Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Bug Bounty Intelligence

Source: HackerOne public disclosures · updated every 6h

Browse publicly disclosed bug bounty reports from HackerOne. Filter by severity, weakness type, or program. Cross-referenced with CVE IDs where available.

Disclosed Reports
12,221
CVE-linked
1,854
Programs
342
New This Week
6
Csrf on creating course
Udemy Cross-Site Request Forgery (CSRF) (CWE-352)
Unknown
2017-01-10
CSRF csrftoken in cookies
Gratipay Cross-Site Request Forgery (CSRF) (CWE-352)
High
2016-12-07
account.ubnt.com CSRF
Ubiquiti Inc. Cross-Site Request Forgery (CSRF) (CWE-352)
Unknown
2016-12-05
Order-phishing via Payment ID URL
PortSwigger Web Security Cross-Site Request Forgery (CSRF) (CWE-352)
Low
2016-11-30
Unknown
2016-11-21
CSRF in github integration
Slack Cross-Site Request Forgery (CSRF) (CWE-352)
Medium
2016-11-18
Possible CSRF during external programs
HackerOne Cross-Site Request Forgery (CSRF) (CWE-352)
Low
2016-10-18
Cross-Site Request Forgery (CSRF)
Instacart Cross-Site Request Forgery (CSRF) (CWE-352)
Unknown
2016-10-13
Twitter Disconnect CSRF
Eternal Cross-Site Request Forgery (CSRF) (CWE-352)
Unknown
2016-09-30
Send emails to all users using Camptix
Ian Dunn Cross-Site Request Forgery (CSRF) (CWE-352)
Unknown
2016-09-27
Unknown
2016-09-27
Unknown
2016-09-19
Unknown
2016-09-15
CSRF To change Email Notification Settings
Instacart Cross-Site Request Forgery (CSRF) (CWE-352)
Unknown
2016-09-15
CSRF
Legal Robot Cross-Site Request Forgery (CSRF) (CWE-352)
Unknown
2016-09-09
Unknown
2016-09-02
CSRF Add Album On onpatient.com
drchrono Cross-Site Request Forgery (CSRF) (CWE-352)
Unknown
2016-08-31
Top Weakness Types
Most Active Programs
ProgramReportsMax $
U.S. Dept Of Defense896
Internet Bug Bounty817
HackerOne609
Nextcloud582
Shopify464
curl440
Node.js third-party modules307
GitLab258 $13,950
X / xAI250 $2,500
Uber239