information-disclosure 31
- Hidden GraphQL Field Leads to API Key Disclosure | BuggedUp
- LDAP Injection Leads to Authentication Bypass and Blind Secret Extraction | Bound
- AI Prompt Bypass Exposes Restricted Production Secret | Indexed
- Prompt Injection Leads to Secret Disclosure | Statica
- Exposed Git Repository Leads to Header-Based Admin Bypass | Packed
- SQL Injection Exposes API Credentials | CarCloppin
- Exposed Admin Route and Default Credentials Lead to Staff Panel Access | Powerpopped
- SQL Injection Exposes Internal Vault Secret | LuggageLift
- Information Disclosure via Exposed Git Repository | GamedYourself
- SQL Injection Leads to Hidden Product Data Disclosure | BackAisle
- Locked - Exposed Git Repository to Authentication Bypass | Locked"
- Local File Inclusion and SQL Injection to RCE | Keyem
- Multi-Step Access Control Bypass Leads to Administrative Compromise | Tamper Temple
- Information Disclosure – Sensitive Resource Exposure via robots.txt | Sundial Observatory
- Information Disclosure – Redirect Debug Comment Exposure | Redirect Run
- Information Disclosure – Sensitive HTML Comment Exposure | Vellichor Press
- Information Disclosure – Debug Branch Receipt Exposure | Quikpay Receipts
- Information Disclosure – Client-Side Analytics Exposure | Pebble & Pine
- Exposed Git Repository Information Disclosure | Loop & Roam Records
- Local File Inclusion via Double URL Encoding | Mirage
- GraphQL Information Disclosure – System Configuration Exposure | Schematic
- Sensitive Information Disclosure – Secrets Exposed in Base64 Session Cookie | Cookie Cutter
- Information Disclosure – Sensitive Debug Header Leakage via Response Metadata | Header Hunt
- SQL Injection to Admin Access – Hidden Identity Exposure | The Caretaker
- LDAP Injection – Hidden Registrar Archive Disclosure | Saint Croix University
- GraphQL Introspection and Sensitive Data Exposure | Ottergram
- UUID-Based IDOR Through Member API | Apex
- Local File Inclusion – Arbitrary File Read Leading to Flag Disclosure | Corridor
- SQL Injection – Full Database Extraction via Search Function | Flower
- Information Disclosure – Sensitive Data Exposure via Source Code, Headers & Public Files | Hidden in Plain Sight
- Broken Access Control – Unprotected Admin Panel via Unpredictable URL Leading to Privilege Escalation | Unprotected Admin Panel