webverse 16
- Hidden GraphQL Field Leads to API Key Disclosure | BuggedUp
- Exposed Git Repository Leads to Header-Based Admin Bypass | Packed
- Path Traversal Leads to Arbitrary File Read | Ohmly
- Race Condition Leads to Like Counter Manipulation | CatTrap
- Blind Command Injection via GraphQL Host Checks | WorldWeb
- Server-Side Template Injection Leads to Arbitrary File Read | HammerHopper
- Command Injection Leads to Remote Code Execution | TheFallen
- Stored XSS Leads to Session Hijacking | DillyDent
- Command Injection through EXIF Metadata Processing | PhotoStore
- SVG XXE Leads to Local File Disclosure | Educated
- Information Disclosure via Exposed Git Repository | GamedYourself
- Command Injection via Filename Parameter Leading to Remote Code Execution | Quotin
- IDOR in Order Access – Unauthorized Order Data Exposure | Hartwood
- IDOR – Unauthorized Access to Borrower Records | Overdue
- Local File Inclusion – Arbitrary File Read Leading to Flag Disclosure | Corridor
- SQL Injection – Full Database Extraction via Search Function | Flower