A05 - Injection 63
- Prompt Injection Leads to Remote Code Execution | Plotted
- Server-Side Includes Injection Leads to Remote Code Execution | Tockerry
- Reflected XSS via Attribute Injection | Echoed
- FFmpeg Argument Injection Leads to Arbitrary File Read | Splice
- LDAP Injection Leads to Authentication Bypass and Blind Secret Extraction | Bound
- SQL Injection Exposes API Credentials | CarCloppin
- XXE Leads to Local File Disclosure | Chainline
- SQL Injection Exposes Internal Vault Secret | LuggageLift
- Prototype Pollution Leads to XSS | Subtracted
- Blind Command Injection via GraphQL Host Checks | WorldWeb
- Parameter Pollution Leads to Checkout Abuse | Unsoakable
- Server-Side Template Injection Leads to Arbitrary File Read | HammerHopper
- Command Injection Leads to Remote Code Execution | TheFallen
- Stored XSS Leads to Session Hijacking | DillyDent
- Command Injection through EXIF Metadata Processing | PhotoStore
- SVG XXE Leads to Local File Disclosure | Educated
- Server-Side Template Injection via Vault Secret Rendering | SwitchBack
- Password Reset Poisoning to Twig SSTI RCE | Inked
- Stored XSS Leads to Admin Cookie Exfiltration | Crate & Sleeve
- NoSQL Injection Leads to Authentication Bypass | Smoothie
- Stored XSS and JSONP Callback Injection Leads to Admin Session Theft | PhoneVault
- LDAP Injection Leads to Authentication Bypass | MeltDown
- SQL Injection Leads to Hidden Product Data Disclosure | BackAisle
- KrissCut — SQL Injection | KrissCut
- MooKoo — Server-Side Template Injection to RCE | Mookoo
- Local File Inclusion and SQL Injection to RCE | Keyem
- GraphQL SQL Injection to JWT Admin Forgery | SweetCore
- NoSQL Injection to Mass Assignment Admin Takeover | Expensiel
- Server-Side Template Injection via Unsigned JWT Claim | GeoJearyy
- Stored Cross-Site Scripting (XSS) Leads to Administrative Session Hijacking | PortWart
- XXE Injection via Envelope Import Leads to Arbitrary File Read | Foldmark
- NoSQL Injection Leads to Treasury Account Takeover | Coined
- NoSQL Injection via Search Filter Object Leads to Hidden Rental Disclosure | SwiftSearch Hotels
- SQL Injection in Voucher Search Leads to Executive Voucher Disclosure | Voucher Vault
- SQL Injection via Issue Identifier Parameter | Trace Control
- OS Command Injection via Archive Export Filename | Parchive
- Cross-Site Scripting (XSS) – Inadequate Input Filter Bypass | Palisade
- Cross-Site Scripting (XSS) – HTML Tag Breakout | Rivet & Tack
- Cross-Site Scripting (XSS) – HTML Comment Breakout | Fermata
- NoSQL Injection Authentication Bypass | Herbalist Remedies
- Cross-Site Scripting (XSS) – Attribute Breakout | Sandpiper Stationery
- Cross-Site Scripting (XSS) – Reflected Search Injection | Ember Kettle
- Arbitrary File Read – image Parameter Leading to file:// Injection | Suited
- SQL Injection – Full Database Extraction via UNION Attack | Versed
- OS Command Injection – Remote Command Execution via Legacy CGI Endpoint | Slash & Sons
- OS Command Injection in Network Diagnostics | Netcheck
- SQL Injection – Secret Extraction from Internal Logs Console | Vibed
- Stored XSS – Internal Endpoint Enumeration Through Comment Injection | Crate & Sleeve
- SQL Injection – Authentication Bypass on Employee Portal | Gatekeeper
- SQL Injection to Admin Access – Hidden Identity Exposure | The Caretaker
- LDAP Injection – Hidden Registrar Archive Disclosure | Saint Croix University
- Command Injection & Broken Function Level Authorization | NewsForge
- Command Injection via Filename Parameter Leading to Remote Code Execution | Quotin
- Server-Side Template Injection Leading to Remote Code Execution | Outbox
- NoSQL Injection Authentication Bypass – Admin Panel Access | SnickerDoodle
- Jinja2 SSTI to Remote Code Execution | SunnySide
- SQL Injection – UNION-Based Credential Extraction via Profile API | Ottergram
- SQL Injection – Database Extraction via Boolean-Based Blind Technique | Stock Check Lab
- SQL Injection – Credential Extraction via UNION Attack | Search Functionality Lab
- SQL Injection – Full Database Extraction via Search Function | Flower
- Command Injection – Remote Code Execution via rollOptions Parameter | Diceforge
- Server-Side Template Injection – Remote Code Execution & Data Exposure | Leaf
- Server-Side Template Injection – Remote Code Execution via Twig & Bind Shell | Leaf