api 7
- Information Disclosure – Debug Branch Receipt Exposure | Quikpay Receipts
- Mass Assignment – Role Escalation | Salt Brook Pilates
- IDOR – Account Export Data Disclosure | Remittance
- GraphQL Information Disclosure – System Configuration Exposure | Schematic
- UUID-Based IDOR Through Member API | Apex
- Broken Authentication – Predictable Timestamp Token Leads to Admin Account Takeover | Sokudo
- Broken Access Control – Unauthorized Stats Modification via HTTP Method Manipulation | BugForge