A05 - Injection 33
- XXE Injection via Envelope Import Leads to Arbitrary File Read | Foldmark
- NoSQL Injection Leads to Treasury Account Takeover | Coined
- NoSQL Injection via Search Filter Object Leads to Hidden Rental Disclosure | SwiftSearch Hotels
- SQL Injection in Voucher Search Leads to Executive Voucher Disclosure | Voucher Vault
- SQL Injection via Issue Identifier Parameter | Trace Control
- OS Command Injection via Archive Export Filename | Parchive
- Cross-Site Scripting (XSS) – Inadequate Input Filter Bypass | Palisade
- Cross-Site Scripting (XSS) – HTML Tag Breakout | Rivet & Tack
- Cross-Site Scripting (XSS) – HTML Comment Breakout | Fermata
- NoSQL Injection Authentication Bypass | Herbalist Remedies
- Cross-Site Scripting (XSS) – Attribute Breakout | Sandpiper Stationery
- Cross-Site Scripting (XSS) – Reflected Search Injection | Ember Kettle
- Arbitrary File Read – image Parameter Leading to file:// Injection | Suited
- SQL Injection – Full Database Extraction via UNION Attack | Versed
- OS Command Injection – Remote Command Execution via Legacy CGI Endpoint | Slash & Sons
- OS Command Injection in Network Diagnostics | Netcheck
- SQL Injection – Secret Extraction from Internal Logs Console | Vibed
- Stored XSS – Internal Endpoint Enumeration Through Comment Injection | Crate & Sleeve
- SQL Injection – Authentication Bypass on Employee Portal | Gatekeeper
- SQL Injection to Admin Access – Hidden Identity Exposure | The Caretaker
- LDAP Injection – Hidden Registrar Archive Disclosure | Saint Croix University
- Command Injection & Broken Function Level Authorization | NewsForge
- Command Injection via Filename Parameter Leading to Remote Code Execution | Quotin
- Server-Side Template Injection Leading to Remote Code Execution | Outbox
- NoSQL Injection Authentication Bypass – Admin Panel Access | SnickerDoodle
- Jinja2 SSTI to Remote Code Execution | SunnySide
- SQL Injection – UNION-Based Credential Extraction via Profile API | Ottergram
- SQL Injection – Database Extraction via Boolean-Based Blind Technique | Stock Check Lab
- SQL Injection – Credential Extraction via UNION Attack | Search Functionality Lab
- SQL Injection – Full Database Extraction via Search Function | Flower
- Command Injection – Remote Code Execution via rollOptions Parameter | Diceforge
- Server-Side Template Injection – Remote Code Execution & Data Exposure | Leaf
- Server-Side Template Injection – Remote Code Execution via Twig & Bind Shell | Leaf