Daily Bug Bounty Writeups by @Piyush Kumawat
This repository contains Bug Bounty writeups
-
💯September 15, 2026 - How HTML Sanitizers Actually Work, and the Five Ways They Break
-
💯September 15, 2026 - dont-use-client-side — picoCTF Write-up | Why Password Validation Should Never Be Client-Side
-
💯September 15, 2026 - How I Found an Unauthenticated IDOR That Exposed Every User’s PII and Access Roles
-
💯September 15, 2026 - Telegram Asked Us to Stay Silent About an XSS. We Published It Anyway.
-
💯September 15, 2026 - Web Cache Deception via URL Parsing Discrepancy — PII Disclosure & Cache Poisoning
-
💯September 14, 2026 - Agentic Bug Hunter
-
💯September 14, 2026 - How Claude Code Landed Me a $500 Supabase Bug Bounty
-
💯September 14, 2026 - Cybersecurity Blog CTF | Full Penetration Testing Challenge
-
💯September 14, 2026 - Attempting to set up my bug bounty foundation