Skip to main content
MemCyber

Disclosures

Public disclosures. Redacted where we have to.

Vulnerabilities we have disclosed through bug bounty platforms, audit contests, and direct vendor coordination. Vendor names are redacted where disclosure is still embargoed or where public attribution was not granted.

958
Disclosures listed
359
Critical severity
358
High severity
5
Reporting channels

Showing 125 of 958

Public security disclosures by MemCyber — filterable by severity, category, and reporting channel.
Finding Target Category Channel Severity Date
Fund Theft Chain via total_override + mark_as_paid on Payment Gateway

Purchase price can be overridden arbitrarily and marked paid without funds, enabling full fund theft across merchant plugin ecosystem.

CVSS 10.0
European Payment Gateway
EU
Business Logic Responsible Disclosure Critical 2026-04
Unlimited Live Payout Creation Without Verification on Payment Gateway

Live payout creation endpoint accepts unauthenticated requests producing unlimited real-money payouts to attacker-controlled accounts.

CVSS 10.0
European Payment Gateway
EU
Business Logic Responsible Disclosure Critical 2026-04
NoSQL Injection on userDetails Leading to Admin Account Compromise

Mongo operator injection on userDetails dumps admin profile including plaintext withdrawal OTP and 2FA token.

CVSS 10.0
SEA P2P Crypto Exchange
SEA
NoSQL Injection Responsible Disclosure Critical 2026-04
OAuth2 Token Forge Grants 30-Day Access Token for Any User

Token endpoint issues valid 30-day bearer tokens for arbitrary user IDs without credentials, impacting 1.73M investors.

CVSS 10.0
SEA Investment Platform
SEA
Broken Authentication Responsible Disclosure Critical 2026-04
Unauthenticated IDOR Dumps 1.73M Investor PII and KYC Photos

Profile API returns KTP, bank accounts and KYC identity_file URLs without auth for any user ID.

CVSS 10.0
SEA Investment Platform
SEA
IDOR Responsible Disclosure Critical 2026-04
Flamberge Auth-less GCS Bucket Read/Write Across 11 Buckets

Signer service issues signed GCS URLs without auth, allowing arbitrary upload/download to KYC and SBN buckets.

CVSS 10.0
SEA Investment Platform
SEA
S3 Misconfig Responsible Disclosure Critical 2026-04
JWT HS256 Weak Secret Exposed in APK Cracks to Plaintext

Legacy JWT secret `shhhhh` used for session signing; attackers forge tokens for any user or admin.

CVSS 10.0
Indian Crypto Exchange
SEA
JWT Issues Responsible Disclosure Critical 2026-04
S3 Bucket KYC Data Mass Exposure with Versioning Recovery

Public bucket lists 1352 KYC documents and versioning allows recovery of supposedly deleted files.

CVSS 10.0
Indian Crypto Exchange
SEA
S3 Misconfig Responsible Disclosure Critical 2026-04
S3 Bucket KYC Data Mass Exposure 1352 Documents

Public ThroughBit bucket lists 1352 KYC docs spanning two pagination batches.

CVSS 10.0
Indian Crypto Exchange
SEA
S3 Misconfig Responsible Disclosure Critical 2026-04
Pre-Auth RCE via Fastjson $ref Chain

Fastjson $ref gadget chain on CardGoal API yields unauthenticated remote code execution.

CVSS 10.0
Gaming Marketplace
SEA
Deserialization Responsible Disclosure Critical 2026-04
Redis Full Control via SSRF + CRLF Injection

SSRF chain sends arbitrary Redis commands enabling DB control.

CVSS 10.0
Gaming Marketplace
SEA
SSRF Responsible Disclosure Critical 2026-04
Blind SSRF: Internal Network Discovery via Timing Oracle

Response timing differentiates reachable vs unreachable internal hosts, enabling network mapping.

CVSS 10.0
Gaming Marketplace
SEA
SSRF Responsible Disclosure Critical 2026-04
Fastjson Deserialization: 60+ Dangerous Classes Reachable

60+ gadget classes instantiated via Fastjson body parsing enabling RCE and file write chains.

CVSS 10.0
Gaming Marketplace
SEA
Deserialization Responsible Disclosure Critical 2026-04
GraphQL customerSearch Returns PII + Wallet Balances Unauth

Cashia customerSearch query returns full PII and wallet balances for 60 customers without auth.

CVSS 10.0
African Neobank
Africa
GraphQL Issues Responsible Disclosure Critical 2026-04
back-office OAuth Registration Bypass -> 2.33M Transaction Data Breach

OAuth back-office allows registration with arbitrary domain leading to read access on 2.33M transactions.

CVSS 10.0
African Neobank
Africa
Auth Bypass Responsible Disclosure Critical 2026-04
payplus-1dfdf - Firestore FULL CRUD Plaintext Passwords + 13,554 KYC

Crypto platform Firestore has read/write/update/delete; plaintext passwords, PINs, 13,554 KYC images.

CVSS 10.0
African Fintech Firebase Cohort
Africa
Firebase Misconfig Responsible Disclosure Critical 2026-04
Unauthenticated KYC Verification Forgery via SmileID Callback

/smile-id/callback accepts forged POSTs without signature/IP check; attacker can KYC-verify ANY user.

CVSS 10.0
West African Crypto Exchange
Africa
KYC Bypass Responsible Disclosure Critical 2026-04
Unauthenticated API Keys Endpoint Exposes 288 Business Keys

Public endpoint returns 288 merchant API keys enabling attacker to act as any merchant on the platform.

CVSS 10.0
African Crypto Payment Processor
Africa
Credential Exposure Responsible Disclosure Critical 2026-04
Internal Backend Exposed on Eight Ports With No Firewall

Backend host reachable on eight internal ports directly from the internet, exposing databases and admin services without firewall.

CVSS 10.0
African Crypto Payment Processor
Africa
Cloud Misconfig Responsible Disclosure Critical 2026-04
Redis Commander Unauth Full Read/Write Access

Redis Commander UI exposed without auth allowing arbitrary read/write against production Redis.

CVSS 10.0
African Crypto Payment Processor
Africa
Admin Panel Exposure Responsible Disclosure Critical 2026-04
Kafdrop Unauth Full Kafka Access

Kafdrop UI accessible without credentials disclosing 29 topics with live payment messages and offsets.

CVSS 10.0
African Crypto Payment Processor
Africa
Admin Panel Exposure Responsible Disclosure Critical 2026-04
EVM Webhook Deposit Injection (Production)

Production EVM deposit webhook lacks signature validation enabling injection of forged confirmed deposits.

