 upvotes, $250
- CRLF injection in info.hacker.one to HackerOne - 19 upvotes, $0
- IDOR on Program Visibilty (Revealed / Concealed) against other team members to HackerOne - 19 upvotes, $0
- Homograph attack in escalate report to HackerOne - 18 upvotes, $500
- Switching the user to the attacker's account to HackerOne - 18 upvotes, $150
- Session not expired on logout to HackerOne - 18 upvotes, $100
- Insecure SHA1withRSA in b5s.hackerone-ext-content.com and a4l.hackerone-ext-content.com to HackerOne - 18 upvotes, $0
- Missing Certificate Authority Authorization rule to HackerOne - 18 upvotes, $0
- Additional bypass allows SSRF for internal netblocks to HackerOne - 18 upvotes, $0
- Previous attachments can be referenced when creating a new report to HackerOne - 17 upvotes, $500
- GIF flooding to HackerOne - 17 upvotes, $250
- DNS Cache Poisoning to HackerOne - 17 upvotes, $100
- Enumeration of users to HackerOne - 17 upvotes, $0
- Able to create basic user account via Google login on HackerOne Drupal CMS to HackerOne - 17 upvotes, $0
- Private partial disclosure of h1 infrastructure to HackerOne - 17 upvotes, $0
- report id is exposed for undisclosed reports in Hacktivity to HackerOne - 17 upvotes, $0
- Improper session management to HackerOne - 16 upvotes, $100
- Possible CSRF during joining report as participant to HackerOne - 16 upvotes, $0
- Example HackerOne security@ forward domain is not registered to HackerOne - 16 upvotes, $0
- www.hackerone.com website CSP "script-src" includes "unsafe-inline" to HackerOne - 16 upvotes, $0
- Exposing hackerone users personally identifiable information by abusing sandbox with swag reward enabled to HackerOne - 16 upvotes, $0
- Corrupted Authorization header can cause logs not to be ingested properly in ████████ to HackerOne - 16 upvotes, $0
- Lack of length validation on user address attribute to HackerOne - 16 upvotes, $0
- Homograph attack to HackerOne - 15 upvotes, $500
- Invalid Phabricator API token revealed through error message when escalating a report to HackerOne - 15 upvotes, $500
- Invited team member can disclosure slack channels to HackerOne - 15 upvotes, $500
- Ability to monitor reports' submission in real time to HackerOne - 15 upvotes, $0
- Limited Open redirection using SSO-SAML to HackerOne - 15 upvotes, $0
- Submitted reports state logs leakage to HackerOne - 15 upvotes, $0
- Know whether private program for company exist or not to HackerOne - 14 upvotes, $500
- HTML injection can lead to data theft to HackerOne - 14 upvotes, $500
- Old titles are not hidden in reports with limited disclosure to HackerOne - 14 upvotes, $500
- Real impersonation to HackerOne - 14 upvotes, $100
- Broken Authentication and session management OWASP A2 to HackerOne - 14 upvotes, $100
- Information disclosure (reset password token) and changing the user's password to HackerOne - 14 upvotes, $100
- Report title and issue information prepopulated to HackerOne - 14 upvotes, $0
- Users contents on AWS is cacheable to HackerOne - 14 upvotes, $0
- Session hijacking attack to HackerOne - 14 upvotes, $0
- Vulnerability with the way \ escaped characters in <http://danlec.com> style links are rendered to HackerOne - 13 upvotes, $5000
- Interstitial redirect bypass / open redirect in https://hackerone.com/zendesk_session to HackerOne - 13 upvotes, $500
- Able to remove the admin access of my program to HackerOne - 13 upvotes, $500
- Obtain the username & the uid of the one doing the S3 sync on Hackerone to HackerOne - 13 upvotes, $0
- Researcher gets email updates on a private program after he/she quits that program. to HackerOne - 13 upvotes, $0
- Rounding errors on rewarding a bounty leads to bypassing the 20% H1 commission fee to HackerOne - 13 upvotes, $0
- Improperly validated fields allows injection of arbitrary HTML via spoofed React objects to HackerOne - 12 upvotes, $5000
- HTTP header injection in info.hackerone.com allows setting cookies for hackerone.com to HackerOne - 12 upvotes, $1000
- Flawed account creation process allows registration of usernames corresponding to existing file names to HackerOne - 12 upvotes, $0
