You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: tops_by_bug_type/TOPCLICKJACKING.md
+27-27Lines changed: 27 additions & 27 deletions
Original file line number
Diff line number
Diff line change
@@ -1,13 +1,13 @@
1
1
Top Clickjacking reports from HackerOne:
2
2
3
3
1.[RCE of Burp Scanner / Crawler via Clickjacking ](https://hackerone.com/reports/1274695) to PortSwigger Web Security - 163 upvotes, $3000
4
-
2.[Twitter Periscope Clickjacking Vulnerability](https://hackerone.com/reports/591432) to X (Formerly Twitter) - 134 upvotes, $1120
5
-
3.[Highly wormable clickjacking in player card](https://hackerone.com/reports/85624) to X (Formerly Twitter) - 132 upvotes, $0
4
+
2.[Twitter Periscope Clickjacking Vulnerability](https://hackerone.com/reports/591432) to X / xAI - 134 upvotes, $1120
5
+
3.[Highly wormable clickjacking in player card](https://hackerone.com/reports/85624) to X / xAI - 132 upvotes, $0
6
6
4.[Clickjacking on donation page](https://hackerone.com/reports/921709) to WordPress - 89 upvotes, $0
7
7
5.[Clickjacking in main domain https://topechelon.com/](https://hackerone.com/reports/2964441) to Top Echelon Software - 77 upvotes, $0
8
-
6.[Viral Direct Message Clickjacking via link truncation leading to capture of both Google credentials & installation of malicious 3rd party Twitter App](https://hackerone.com/reports/643274) to X (Formerly Twitter) - 64 upvotes, $0
8
+
6.[Viral Direct Message Clickjacking via link truncation leading to capture of both Google credentials & installation of malicious 3rd party Twitter App](https://hackerone.com/reports/643274) to X / xAI - 64 upvotes, $0
9
9
7.[Sensitive Clickjacking on admin login page.](https://hackerone.com/reports/389145) to Shipt - 55 upvotes, $0
10
-
8.[Stealing User emails by clickjacking cards.twitter.com/xxx/xxx](https://hackerone.com/reports/154963) to X (Formerly Twitter) - 49 upvotes, $0
10
+
8.[Stealing User emails by clickjacking cards.twitter.com/xxx/xxx](https://hackerone.com/reports/154963) to X / xAI - 49 upvotes, $0
11
11
9.[Clickjacking vkpay](https://hackerone.com/reports/374817) to VK.com - 44 upvotes, $0
12
12
10.[[api.tumblr.com] Exploiting clickjacking vulnerability to trigger self DOM-based XSS](https://hackerone.com/reports/953579) to Automattic - 30 upvotes, $0
13
13
11.[URL is vulnerable to clickjacking https://app.passit.io/](https://hackerone.com/reports/530008) to Passit - 28 upvotes, $0
@@ -32,7 +32,7 @@ Top Clickjacking reports from HackerOne:
32
32
30.[Clickjacking on https://www.goodhire.com/api](https://hackerone.com/reports/298028) to Inflection - 12 upvotes, $0
33
33
31.[URL is vulnerable to clickjacking](https://hackerone.com/reports/712376) to MyCrypto - 12 upvotes, $0
34
34
32.[Modify account details by exploiting clickjacking vulnerability on refer.wordpress.com](https://hackerone.com/reports/765355) to Automattic - 12 upvotes, $0
35
-
33.[Clickjacking Periscope.tv on Chrome](https://hackerone.com/reports/198622) to X (Formerly Twitter) - 11 upvotes, $560
35
+
33.[Clickjacking Periscope.tv on Chrome](https://hackerone.com/reports/198622) to X / xAI - 11 upvotes, $560
36
36
34.[AWS S3 website can't serve security headers, may allow clickjacking](https://hackerone.com/reports/149572) to Legal Robot - 11 upvotes, $0
37
37
35.[Following links are vulnerable to clickjacking](https://hackerone.com/reports/289246) to Semrush - 11 upvotes, $0
38
38
36.[Single Sing On - Clickjacking](https://hackerone.com/reports/299009) to Semrush - 11 upvotes, $0
@@ -86,28 +86,28 @@ Top Clickjacking reports from HackerOne:
86
86
84.[Clickjacking at surveylink.yahoo.com](https://hackerone.com/reports/3578) to Yahoo! - 3 upvotes, $0
0 commit comments