bugforge 15
- XInclude Injection to Arbitrary File Read | Tanuki
- IDOR via Sequential Order IDs | Cheesy Does It
- Race Condition in Cart and Checkout Flow – Multi-Item Purchase for Single Charge | Cafe Club
- GraphQL Introspection and Sensitive Data Exposure | Ottergram
- Predictable Time-Based Auth Token Leading to Authentication Bypass | Sokudo
- Weak Session Token Design – Predictable MD5-Based Session Hijacking | CopyPasta
- XML External Entity (XXE) via Deck Import Feature | Tanuki
- Path Traversal – Arbitrary File Read via Image Endpoint | Ottergram
- Broken Authentication – Predictable Timestamp Token Leads to Admin Account Takeover | Sokudo
- Broken Access Control – Admin Access Token Brute Force Leads to Unauthorized Admin Access | Gift List
- Broken Access Control – Role Manipulation via User Registration | Tanuki
- Command Injection – Remote Code Execution via rollOptions Parameter | Diceforge
- File Inclusion – Arbitrary File Read via Image Endpoint | Ottergram
- IDOR – Unauthorized Access to Shared Notes via Base64 ID Manipulation | BugForge
- Broken Access Control – Unauthorized Stats Modification via HTTP Method Manipulation | BugForge