- Introspection query leaks sensitive graphql system information. to HackerOne - 12 upvotes, $0
- Lack of cross-origin request blocking allows leaking of sensitive information on several endpoints to HackerOne - 12 upvotes, $0
- GitHub users outside of HackerOne organization can create and update Wiki pages of certain public HackerOne repositories to HackerOne - 12 upvotes, $0
- Changes to data in a CVE request after draft via GraphQL query to HackerOne - 12 upvotes, $0
- Unintended HTML inclusion as a result of https://hackerone.com/reports/110578 to HackerOne - 11 upvotes, $500
- Requesting Mediation possible on reports that are too old for mediation to HackerOne - 11 upvotes, $500
- CSP not consistently applied to HackerOne - 11 upvotes, $250
- Verbose PHP error messages exposed on a blog article to HackerOne - 11 upvotes, $0
- CSRF login to HackerOne - 10 upvotes, $100
- javascript: and mailto: links are allowed in JIRA integration settings to HackerOne - 10 upvotes, $100
- Unauthorized Team members viewing to HackerOne - 10 upvotes, $0
- Possible CSRF during external programs to HackerOne - 10 upvotes, $0
- Missing rate limit on critical user actions e.g. reset password, change email, disable account. to HackerOne - 10 upvotes, $0
- Missing Certificate Authority Authorization rule to HackerOne - 10 upvotes, $0
- Moving a report to a different program doesn't reassign the Custom Field Values to HackerOne - 10 upvotes, $0
- Markdown parsing issue enables insertion of malicious tags and event handlers to HackerOne - 9 upvotes, $5000
- CSRF possible when SOP Bypass/UXSS is available to HackerOne - 9 upvotes, $2500
- PNG compression DoS to HackerOne - 9 upvotes, $500
- Logical issues with account settings to HackerOne - 9 upvotes, $150
- Privilege escalation..., or not?! to HackerOne - 9 upvotes, $0
- Manipulate report timeline activity by using null byte. to HackerOne - 9 upvotes, $0
- homograph attack. IDNs displayed in unicode in bug reports and on external link warning page to HackerOne - 8 upvotes, $500
- RTL override symbol not stripped from file names to HackerOne - 8 upvotes, $500
- Disclosure of external users invited to a specific report to HackerOne - 8 upvotes, $500
- Inadequate access controls in "Vote" functionality??? to HackerOne - 8 upvotes, $0
- Reward Money Leakage to HackerOne - 8 upvotes, $0
- Information disclosure via policy update notifications after removal from program to HackerOne - 8 upvotes, $0
- Search query text, including from potentially undisclosed reports, sent to Google Analytics on Inbox query page to HackerOne - 8 upvotes, $0
- GraphQL sessions aren't immediately invalidated when user password is changed to HackerOne - 8 upvotes, $0
- While adding a payment method - Notification email not sent to newly added email ID as well as there is no verification for new email id (Paypal) to HackerOne - 8 upvotes, $0
- Open redirect in "Language change". to HackerOne - 7 upvotes, $500
- Limited CSRF bypass. to HackerOne - 7 upvotes, $500
- CSV Injection at the CSV export feature to HackerOne - 7 upvotes, $500
- Login page password-guessing attack to HackerOne - 7 upvotes, $0
- LinkedIN URL should be HTTPS to HackerOne - 7 upvotes, $0
- Private Program all members disclosed to HackerOne - 7 upvotes, $0
- Leakage badges on disabled user to HackerOne - 7 upvotes, $0
- Private program activity timeline information disclosure to HackerOne - 6 upvotes, $5000
- External programs revealing info to HackerOne - 6 upvotes, $1500
- Pre-generation of 2FA secret/backup codes seems like an unnecessary risk to HackerOne - 6 upvotes, $1000
- File Name Enumeration to HackerOne - 6 upvotes, $500
- Gain reputation by creating a duplicate of an existing report to HackerOne - 6 upvotes, $500
- Increase number of bugs by sending duplicate of your own valid report to HackerOne - 6 upvotes, $500
- Session not invalidated after password reset to HackerOne - 6 upvotes, $100
- Autocomplete enabled in Paypal preferences to HackerOne - 6 upvotes, $100