CVSS 10.0
African Crypto Payment Processor
Africa
Webhook Forgery Responsible Disclosure Critical 2026-04
Eight+ Payment Gateway Webhooks Forgeable

All eight inbound payment gateway webhooks accept forged payloads permitting arbitrary balance manipulation.

CVSS 10.0
African Crypto Payment Processor
Africa
Webhook Forgery Responsible Disclosure Critical 2026-04
Complete Attack Chain: Create->Forge->Validate = Free Money

Chain of unauthenticated transaction creation plus webhook forgery and broken validation yields free settled funds.

CVSS 10.0
African Crypto Payment Processor
Africa
Business Logic Responsible Disclosure Critical 2026-04
Internal Webhooks Accept Negative Amounts and Race Conditions

All eight internal webhooks accept negative amounts and exhibit race conditions enabling arbitrary balance inflation.

CVSS 10.0
African Crypto Payment Processor
Africa
Business Logic Responsible Disclosure Critical 2026-04
RabbitMQ Default Credentials (guest/guest)

RabbitMQ broker retains guest/guest default allowing full AMQP access including administrative actions.

CVSS 10.0
EU iGaming Operator
EU
Default Creds Responsible Disclosure Critical 2026-04
SumSub Webhook Forgery -- KYC Bypass

POST https://[vendor]/kyc/sumsub_webhook/ Content-Type: application/json

CVSS 10.0
EU Crypto Exchange
EU
KYC Bypass Responsible Disclosure Critical 2026-04
[vendor] S3 Bucket Full Compromise - Deep Exfiltration Proof

Target: [vendor] Asset: AWS S3 Bucket [vendor] (us-west-2) Status: VERIFIED - Full R/W/D Access Proven

CVSS 10.0
EU Crypto Exchange
EU
S3 Misconfig Responsible Disclosure Critical 2026-04
S3 Full Read/Write/Delete via Unauthenticated Cognito Role

AWS Cognito Identity Pool us-east-1:b1cc32f2-117f-41c3-b797-e19d0e41b75e unauthenticated erisime acik. Elde edilen IAM role amplify-korapaykyc-dev-41238-unauthRole, [vendor] S3 bucket'ina s3:PutObject, s3:GetObject, s3:DeleteObject, s3:ListBucket dahil tam erisim sagliyor. Bucket versioning KAPALI. Bu, saldirganin KYC dokumentlarini okuyabil

CVSS 10.0
EU Crypto Exchange
EU
S3 Misconfig Responsible Disclosure Critical 2026-04
Firebase Storage Full R/W/D — 247,303+ Customer Documents

> UPGRADED from original report: File count increased from 20,000 to 247,303+. WRITE and DELETE access confirmed

CVSS 10.0
African SME Lender
Africa
Firebase Misconfig Responsible Disclosure Critical 2026-04
[vendor] - Full Account Takeover Chain (End-to-End Proof)

Target: [vendor] / [vendor] Classification: CRITICAL (CVSS 10.0) Attack Type: Full Account Takeover Chain (Password Reset OTP Brute-Force + No Email Change OTP + JWT Over-Expiry)

CVSS 10.0
Crypto Payment Processor
Global
Broken Authentication Responsible Disclosure Critical 2026-04
(UPDATED): Source Map -> Full Exploitation Achieved

New evidence: - Source map-den elde edilen melumatla 3 hesab yaradildi - Butun endpoint-ler test edildi ve 8 yeni vulnerability tapildi

CVSS 10.0
Crypto Payment Processor
Global
Information Disclosure Responsible Disclosure Critical 2026-04
ATO via OTP Brute Force (No Rate Limit)

Total: 12 Critical + 6 High + 3 Medium = 21 unique findings

CVSS 10.0
Crypto Payment Processor
Global
Broken Authentication Responsible Disclosure Critical 2026-04
JWT Forgery + IDOR: Full Account Takeover & Wallet Access POC

Researcher: Atilla Memmedli

CVSS 10.0
Crypto Exchange Platform
Global
IDOR Responsible Disclosure Critical 2026-04
OTP Token Injection Leads to Mass Account Takeover

Accounts list endpoint returns server-generated OTP tokens allowing attacker to set password and take over any account zero-click.

CVSS 9.9
African Neobank
Africa
Broken Authentication Responsible Disclosure Critical 2026-04
Open Merchant Registration with Automatic Admin Privileges

Anyone can signup and is auto-granted admin role with no email or KYC verification on production merchant panel.

CVSS 9.8
European Payment Gateway
EU
Privilege Escalation Responsible Disclosure Critical 2026-04
Price Manipulation via Negative Debt Parameter

Negative debt values accepted during purchase create, reducing total due to near-zero for paid transactions.

CVSS 9.8
European Payment Gateway
EU
Business Logic Responsible Disclosure Critical 2026-04
Unauthenticated OTP Disclosure via trade/userDetails Enables ATO

trade/userDetails endpoint returns withdrawal OTP without authentication, making full account takeover one-step.

CVSS 9.8
SEA P2P Crypto Exchange
SEA
Broken Authentication Responsible Disclosure Critical 2026-04
Predictable apiKey via Exposed encryptAlgo (Forge Any User Token)

Source map exposes encryptAlgo allowing client-side generation of any user's apiKey including admin.

CVSS 9.8
SEA P2P Crypto Exchange
SEA
JWT Issues Responsible Disclosure Critical 2026-04
Auth Middleware Bypass on Crypto Withdrawal Endpoint

withdraw_amount endpoint passes decryptAlgo but skips identity check allowing unauthorized withdrawals with forged apiKey.

CVSS 9.8
SEA P2P Crypto Exchange
SEA
Auth Bypass Responsible Disclosure Critical 2026-04
Zero OTP Rate Limiting Enables 5-Minute Account Brute Force

50 sequential OTP attempts all return 404 with zero throttling allowing exhaustive OTP brute force.

CVSS 9.8
SEA P2P Crypto Exchange
SEA
Rate Limit Bypass Responsible Disclosure Critical 2026-04
Production PG2 JWT Issuer Validation Bypass for Fund Transfer

Production payment gateway accepts JWTs from enumerable issuers without signature verification on 17 fund-transfer routes.

CVSS 9.8
Indian Investment Broker
SEA
JWT Issues Responsible Disclosure Critical 2026-04
GCS Bucket Public Listing Exposes Admin Panel Backup + Source Maps

Public bucket lists 52 source maps and admin panel tarball with 407 source files including investor service code.

CVSS 9.8
SEA Investment Platform
SEA
Cloud Misconfig Responsible Disclosure Critical 2026-04
Cashfree Payment Gateway Secret Key Exposed in APK

Live Cashfree secret key embedded in APK enables server-side payment creation on attacker's behalf.

