api-security 8
- NoSQL Injection via Search Filter Object Leads to Hidden Rental Disclosure | SwiftSearch Hotels
- GraphQL BOLA via Introspection & Insecure Resolver Access | Slate Quarry
- JWT Secret Cracking & Privilege Escalation via Forged Tokens | Tally
- XInclude Injection to Arbitrary File Read | Tanuki
- IDOR via Sequential Order IDs | Cheesy Does It
- IDOR in Order Access – Unauthorized Order Data Exposure | Hartwood
- GraphQL Introspection and Sensitive Data Exposure | Ottergram
- Predictable Token Enumeration – Gift Card Redemption Abuse | BugForge Lab