- All Active user sessions should be deleted when user change his password! to HackerOne - 6 upvotes, $100
- External links should use rel="noopener" or use the redirect service to HackerOne - 6 upvotes, $0
- Reputation Manipulation (Theoretical) to HackerOne - 6 upvotes, $0
- Missing Password Confirmation at a Critical Function (Payout Method) to HackerOne - 6 upvotes, $0
- Ajouter le même utilisateur que celui déjà inscrit dans les équipes to HackerOne - 6 upvotes, $0
- Information leakage - Private reports cached by Google to HackerOne - 6 upvotes, $0
- CSP Bypass: Click handler for links with data-method="post" can cause authenticity_token to be sent off domain to HackerOne - 5 upvotes, $2000
- Ability to see common response titles of other teams (limited) to HackerOne - 5 upvotes, $1000
- No email verification on username change to HackerOne - 5 upvotes, $500
- Logic Issue with Reputation: Boost Reputation Points to HackerOne - 5 upvotes, $500
- CSV Injection with the CVS export feature to HackerOne - 5 upvotes, $500
- Improve signals in reputation to HackerOne - 5 upvotes, $500
- Multiple issues with Markdown and URL parsing to HackerOne - 5 upvotes, $500
- Websites opened from reports can change url of report page to HackerOne - 5 upvotes, $500
- CSS leaks SCSS debug info to HackerOne - 5 upvotes, $100
- Control Characters Not Stripped From Username on Signup to HackerOne - 5 upvotes, $100
- Flawed account creation process allows registration of usernames corresponding to existing file names to HackerOne - 5 upvotes, $100
- Adding an user email address to the list before confirming. to HackerOne - 5 upvotes, $0
- "learn more here", reward email - domain expired. to HackerOne - 5 upvotes, $0
- javascript: and mailto: links are allowed on users' profiles to HackerOne - 5 upvotes, $0
- Report title autocompletion to HackerOne - 5 upvotes, $0
- In markdown, parsing things like @danlec and #46072 after links is unsafe to HackerOne - 5 upvotes, $0
- Deleted name still present via mouseover functionality for user accounts to HackerOne - 5 upvotes, $0
- Reflected Filename Download to HackerOne - 5 upvotes, $0
- DOS Report FILE html inside <code> in markdown to HackerOne - 5 upvotes, $0
- Open redirect deceive in hackerone.com via another open redirect link. to HackerOne - 5 upvotes, $0
- Partial disclosure of undisclosed programs through <meta> tags to HackerOne - 5 upvotes, $0
- Information disclosure to HackerOne - 5 upvotes, $0
- Send AJAX request to external domain to HackerOne - 4 upvotes, $2500
- Cross-domain AJAX request to HackerOne - 4 upvotes, $2500
- Insecure Direct Object Reference vulnerability to HackerOne - 4 upvotes, $500
- Team Member███ associated with a Custom Group Created with 'Program Managment' only permissions can Comments on Bug Reports to HackerOne - 4 upvotes, $500
- Private Program Disclosure in /:handle/reports/draft.json endpoint to HackerOne - 4 upvotes, $500
- Private Program Disclosure in /:handle/settings/allow_report_submission.json endpoint to HackerOne - 4 upvotes, $500
- New hacktivity view discloses report IDs of non-public reports to HackerOne - 4 upvotes, $500
- New hacktivity view discloses report IDs of non-public reports to HackerOne - 4 upvotes, $500
- Session Management to HackerOne - 4 upvotes, $100
- Session Hijacking attack (Different Scenario) to HackerOne - 4 upvotes, $0
- Email changing to HackerOne - 4 upvotes, $0
- "early preview" programs disclosure to HackerOne - 4 upvotes, $0
- Markdown code block sequence makes report unreadable to HackerOne - 4 upvotes, $0
- profile cover can also load external URL's to HackerOne - 4 upvotes, $0
- Denial of Service any Report to HackerOne - 4 upvotes, $0
- Reflected File Download to HackerOne - 4 upvotes, $0
- Race Conditions Exist When Accepting Invitations to HackerOne - 4 upvotes, $0
- Issue with password change in Disabled Account to HackerOne - 4 upvotes, $0
- Information Disclosure which violate program privacy to HackerOne - 4 upvotes, $0
- Mismatch between frontend and backend validation via
ban_researcher