CVSS 9.8
Indian Crypto Exchange
SEA
API Key Exposure Responsible Disclosure Critical 2026-04
Unauthenticated Cryptocurrency Withdrawal Endpoints

Withdrawal endpoints skip JWT validation, allowing attacker-triggered BTC/ETH outflows.

CVSS 9.8
Indian Crypto Exchange
SEA
Auth Bypass Responsible Disclosure Critical 2026-04
Rancher Kubernetes Management API Publicly Accessible

Two Rancher K8s management APIs reachable from the internet, one at v2.11.1, allowing cluster-wide control.

CVSS 9.8
MENA Crypto Exchange
MENA
Admin Panel Exposure Responsible Disclosure Critical 2026-04
HMAC API Signing Secret Exposed in Client-Side JS

Young Platform exchange JS bundle embeds HMAC secret used to sign all BFF and Identity API requests.

CVSS 9.8
European Crypto Exchange
EU
Credential Exposure Responsible Disclosure Critical 2026-04
Unauthenticated User Deletion Endpoint

Cardify /api/user/tests/delete_user.php deletes arbitrary user accounts without auth.

CVSS 9.8
African Crypto Gift Card Platform
Africa
BFLA Responsible Disclosure Critical 2026-04
Admin Authentication Bypass via Telegram Parameter (13 Endpoints)

Setting ?telegram=1 on 13 admin endpoints bypasses session check and triggers real bank payouts/KYC approval.

CVSS 9.8
African Crypto Gift Card Platform
Africa
Auth Bypass Responsible Disclosure Critical 2026-04
Unauthenticated Gift Card Callback Forgery

Gift card OCR callback accepts forged results crediting attacker cards.

CVSS 9.8
Gaming Marketplace
SEA
Webhook Forgery Responsible Disclosure Critical 2026-04
CORS Origin Reflection + Credentials (Admin Takeover)

Admin API reflects arbitrary origin with credentials enabling cross-origin admin ATO.

CVSS 9.8
Gaming Marketplace
SEA
CORS Responsible Disclosure Critical 2026-04
Temporal UI Unauthenticated Production Payment Data Exposure

Temporal UI publicly reachable enabling workflow history viewing and namespace creation.

CVSS 9.8
African Neobank
Africa
Admin Panel Exposure Responsible Disclosure Critical 2026-04
apexmetanew - Firestore + Storage Open

Same operator as payplus; Firestore and Storage both open with financial data.

CVSS 9.8
African Fintech Firebase Cohort
Africa
Firebase Misconfig Responsible Disclosure Critical 2026-04
BTC Wallet Abuse (payplus/apexmetanew) Virtual Card Theft

446 virtual cards accessible via open Firestore enabling direct card abuse.

CVSS 9.8
African Fintech Firebase Cohort
Africa
Business Logic Responsible Disclosure Critical 2026-04
Firebase Realtime Database Open Read/Write

RTDB default rules allow anonymous writes; already exploited by external party.

CVSS 9.8
African Investment Fintech
Africa
Firebase Misconfig Responsible Disclosure Critical 2026-04
Monnify Webhook Forgery No Signature Validation

production.embed accepts Monnify webhooks without verifying monnify-signature HMAC; fake payment injection.

CVSS 9.8
African Investment Fintech
Africa
Webhook Forgery Responsible Disclosure Critical 2026-04
Metabase Setup Token Exposed Config Dump

metabase.dexpay.io leaks setup-token + 118 config keys unauth.

CVSS 9.8
African P2P Crypto Settlement
Africa
Credential Exposure Responsible Disclosure Critical 2026-04
AirSign Microservice Unauth Registration + Ed25519 Key

AirSign registers any caller producing Ed25519 key unlocking full platform access.

CVSS 9.8
African Payment Platform
Africa
Auth Bypass Responsible Disclosure Critical 2026-04
BFLA on 180+ Admin Mutations via USER JWT

Any USER JWT can call createAdmin, assignUserRole, updateKycStatus, automateWithdrawal admin mutations.

CVSS 9.8
Series B African Fintech
Africa
BFLA Responsible Disclosure Critical 2026-04
Zero-Click ATO via Unthrottled Reset OTP + Oracle

forgotPassword emits unlimited simultaneous OTPs with differential error oracle; ~3 min per victim.

CVSS 9.8
Series B African Fintech
Africa
Broken Authentication Responsible Disclosure Critical 2026-04
adminSwapCurrencies BFLA Financial Theft

USER JWT can swap any user's funds at manipulated rate; $22.5M platform-wide exposure.

CVSS 9.8
Series B African Fintech
Africa
BFLA Responsible Disclosure Critical 2026-04
Unauthenticated User Profile Modification via SmileID Callback

Same SmileID callback overwrites displayName, first/last name, and address for any user.

CVSS 9.8
West African Crypto Exchange
Africa
Access Control Responsible Disclosure Critical 2026-04
Production OTP Bypass via Test Account Backdoor

Phone 2250749994257 accepts any non-empty OTP; issues 90-day JWT with real production KYC data.

CVSS 9.8
West African Crypto Exchange
Africa
Auth Bypass Responsible Disclosure Critical 2026-04
Monnify Webhook Signature Bypass Enables Unauthenticated Deposit Injection

Monnify webhook endpoint accepts arbitrary payloads without HMAC signature or IP whitelist validation, allowing attacker to forge deposit/refund/disbursement events and credit arbitrary amounts.

CVSS 9.8
African Neobank
Africa
Webhook Forgery Responsible Disclosure Critical 2026-04
Password Reset OTP Brute Force Leads to Full Account Takeover

Password reset endpoint allows 84 consecutive OTP attempts per window with unlimited OTP requests. 4-6 digit OTP keyspace exhaustible within hours enabling account takeover of any user.

CVSS 9.8
African Neobank
Africa
Broken Authentication Responsible Disclosure Critical 2026-04
Admin Backoffice Open Registration

Admin backoffice exposes open registration, enabling any actor to self-provision an administrator account.

CVSS 9.8
African Neobank
Africa
Access Control Responsible Disclosure Critical 2026-04
Unauthenticated Mass OTP and User Data Exposure

Public accounts endpoint returns full user list with active OTP tokens permitting mass takeover pipeline.

CVSS 9.8
African Neobank
Africa
Information Disclosure Responsible Disclosure Critical 2026-04
NextAuth Authentication Bypass via Social Login Flow

NextAuth callback accepts attacker-controlled userId without proving social identity ownership, issuing session for arbitrary users.

CVSS 9.8
European iGaming Platform
EU
Auth Bypass Private Engagement Critical 2026-04
Firebase Storage Public Read/Write/Delete - 3277 Files Exposed

Firebase Storage bucket permits anonymous read, write and delete across 3277 user/course files enabling supply-chain upload and destructive actions.

