sensitive-data-exposure 13
- SQL Injection – Secret Extraction from Internal Logs Console | Vibed
- Sensitive Information Disclosure – Secrets Exposed in Base64 Session Cookie | Cookie Cutter
- Information Disclosure – Sensitive Debug Header Leakage via Response Metadata | Header Hunt
- IDOR via WebSocket Subscription – Cross-Order Data Exposure | JoyStick
- GraphQL Introspection and Sensitive Data Exposure | Ottergram
- File Extension Blacklist Bypass – Unrestricted Upload to RCE | Hackviser Lab
- File Signature Bypass – Polyglot File Upload to RCE | Hackviser Lab
- MIME Type Filter Bypass – Unrestricted File Upload to RCE | Hackviser Lab
- Unrestricted File Upload – RCE Leading to Database Credential Disclosure | Hackviser Lab
- Information Disclosure – Sensitive Data Exposure via Source Code, Headers & Public Files | Hidden in Plain Sight
- Unauthenticated Access – MySQL Misconfiguration Leading to Data Exposure | Query Gate
- Anonymous Access – FTP Misconfiguration Leading to Credential Disclosure | File Hunter
- IDOR – Password Disclosure via Insecure Direct Object Reference | User ID Controlled by Request Parameter