
hackerone-reports
Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

CVE-2026-45746, CVE-2026-45750, CVE-2026-53547 — three critical vulnerabilities in Termix: cross-tenant session hijacking, OS command injection, and…

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…

CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)

Technical analysis and advisory for CVE-2026-48908: Unauthenticated Arbitrary File Upload to RCE in JoomShaper SP Page Builder.

Professional vulnerability assessment report for Kirki WordPress account security risk, including technical impact, remediation, and mitigation…

PoC & Write-up for CVE-2025-68434: Critical CSRF in OpenSourcePOS. Exploits a disabled filter configuration to allow unauthenticated attackers to…

Public advisory for CVE-2025-65640: Stored XSS vulnerability in Globe Document Intelligence.

Detailed CVE-2025-67876 proof-of-concept demonstrating stored XSS in ChurchCRM group role names leading to admin session hijacking, with full…

This repository provides a practical comparison of breach intelligence, dark web monitoring, and identity exposure services, with a focus on factors…

Authenticated Stored Cross-Site Scripting (XSS) in IndieWeb WordPress Plugin

Proof-of-concept demonstrating unauthenticated cross-origin takeover of Nhost MCP Server, enabling database exfiltration, table drops, and permission…

eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's…

A reflected Cross-Site Scripting (XSS) vulnerability exists in the Edit User functionality of the Microworld Technologies eScan Management Console…

🧨 CVE-2025-14783: Easy Digital Downloads Account Takeover PoC

A public disclourse of CVE-2025-67730 in Frape lms By dharan ragunathan

In-depth technical analysis of CVE-2025-1974 (IngressNightmare), a critical RCE in ingress-nginx validating admission controller for Kubernetes,…

Detailed disclosure of CVE-2025-22963, a CSRF vulnerability in Teedy <= v1.11 enabling account takeover via forced user information changes.