CVSS 9.8
EU EdTech Platform
EU
Firebase Misconfig Responsible Disclosure Critical 2026-04
Registration PIN Verification Bypass via activate-account

Registration flow lets attacker skip PIN verification and directly invoke activate-account, creating activated accounts without email control.

CVSS 9.8
EU EdTech Platform
EU
Auth Bypass Responsible Disclosure Critical 2026-04
Change-Password IDOR Without Authorization Check

Authenticated user can change password of any other user via unprotected change-password endpoint.

CVSS 9.8
EU EdTech Platform
EU
IDOR Responsible Disclosure Critical 2026-04
Metabase Setup Token Exposed (Unauth Admin Reprovisioning)

Metabase session properties leak valid setup token usable to reconfigure admin when setup flow not finalized.

CVSS 9.8
West African B2B Fintech
Africa
Cloud Misconfig Responsible Disclosure Critical 2026-04
Kafka UI Complete Unauthenticated Access

Kafka UI reachable without auth exposing 55 topics including KYC and payment message streams.

CVSS 9.8
African Fintech Marketplace
Africa
Admin Panel Exposure Responsible Disclosure Critical 2026-04
Metabase Setup Token Exposed (bi.koywe)

Metabase BI instance exposes unrotated setup token enabling admin provisioning.

CVSS 9.8
LATAM Crypto Platform
LATAM
Cloud Misconfig Responsible Disclosure Critical 2026-04
Metabase Setup Token Exposed (bi.tiendacrypto)

Second Metabase BI tenant exposes active setup token with unauthenticated admin bootstrap path.

CVSS 9.8
LATAM Crypto Platform
LATAM
Cloud Misconfig Responsible Disclosure Critical 2026-04
Metabase Setup Token Exposure (bi.vpay.africa)

BI instance exposes active Metabase setup token enabling admin provisioning bypass.

CVSS 9.8
African Payment Platform
Africa
Cloud Misconfig Responsible Disclosure Critical 2026-04
Firestore Database — 74,676 Records with PII/BVN Exposure

> NEW FINDING — Not in original report

CVSS 9.8
African SME Lender
Africa
Firebase Misconfig Responsible Disclosure Critical 2026-04
Firebase Storage Production Bucket - Complete KYC Data Exposure

https://firebasestorage.googleapis.com/v0/b/[vendor].appspot.com/o

CVSS 9.8
African SME Lender
Africa
Firebase Misconfig Responsible Disclosure Critical 2026-04
Metabase Setup-Token Exposure

Finding: Metabase instance exposes setup-token in session properties, enabling FULL admin takeover

CVSS 9.8
SEA Crypto Exchange
SEA
Admin Panel Exposure Responsible Disclosure Critical 2026-04
[vendor] Admin API — Spring Boot Actuator Deep-Dive + Origin Bypass Chain

Target: admin-api.[vendor]:7443 ([vendor]-PRO-ADMIN-SERVICE) Base URL: https://admin-api.[vendor]:7443/AdminApi/actuator Stack: Spring Boot 3.x, Tomcat 10.1.4, Java 17.0.11+7-LTS-207, Oracle DB, Redis 7.0.15, SMTP2GO

CVSS 9.8
Global Crypto Exchange
Global
Admin Panel Exposure Responsible Disclosure Critical 2026-04
[vendor] (HashCash Consultants) - Infrastructure Vulnerability Assessment

Target: [vendor], hashcashconsultants.com, hcx.com Scope: Infrastructure, exposed services, misconfigurations

CVSS 9.8
Global Crypto Exchange
Global
KYC Bypass Responsible Disclosure Critical 2026-04
[vendor] API Authentication & Authorization Findings

Target: [vendor] (White-Label Crypto Exchange Platform) Scope: API auth bypass, IDOR, BOLA/BFLA, privilege escalation

CVSS 9.8
Global Crypto Exchange
Global
IDOR Responsible Disclosure Critical 2026-04
[vendor] - Firebase Veritabani Tam Erisim (Okuma + Yazma)

Tarih: 2026-04-10 Hedef: [vendor] ([vendor] - Nijerya Toplu Gida Alisveris Platformu) Platform: Firebase (farmcrowdy-727ba) + Medusa.js (Next.js) Toplam Bulgu: 3 (1 Critical + 1 High + 1 Medium)

CVSS 9.8
African E-Commerce Platform
Africa
Firebase Misconfig Responsible Disclosure Critical 2026-04
Security Finding

[redacted].io / [redacted][target] - Critical Security Assessment Target: app.[redacted].io, secureapi.[redacted][target], admin.[redacted][target] Total Findings: 12 (7 Critical + 3 High + 2 Medium) FINDING 1: Arbitrary BTC Balance Manipulation via Unauthenticated-Like Endpoin

CVSS 9.8
MENA Crypto Exchange
MENA
API Key Exposure Responsible Disclosure Critical 2026-04
Phase3 Critical Findings

[redacted].io / [redacted][target] - Phase 3: CVSS 10 Findings Target: [redacted].io / [redacted][target] / [target] / [target] Tester: Atilla Memmedli (Authorized Bug Bounty) NEW CRITICAL FINDINGS: 8 Verified (5 Critical + 2 High + 1 Medium)

CVSS 9.8
MENA Crypto Exchange
MENA
JWT Issues Responsible Disclosure Critical 2026-04
(NEW): Admin Account Takeover via Password Reset Chain + OTP Brute Force

Finding 22 (NEW): Admin Account Takeover via Password Reset Chain + OTP Brute Force Severity: CRITICAL (CVSS 9.8 - AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The admin password reset endpoint (`/api/v1/admin/auths/reset-password`) is fully accessible with only a device token (no user a

CVSS 9.8
Nigerian Payment Provider
Africa
Rate Limit Bypass Responsible Disclosure Critical 2026-04
API Signature Without Server Secret on 9 Brand APIs

Signing algorithm runs client-side without server secret, enabling arbitrary request signing.

CVSS 9.6
Gaming Marketplace
SEA
Broken Authentication Responsible Disclosure Critical 2026-04
Django DEBUG=True - Full Settings Dump with Admin Token

Django debug reveals 240 settings including Redis/RabbitMQ/Admin bypass token.

CVSS 9.6
African Payment Platform
Africa
Information Disclosure Responsible Disclosure Critical 2026-04
DEV Payment Gateway With Full Fund Transfer API Publicly Reachable

Non-production PG2 endpoint exposed to internet with all 17 fund routes live, forming a safe-to-exploit staging replica.

CVSS 9.5
Indian Investment Broker
SEA
Admin Panel Exposure Responsible Disclosure Critical 2026-04
Arbitrary File Write via FileOutputStream Deserialization

FileOutputStream reachable via deserialization lets attackers write arbitrary files to server.