leads to H1 support and hackers email spam to HackerOne - 4 upvotes, $0 - SPF whitelist of mandrill leads to email forgery to HackerOne - 3 upvotes, $1000
- Edit Auto Response Messages to HackerOne - 3 upvotes, $1000
- Redirect while opening links in new tabs to HackerOne - 3 upvotes, $500
- Making any Report Failed to load to HackerOne - 3 upvotes, $500
- Accessing title of the report of which you are marked as duplicate to HackerOne - 3 upvotes, $500
- Team Member(s) associated with a Group have Read-only permission (Post internal comments) can post comment to all the participants to HackerOne - 3 upvotes, $500
- Disclosure of private programs that have an "external" page on HackerOne to HackerOne - 3 upvotes, $500
- Putting link inside link in markdown to HackerOne - 3 upvotes, $500
- creating titleless and non-closable bugs to HackerOne - 3 upvotes, $150
- DNS Misconfiguration to HackerOne - 3 upvotes, $100
- A password reset page does not properly validate the authenticity token at the server side. to HackerOne - 3 upvotes, $100
- Securing sensitive pages from SearchBots to HackerOne - 3 upvotes, $100
- Anti-MIME-Sniffing header X-Content-Type-Options header has not been set. to HackerOne - 3 upvotes, $100
- Potential denial of service in hackerone.com/<program>/reward_settings to HackerOne - 3 upvotes, $100
- HTTPS is not enforced for objects stored by HackerOne on Amazon S3 to HackerOne - 3 upvotes, $0
- Missing spf flags for hackerone.com to HackerOne - 3 upvotes, $0
- Enumeration/Guess of Private (Invited) Programs to HackerOne - 3 upvotes, $0
- Logical Issue (Boosting Reputation points) to HackerOne - 3 upvotes, $0
- Minimum bounty of a private program is visible for users that were removed from the program to HackerOne - 3 upvotes, $0
- attack in not an authorized user to HackerOne - 3 upvotes, $0
- Null byte injection to HackerOne - 3 upvotes, $0
- Email Address Leak to HackerOne - 3 upvotes, $0
- Accepting Invalid characters on email address to HackerOne - 3 upvotes, $0
- Signals get affected once reports closed as self to HackerOne - 3 upvotes, $0
- Weird Bug - Ability to see partial of other user's notification to HackerOne - 2 upvotes, $500
- Redirect FILTER bypass in report/comment to HackerOne - 2 upvotes, $500
- Window Opener Property Bug to HackerOne - 2 upvotes, $500
- Improper way of validating a program to HackerOne - 2 upvotes, $500
- Team member invitations to sandboxed teams are not invalidated consistently (v2) to HackerOne - 2 upvotes, $500
- Content Spoofing - External Link Warning Page to HackerOne - 2 upvotes, $500
- Issue with password change to HackerOne - 2 upvotes, $500
- Logic error with notifications: user that has left team continues to receive notifications and can not 'clean' this area on account to HackerOne - 2 upvotes, $500
- mailto: link injection on https://hackerone.com/directory to HackerOne - 2 upvotes, $500
- Number of invited researchers disclosed as part of JSON search response to HackerOne - 2 upvotes, $500
- CSV Injection via the CSV export feature to HackerOne - 2 upvotes, $500
- Distinguish EP+Private vs Private programs in HackerOne to HackerOne - 2 upvotes, $500
- CSV Injection via the CSV export feature to HackerOne - 2 upvotes, $500
- Mediation link can be accepted by other users to HackerOne - 2 upvotes, $500
- SECURITY: Referencing previous Reports attachment_IDs on new Reports via Draft_Sync DELETES Attachments to HackerOne - 2 upvotes, $500
- Issue with remember_user_token to HackerOne - 2 upvotes, $150
- Category- Broken Authentication and Session Management (leads to account compromise if some conditions are met) to HackerOne - 2 upvotes, $100
- Change Any username and profile link in hackerone to HackerOne - 2 upvotes, $100
- Denial of Service to HackerOne - 2 upvotes, $100
- Arbitrary file uploads to Amazon WS. to HackerOne - 2 upvotes, $0
- Flooding mailbox of user to HackerOne - 2 upvotes, $0
- harvesting attack on user registration to HackerOne - 2 upvotes, $0
- No option to logout concurrent sessions to HackerOne - 2 upvotes, $0
- Account takeover to HackerOne - 2 upvotes, $0
- Restrict any user from logging into his account. to HackerOne - 2 upvotes, $0
