Top 100 Upvoted Reports

Top 100 upvoted reports from HackerOne:

  1. Account takeover via leaked session cookie to HackerOne - 1447 upvotes, $20000

  2. Potential pre-auth RCE on Twitter VPN to Twitter - 1135 upvotes, $20160

  3. WannaCrypt “Killswitch” to HackerOne - 790 upvotes, $10000

  4. DoS on PayPal via web cache poisoning to PayPal - 790 upvotes, $9700

  5. Subdomain Takeover to Authentication bypass to Roblox - 659 upvotes, $2500

  6. Webshell via File Upload on ecjobs.starbucks.com.cn to Starbucks - 657 upvotes, $4000

  7. Time-Based SQL injection at city-mobil.ru to Mail.ru - 609 upvotes, $15000

  8. Getting all the CD keys of any game to Valve - 597 upvotes, $20000

  9. Ability to reset password for account to Upserve - 595 upvotes, $3500

  10. Stored XSS in Wiki pages to GitLab - 590 upvotes, $4500

  11. Stored XSS on imgur profile to Imgur - 586 upvotes, $650

  12. The return of the < to Rockstar Games - 518 upvotes, $1000

  13. Shopify Stocky App OAuth Misconfiguration to Shopify - 508 upvotes, $5000

  14. BAD Code ! to Paragon Initiative Enterprises - 468 upvotes, $0

  15. Reflected XSS in OAUTH2 login flow to LINE - 462 upvotes, $1989

  16. Steal ALL collateral during liquidation by exploiting lack of validation in flip.kick to Maker Ecosystem Growth Holdings, Inc - 461 upvotes, $50000

  17. XSS in steam react chat client to Valve - 444 upvotes, $7500

  18. XSS vulnerable parameter in a location hash to Slack - 435 upvotes, $1100

  19. How the Bug stole hacking to HackerOne - 435 upvotes, $0

  20. Blind SQL Injection to InnoGames - 427 upvotes, $2000

  21. Access to multiple production Grafana dashboards to Snapchat - 423 upvotes, $10000

  22. Open prod Jenkins instance to Snapchat - 419 upvotes, $15000

  23. CRLF injection to Twitter - 404 upvotes, $2940

  24. Account Takeover worki.ru to Mail.ru - 388 upvotes, $1700

  25. Remote code execution on Basecamp.com to Basecamp - 383 upvotes, $5000

  26. Blind XSS on image upload to CS Money - 382 upvotes, $1000

  27. Stored XSS Vulnerability to WordPress - 381 upvotes, $500

  28. Read-only application can publish/delete fleets to Twitter - 377 upvotes, $7700

  29. Cross-organization data access in city-mobil.ru to Mail.ru - 363 upvotes, $8000

  30. SQL injection at fleet.city-mobil.ru to Mail.ru - 360 upvotes, $10000

  31. Account TakeOver at my.33slona.ru to Mail.ru - 359 upvotes, $1700

  32. Account TakeOver at my.33slona.ru to Mail.ru - 359 upvotes, $1700

  33. RCE on shared.mail.ru due to "widget" plugin to Mail.ru - 358 upvotes, $10000

  34. URL link spoofing to Slack - 349 upvotes, $250

  35. Stored XSS in wordpress.com to Automattic - 345 upvotes, $650

Back

Last updated