CVSS 9.5
Gaming Marketplace
SEA
Deserialization Responsible Disclosure Critical 2026-04
ServerSocket Port Binding via Deserialization

ServerSocket instantiation allows listener binding as foothold for post-exploit.

CVSS 9.5
Gaming Marketplace
SEA
Deserialization Responsible Disclosure Critical 2026-04
GCS Bucket cashiacdn Public Listing of 14,121 Objects

Public bucket lists 14121 objects including KRA PIN certificates and KYC attachments.

CVSS 9.5
African Neobank
Africa
Cloud Misconfig Responsible Disclosure Critical 2026-04
— CVSS 10.0 — JWT Forge → Tüm Merchant API Erişimi

Finding 5 — CVSS 10.0 — JWT Forge → Tüm Merchant API Erişimi JWT Secret: `714a7ea9a0ef4d7886f41fd8b782fa7d` (HS256) Kaynak: GCE sunucu `/var/www/html/proxy/.env` + Cloud Run env var Etkilenen Merchant'lar (SUPER_ADMIN):

CVSS 9.5
African Remittance Provider
Africa
JWT Issues Responsible Disclosure Critical 2026-04
Unauthenticated Laravel Log Viewer Exposes DB Backup Emails and Admin Logs

Staging Laravel log-viewer is accessible without auth and leaks database backup delivery metadata, admin email, SQL traces, forge paths and webhook payloads.

CVSS 9.4
African Neobank
Africa
Information Disclosure Responsible Disclosure Critical 2026-04
GKE Kubernetes API Server Publicly Exposed

eramba subdomain exposes Kubernetes API server with version and verbose health responses.

CVSS 9.3
African Investment Fintech
Africa
Cloud Misconfig Responsible Disclosure Critical 2026-04
Unrestricted STOMP Topic Wildcard Subscription

STOMP broker accepts wildcard topic subscription exposing 2903 live messages including odds and user context.

CVSS 9.3
EU iGaming Operator
EU
WebSocket Issues Responsible Disclosure Critical 2026-04
Unauthenticated File Write + Webhook Forgery Chain [CRITICAL]

Vulnerable Components: - https://payout.[vendor]/file_creator.php → writes to HOOK_xLmu... directory - https://payout.[vendor]/file_reloadly_creator.php → writes to ACTIVE HOOK_JXO3... directory - https://payout.[vendor]/redbiller/ → directory listing confirms file creation

CVSS 9.3
Crypto Exchange Platform
Global
Webhook Forgery Responsible Disclosure Critical 2026-04
Security Finding

1. API Token-Only Authentication (No IP Restriction) The API is protected only by an `X-Auth-Token` header. If the API token is leaked (via .env, git history, or brute force), ALL document templates, submissions, and submitter data become accessible. There is no IP allowlist or a

CVSS 9.3
Nigerian Payment Provider
Africa
Rate Limit Bypass Responsible Disclosure Critical 2026-04
Odoo ERP Public Signup + Full Stack Trace Information Disclosure [CRITICAL]

Finding 1: Odoo ERP Public Signup + Full Stack Trace Information Disclosure [CRITICAL] Summary: erp.[redacted].ng adresinde Odoo ERP sistemi public internet'e acik ve /web/signup sayfasi aktif. Herhangi biri hesap olusturabilir. Ayrica tum hata yanitlarinda full Python stack trace'l

CVSS 9.3
Nigerian Neobank
Africa
Information Disclosure Responsible Disclosure Critical 2026-04
Security Finding

1. Attacker fetches `https://merchant.[redacted].ai/app-config.js` 2. Extracts [target] WRITE key -- can send emails/push notifications to all [redacted] merchants 3. Extracts Rutter production key -- can access merchant e-commerce integrations 4. Extracts GetStream key -- can access re

CVSS 9.3
MENA BNPL Provider
MENA
Firebase Misconfig Responsible Disclosure Critical 2026-04
— CVSS 10.0 — PROD PostgreSQL Direkt Erişim (12 Veritabanı)

Finding 1 — CVSS 10.0 — PROD PostgreSQL Direkt Erişim (12 Veritabanı) Endpoint: `[ip]:5432` (GCP Cloud SQL `[redacted]-prd`, europe-west2) — TCP AÇIK Credentials: `[redacted]-prd:idC4KeJkaaN!AoNp` Kaynak: `[redacted]-ccee8_cloudbuild/source/.tgz` → `prd.yml` CI/CD arşivi

CVSS 9.3
African Remittance Provider
Africa
Admin Panel Exposure Responsible Disclosure Critical 2026-04
Disclosure Report

| 13 | Password Reset OTP Brute Force (0 rate limit, 500+ attempts) | 8.5 | | 14 | Biometric Authentication Endpoint Discovered (/api/biometric) | 8.5 | | 15 | Nova Files Preview - Potential Arbitrary File Read | 8.5 | | 16 | Bearer Tokens Survive Password Change (persistent ATO)

CVSS 9.3
African Crypto Exchange
Africa
CORS Responsible Disclosure Critical 2026-04
Public Postman API Documentation with Production Data [CRITICAL]

Finding 3: Public Postman API Documentation with Production Data [CRITICAL] Vulnerable Endpoint: https://docs.[redacted].com/ [redacted]'nin Merchant API'si Postman Documenter ile herkese acik dokumante edilmistir. Dokumantasyon 21 endpoint, request body ornekleri, response ornekleri, me

CVSS 9.3
African Fintech
Africa
Information Disclosure Responsible Disclosure Critical 2026-04
Mid Size Platform Targets

Mid-Size Platform Targets - 10 Verified Targets with Initial Findings Tarama Tipi: Reconnaissance + Initial Vulnerability Discovery TARGET 1: [redacted] ([redacted].co) - Saudi BNPL Unicorn Company: [redacted], Saudi Arabia BNPL (Buy Now Pay Later)

CVSS 9.3
Mid-size Platforms
Global
Information Disclosure Responsible Disclosure Critical 2026-04
CRITICAL - Admin Panel Source Map Exposure (6.1 MB)

Finding 1: CRITICAL - Admin Panel Source Map Exposure (6.1 MB) URL: `https://adminer.[redacted].site` Source Maps: ALL `.js.map` files accessible (200 OK) - `app.b9a4e86d.js.map` - 111 KB

CVSS 9.3
Mixed Platforms
Global
Information Disclosure Responsible Disclosure Critical 2026-04
Firebase Mass Scan

Firebase Misconfiguration Mass Scan -- 2026-04-10 Scanned 100+ crypto/fintech platforms for Firebase security misconfigurations. Found 3 platforms with open Firebase Storage, 2 platforms with open Realtime Database, and 1 platform with open Firestore. The most critical finding is