- Homograph Attack to HackerOne - 2 upvotes, $0
- Minor Bug: Public un-compiled CSS with original sass, versioning, source map, comments, etc. to HackerOne - 2 upvotes, $0
- Content spoofing on invitations page to HackerOne - 2 upvotes, $0
- Sending emails (via HackerOne) impersonating other users to HackerOne - 2 upvotes, $0
- Abusing HOF rankings in limited circumstances to HackerOne - 2 upvotes, $0
- Possible XSS to HackerOne - 2 upvotes, $0
- Add text to the title of the page "Thanks" to HackerOne - 2 upvotes, $0
- Spamming any user from Reset Password Function to HackerOne - 2 upvotes, $0
- HackerOne Important Emails Notification are sent in clear-text to HackerOne - 2 upvotes, $0
- Reverse Tabnabbing Vulnerability in Outgoing Links to HackerOne - 2 upvotes, $0
- Reputation gain split by company can be used to track the existence of otherwise undisclosed reports to HackerOne - 2 upvotes, $0
- Breaking Bugs as team member to HackerOne - 1 upvotes, $500
- Team member invitations to sandboxed teams are not invalidated consistently to HackerOne - 1 upvotes, $500
- Open-redirect on hackerone.com to HackerOne - 1 upvotes, $500
- Homograph attack to HackerOne - 1 upvotes, $500
- Fake URL + Additional vectors for homograph attack to HackerOne - 1 upvotes, $500
- External URL page bypass to HackerOne - 1 upvotes, $500
- Reopen Disable Accounts/ Hidden Access After Disable to HackerOne - 1 upvotes, $500
- Invitation is not properly cancelled while inviting to bug reports. to HackerOne - 1 upvotes, $500
- Private Program and bounty details disclosed as part of JSON search response to HackerOne - 1 upvotes, $500
- User with Read-Only permissions can request/approve public disclosure to HackerOne - 1 upvotes, $500
- User with Read-Only permissions can edit the Internal comment Activities on Bug Reports After Revoke the team access permissions to HackerOne - 1 upvotes, $500
- User with Read-Only permissions can manually public disclosure the report to HackerOne - 1 upvotes, $500
- Internal bounty and swag details disclosed as part of JSON response to HackerOne - 1 upvotes, $500
- Potential denial of service in hackerone.com/teams/new to HackerOne - 1 upvotes, $100
- Password Reset Bug to HackerOne - 1 upvotes, $100
- Marking notifications as read CSRF bug to HackerOne - 1 upvotes, $100
- Criptographic Issue: Strisct Transport Security with not good max age..(TOO SHORT!) to HackerOne - 1 upvotes, $0
- Improper filtering of classes used in codeblocks in Markdown to HackerOne - 1 upvotes, $0
- Cache leads to Privacy leaks to HackerOne - 1 upvotes, $0
- Account Hijacking (Only rare case scenario) to HackerOne - 1 upvotes, $0
- Notification of previous signed out user leakage. to HackerOne - 1 upvotes, $0
- Auto Approval of Invitation to join Team as a Team member to HackerOne - 1 upvotes, $0
- Substantially weakened authenticity verification when using 'Remember me for a week' to HackerOne - 1 upvotes, $0
- Reflected File Download attack allows attacker to 'upload' executables to hackerone.com domain to HackerOne - 1 upvotes, $0
- (lack of) smtp transport layer security to HackerOne - 1 upvotes, $0
- Email Notification should be get while changing Paypal Email to HackerOne - 1 upvotes, $0
- Weak HSTS age in support hackerone site to HackerOne - 1 upvotes, $0
- Hackerone impersonation to HackerOne - 1 upvotes, $0
- HackerOne Private Programs users disclosure and de-anonymous-ize to HackerOne - 1 upvotes, $0
- Requesting unknown file type returns Ruby object w/ address to HackerOne - 1 upvotes, $0
- User with Read-Only permissions can edit the SwagAwarded Activities on Bug Reports to HackerOne - 1 upvotes, $0
- Redirection Page throwing error instead of redirecting to site to HackerOne - 1 upvotes, $0
- URL Crashing browser. {Tested on firefox, Chrome and Safari} to HackerOne - 1 upvotes, $0
- Content Spoofing via reports to HackerOne - 1 upvotes, $0
- Denial of service in report view. to HackerOne - 1 upvotes, $0
- Pending member invitations are not revoked on program name change to HackerOne - 1 upvotes, $0