
CVE-2020-27747
Possible Account Takeover | Brute Force Ability

Possible Account Takeover | Brute Force Ability

Bug bounty and vulnerability research reports by Desai Vinayak — includes CVE-2023-50290 (Apache Solr) and Zscaler subdomain takeover findings.

CVE-2025-4322 – Unauthenticated Privilege Escalation via Password Update "Account Takeover" 🔥

CVE-2020-35847, CVE-2020-35848 : Account Takeover

Unauthenticated CSRF Account TakeOver in BigTreeCMS v4.4.14

Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

LiteSpeed Unauthorized Account Takeover

Stacks Mobile App Builder <= 5.2.3 - Authentication Bypass via Account Takeover

PoC for the type confusion vulnerability in Mac's CMS that results in authentication bypass and administrator account takeover.

1-Click Login: Passwordless Authentication 1.4.5 - Authentication Bypass via Account Takeover

Implementation and exploitation of CVE-2023-7028 account takeover vulnerability related to GO-TO CVE weekly articles of the 11th week.

Cross-Site Request Forgery (CSRF) vulnerability in the password change function, which allows remote attackers to change the admin password without…

Survey XSS combined with CSRF leads to Admin Account Takeover in Concrete5 8.5.4

Exploit chain for WordPress Core using REST API route-confusion and SQL injection for unauthenticated RCE, privilege escalation, and full server…

PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)

Proof-of-concept exploit for CVE-2026-72898, an unauthenticated SQL injection in Metabase's password-reset endpoint. Forges an admin session for full…

Docker lab reproducing CVE-2026-71362 Magento/Adobe Commerce account takeover via customer-session identity switch, with PoC and official-patch A/B/A…