CVSS 9.3
Firebase Mass Scan
Global
Firebase Misconfig Responsible Disclosure Critical 2026-04
Source Map Exposure - API Endpoints and Bank Account Validation Logic [CRITICAL]

Finding 2: Source Map Exposure - API Endpoints and Bank Account Validation Logic [CRITICAL] Summary: win.[redacted].ng ("[redacted] Accounts Validation") uygulamasinda source map dosyalari public erisime acik. Source map'ler, uygulamanin tam kaynak kodunu icerir ve icinden unauthentica

CVSS 9.3
Nigerian Neobank
Africa
Information Disclosure Responsible Disclosure Critical 2026-04
PIN Overwrite Without Old PIN Verification (CRITICAL - CVSS 8.8)

Finding 13: PIN Overwrite Without Old PIN Verification (CRITICAL - CVSS 8.8) Vulnerable Endpoint: `POST https://thor.[redacted].com/api/user/pin` Type: Broken Authentication (CWE-620) The `POST /api/user/pin` endpoint allows overwriting an existing transaction PIN without verifying

CVSS 9.3
African Crypto Exchange
Africa
XSS Responsible Disclosure Critical 2026-04
CRITICAL - 60+ Admin API Endpoints Exposed

Finding 2: CRITICAL - 60+ Admin API Endpoints Exposed Via source map analysis, all admin API endpoints discovered:

CVSS 9.3
Mixed Platforms
Global
Information Disclosure Responsible Disclosure Critical 2026-04
CRITICAL - Internal Support App Full Source Code Exposure (12.8MB, 500 Files, 199 GraphQL Operations)

Finding 1: CRITICAL - Internal Support App Full Source Code Exposure (12.8MB, 500 Files, 199 GraphQL Operations) The [redacted] internal support application at `supportapp-new.[redacted].com` exposes a 12.8MB source map containing 500 application source files and 199 GraphQL mutation/query d

CVSS 9.3
African Neobank
Africa
Information Disclosure Responsible Disclosure Critical 2026-04
D[redacted]s - Extracted API Endpoints

Vulnerability D[redacted]s - Extracted API Endpoints Transaction Service (12+ endpoints): Extracted User Model / Permission System Extracted Third-Party Integrations

CVSS 9.3
African Fintech
Africa
Access Control Responsible Disclosure Critical 2026-04
New Platforms Critical Findings

Yeni Platform Taramalari - Kritik Bulgular Toplam Hedef: 5 platform (3 CRITICAL + 2 HIGH attack surface) 1. [target] - CRITICAL (Stablecoin Payment Infrastructure) Sektor: Afrika stablecoin odeme altyapisi (Nigeria, Ghana, Kenya, South Africa)

CVSS 9.3
Mixed Platforms
Global
Information Disclosure Responsible Disclosure Critical 2026-04
Unauthenticated Admin Configuration Data Exposure

Admin config endpoint accessible without auth exposes admin user IDs and platform secrets.

CVSS 9.1
SEA P2P Crypto Exchange
SEA
Information Disclosure Responsible Disclosure Critical 2026-04
Mass Wallet Address IDOR Exposing 600+ Users' Crypto Addresses

Wallet address endpoint dumps 600+ user addresses without auth, enabling targeted deanonymisation.

CVSS 9.1
SEA P2P Crypto Exchange
SEA
IDOR Responsible Disclosure Critical 2026-04
getAllTradeList Unauthenticated: 3647 Trades + 120 Plaintext Emails

Public trade list dumps 3647 trades, counterparty emails, and amounts, exposing KYC-adjacent data.

CVSS 9.1
SEA P2P Crypto Exchange
SEA
Information Disclosure Responsible Disclosure Critical 2026-04
Signup Response Leaks 2FA Secret, Bcrypt Hash and OTP

Registration response returns the full Mongo user document including TOTP secret, bcrypt hash and email OTP.

CVSS 9.1
SEA P2P Crypto Exchange
SEA
Credential Exposure Responsible Disclosure Critical 2026-04
Unauthenticated TOTP OTP Generation Enables Mass User Enumeration

Public TOTP OTP endpoint differentiates valid vs invalid clientIDs, enabling enumeration and SMS bomb across 44M accounts.

CVSS 9.1
Indian Investment Broker
SEA
Broken Authentication Responsible Disclosure Critical 2026-04
AWS S3 Configuration Files Publicly Accessible

S3 config files readable without auth leak internal user IDs and service-to-service endpoints.

CVSS 9.1
SEA Investment Platform
SEA
S3 Misconfig Responsible Disclosure Critical 2026-04
Hardcoded OAuth Client Credentials in Production JavaScript

OAuth client id and secret embedded in JS allow forging tokens against backend API used by Bitcoin ATM network.

CVSS 9.1
EU Crypto ATM Operator
EU
Credential Exposure Responsible Disclosure Critical 2026-04
CORS Origin Reflection + Credentials on Admin Dashboard API

Admin dashboard API reflects any Origin with Allow-Credentials, enabling zero-click admin takeover via phishing.

CVSS 9.1
African Crypto Aggregator
Africa
CORS Responsible Disclosure Critical 2026-04
Password Reset Token Leakage + Rate Limit Bypass Enables ATO

Password reset token returned in response body and OTP verification endpoint permits brute force leading to full takeover.

CVSS 9.1
African Fintech Neobank
Africa
Broken Authentication Responsible Disclosure Critical 2026-04
Bani Payment Webhook Inverted Signature Verification

Signature check compares hashes inversely so any mismatched signature passes validation.

CVSS 9.1
African Crypto Gift Card Platform
Africa
Webhook Forgery Responsible Disclosure Critical 2026-04
SafeHaven Payment Webhook No Signature Verification

SafeHaven callback endpoint accepts forged payloads without HMAC verification.

CVSS 9.1
African Crypto Gift Card Platform
Africa
Webhook Forgery Responsible Disclosure Critical 2026-04
Crypto Deposit Webhook Inverted Checksum Verification

Deposit webhook checksum comparison inverted so forged payloads credit attacker wallets.

CVSS 9.1
African Crypto Gift Card Platform
Africa
Webhook Forgery Responsible Disclosure Critical 2026-04
Payment Callback Without Webhook Signature Verification

Shared payment callback endpoint accepts unsigned payloads enabling arbitrary deposit crediting.

CVSS 9.1
African Crypto Gift Card Platform
Africa
Webhook Forgery Responsible Disclosure Critical 2026-04
AES Decryption Key Hardcoded in Admin Source Map

Admin source map leaks AES-CBC key used to encrypt server responses; enables full decryption.

CVSS 9.1
African Digital Platform
Africa
Credential Exposure Responsible Disclosure Critical 2026-04
Zendesk Admin API Token Active - Full User Data Access

Admin Zendesk API token hardcoded in bundle, validated as active with billing_admin+moderator role.

CVSS 9.1
African P2P Crypto Settlement
Africa
Credential Exposure Responsible Disclosure Critical 2026-04
Client-Auth OTP Bypass - Any Code Returns Verified

Client auth service returns verified:true regardless of OTP value.

CVSS 9.1
African Payment Platform
Africa
Auth Bypass Responsible Disclosure Critical 2026-04
Django DEBUG=True on Production

shop.drugstoc.com and staging Django apps expose full stack traces and URL route listings.

CVSS 9.1
African Pharma B2B Platform
Africa
Information Disclosure Responsible Disclosure Critical 2026-04
Full React Source Code Exposure via Source Maps (32.1MB 2675 files)

Admin panel, payment logic, auth flow, hardcoded credentials, merchant IDs exposed via production source maps.

CVSS 9.1
LATAM Crypto Platform
LATAM
Information Disclosure Responsible Disclosure Critical 2026-04
CORS Wildcard on All API Endpoints Enables Cross-Origin Account Takeover

All production and staging API endpoints return Access-Control-Allow-Origin wildcard with Authorization header permitted; malicious site can perform authenticated cross-origin requests.

CVSS 9.1
African Neobank
Africa
CORS Responsible Disclosure Critical 2026-04
Admin Console DELETE /users/{id} Missing Admin Role Check (User Deletion)

DELETE endpoint on admin console reaches controller logic with a regular user token; any authenticated user can delete arbitrary accounts, including admins.

CVSS 9.1
African Neobank
Africa
Access Control Responsible Disclosure Critical 2026-04
reCAPTCHA v3 SECRET KEY Exposed in Client JavaScript

reCAPTCHA v3 secret key hardcoded in frontend allowing attacker to forge bot scores and bypass bot protection globally.

CVSS 9.1
Gaming Marketplace
Global
Credential Exposure Responsible Disclosure Critical 2026-04
JWT Stored in localStorage Exposed to XSS (Token Theft)

JWT access tokens persisted in localStorage are recoverable via any XSS enabling account takeover.

CVSS 9.1
European iGaming Platform
EU
JWT Issues Private Engagement Critical 2026-04
CryptoWallets IDOR Exposes 100K+ Wallet Addresses

Wallet resource enumerable by incrementing numeric ID leaks 100K+ user wallet addresses and balances.

CVSS 9.1
European iGaming Platform
EU
IDOR Private Engagement Critical 2026-04
Password Reset PIN Verify Returns 200 for Any PIN

Password reset PIN verification endpoint returns success for arbitrary input enabling password change on any email.

CVSS 9.1
EU EdTech Platform
EU
Auth Bypass Responsible Disclosure Critical 2026-04
Metabase Google OAuth without Domain Restriction

Metabase Google SSO accepts any Google identity creating self-service admin accounts wired to production database.

CVSS 9.1
West African B2B Fintech
Africa
Cloud Misconfig Responsible Disclosure Critical 2026-04
Unauthenticated OTP Send + Verify Chain (Phone Takeover)

OTP send and verify endpoints accept unlimited calls without rate limit enabling 6-digit OTP brute force phone takeover.

CVSS 9.1
West African B2B Fintech
Africa
Broken Authentication Responsible Disclosure Critical 2026-04
Infisical Secret Manager Open Registration

Infisical instance exposes open signup without email verification or captcha enabling tenant creation and lateral movement to secrets.

CVSS 9.1
African Fintech Marketplace
Africa
Cloud Misconfig Responsible Disclosure Critical 2026-04
BVN Agents Backoffice & Frontoffice Swagger UI Publicly Accessible

BVN agents admin Swagger UI reachable without auth exposing KYC agent workflows.

CVSS 9.1
African Digital Bank
Africa
Admin Panel Exposure Responsible Disclosure Critical 2026-04
Genesys Chat Full Exploitation Chain (User Impersonation)

Unauthenticated Genesys chat token generation plus WACE bot API permits impersonating arbitrary customers in live chat.

CVSS 9.1
EU iGaming Operator
EU
Business Logic Responsible Disclosure Critical 2026-04
CRM SDK CLIENT_ID + CLIENT_SECRET Hardcoded in APK

Android APK embeds CRM client credentials enabling full read/write on marketing event system across members.

CVSS 9.1
EU iGaming Operator
EU
Credential Exposure Responsible Disclosure Critical 2026-04
CRM Auth Token Generation Formula Exposed

Token generation formula decompiled from APK allows reproducing valid auth tokens offline.

CVSS 9.1
EU iGaming Operator
EU
Credential Exposure Responsible Disclosure Critical 2026-04
STOMP Broker Authentication Bypass

STOMP broker accepts CONNECT without credentials permitting unauthenticated subscription.

CVSS 9.1
EU iGaming Operator
EU
WebSocket Issues Responsible Disclosure Critical 2026-04
STOMP Odds Injection +10% Manipulation

Injected STOMP frames propagate to all subscribers allowing attacker to alter live odds received by clients.

CVSS 9.1
EU iGaming Operator
EU
WebSocket Issues Responsible Disclosure Critical 2026-04
Payout Service Directory Listing + Redbiller Webhook Data Exposure [CRITICAL]

Vulnerable Endpoint: https://payout.[vendor]/

CVSS 9.1
Crypto Exchange Platform
Global
Business Logic Responsible Disclosure Critical 2026-04
IDOR - Unauthenticated Bank Account Data Access via X-User-ID Header

Any unauthenticated attacker can read ANY user's bank account information (full legal name, bank name, masked account number, internal IDs) by simply changing the X-User-ID header. No authentication token, session cookie, or API key is required

CVSS 9.1
SEA Crypto Exchange
SEA
IDOR Responsible Disclosure Critical 2026-04
[vendor] - KYC Document Access Testing Evidence

CVSS 9.1
SEA Crypto Exchange
SEA
KYC Bypass Responsible Disclosure Critical 2026-04
CRITICAL - Supabase OKR Database Unauthenticated Full Read Access (413 Employee Records)

The OKR platform at okrs.[vendor] exposes a Supabase backend with anon key that grants unauthenticated read access to the entire profiles table containing 413 employee records with full names, job titles, teams, managers, HiBob IDs, and corporate email addresses, including C-level executives (CEO, CTO, CFO)

CVSS 9.1
European B2B Spend Management
EU
Cloud Misconfig Responsible Disclosure Critical 2026-04
CORS Wildcard with Credentials on Admin Panel and API (CRITICAL)

Finding 1: CORS Wildcard with Credentials on Admin Panel and API (CRITICAL) Severity: Critical (CVSS 9.1 - AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N) Summary: Both admin panels (hiftigh.[redacted].com and [target]) return `Access-Control-Allow-Origin: ` combined with `Access-

CVSS 9.1
MENA Fintech
MENA
CORS Responsible Disclosure Critical 2026-04
Whitelabel Partner Data and MongoDB ObjectIDs Exposed (CRITICAL)

Finding 6: Whitelabel Partner Data and MongoDB ObjectIDs Exposed (CRITICAL) Affected Component: [target] source map Summary: MongoDB ObjectIDs for all whitelabel integration partners (including Worldcoin across 8+ countries) are exposed in client-side source code, along w

CVSS 9.1
LATAM Crypto Platform
LATAM
Information Disclosure Responsible Disclosure Critical 2026-04
Production API Authentication Bypass via Encryption Key Exposure

Finding 2: Production API Authentication Bypass via Encryption Key Exposure The API gateway validation uses an AES-256-CBC encrypted `X-Request-ID` header. The encryption key, IV, API key, and subscription key are all exposed in client-side JavaScript, allowing anyone to forge va

CVSS 9.1
African Remittance Provider
Africa
API Key Exposure Responsible Disclosure Critical 2026-04
Shopify Payment Test Environment API Key Exposure (CRITICAL)

Finding 3: Shopify Payment Test Environment API Key Exposure (CRITICAL) The `sfy-payment-test.[redacted].ai` subdomain exposes a [redacted] API key in its Next.js `__NEXT_DATA__` runtime configuration, accessible without authentication. This is a Shopify payment integration test environmen

CVSS 9.1
MENA BNPL Provider
MENA
API Key Exposure Responsible Disclosure Critical 2026-04
Hardcoded AES-GCM Production Encryption Key in Web Bundle

Client-side AES-GCM key for production payload encryption exposed in JS, reducing encryption to obfuscation.

CVSS 9.0
Indian Investment Broker
SEA
Credential Exposure Responsible Disclosure Critical 2026-04
Hardcoded AES-CBC Key + IV in Mobile App

APK ships with static AES-CBC key and IV used for request protection enabling MITM decryption on all installs.

CVSS 9.0
Indian Investment Broker
SEA
Credential Exposure Responsible Disclosure Critical 2026-04
Virtual Card Callback Without Webhook Signature Verification

Virtual card issuance callbacks skip HMAC validation enabling forged card event injection.

CVSS 9.0
African Crypto Gift Card Platform
Africa
Webhook Forgery Responsible Disclosure Critical 2026-04
Blind SSRF Into Internal Kubernetes Services

Server-side fetch endpoint permits requests to internal Kubernetes cluster services facilitating metadata exfiltration.

CVSS 9.0
European iGaming Platform
EU
SSRF Private Engagement Critical 2026-04
[redacted] Staging Deep Security Assessment

[redacted].com - Staging Environment Deep Security Assessment Target: stage.[redacted].com (staging) vs [redacted].com (production) Discovered: dev.[redacted].com (development), casino.[redacted].com, admin.[redacted].com, sportsbook.[redacted].com, crypto.[redacted].com, api.[redacted].com, sb

CVSS 9.0
EU iGaming Operator
EU
API Key Exposure Responsible Disclosure Critical 2026-04
Unauthenticated Private Trade Chat Access

Trade chat endpoint serves private buyer/seller messages and shared KYC attachments without auth.

CVSS 8.8
SEA P2P Crypto Exchange
SEA
IDOR Responsible Disclosure Critical 2026-04
Coolify PaaS Deployment Platform Publicly Accessible

Coolify deployment platform accessible over internet without hardening enabling deployment and container control plane attacks.

CVSS 8.8
African Fintech Marketplace
Africa
Admin Panel Exposure Responsible Disclosure Critical 2026-04
CORS Origin Reflection with Credentials on Backend Services

Multiple backend services reflect arbitrary Origin with credentials enabling cross-origin authenticated operations.

CVSS 8.8
African Digital Bank
Africa
CORS Responsible Disclosure Critical 2026-04
STOMP Message Injection into Topics

STOMP broker accepts SEND to arbitrary topics enabling attacker to inject odds and score events.

CVSS 8.8
EU iGaming Operator
EU
WebSocket Issues Responsible Disclosure Critical 2026-04
Source Map Exposure: 243 Source Files, 10.9MB Full Frontend

Production source maps reveal 243 files including API encryption helpers, internal endpoints and admin routes.

CVSS 8.6
SEA P2P Crypto Exchange
SEA
Information Disclosure Responsible Disclosure Critical 2026-04
Vercel Deployment Credentials + Internal Infra Leak

DevDashboard JS leaks NUXT_ENV_VERCEL_ARTIFACTS_TOKEN, ORG_ID, PROJECT_ID enabling Vercel supply-chain.

CVSS 8.6
African Crypto Infrastructure
Africa
Credential Exposure Responsible Disclosure Critical 2026-04
Kubernetes Cluster Disclosure via Unauth /health

WalletPro API gateway /health reveals node IPs, pod names, service account, microservice names, Datadog labels.

CVSS 8.6
European Crypto Exchange
EU
Information Disclosure Responsible Disclosure Critical 2026-04
Payment Gateway Credentials Hardcoded in Production JS

NGenius and Checkout.com API keys embedded in SPA bundle; NGenius keys only base64-encoded.

CVSS 8.6
MENA Regulated Crypto Exchange
MENA
Credential Exposure Responsible Disclosure Critical 2026-04
Production Secret Token Hardcoded in Client-Side JavaScript

x-secret-token used by all authenticated endpoints is hard-coded in browser bundle.

CVSS 8.6
West African B2B Fintech
Africa
Credential Exposure Responsible Disclosure Critical 2026-04
Develop Environment REACT_APP_SECRET Encryption Key Disclosed

Develop bundle exposes REACT_APP_SECRET used as encryption key for client-side session storage.

CVSS 8.6
West African B2B Fintech
Africa
Credential Exposure Responsible Disclosure Critical 2026-04
Unrestricted Firebase Authentication Registration

Firebase Auth allows open email/password registration without email verification enabling unbounded account creation.

CVSS 8.6
African Fintech
Africa
Firebase Misconfig Responsible Disclosure Critical 2026-04
User App Full Source Code Exposure via Source Map (502 files)

User app exposes 9.6MB source map with 502 TypeScript files including exchange logic.

CVSS 8.6
LATAM Crypto Platform
LATAM
Information Disclosure Responsible Disclosure Critical 2026-04
KYC API Key Hardcoded in Android APK

Static KYC API key enables direct invocation of KYC provider endpoints and enumeration of document flows.

CVSS 8.5
Indian Investment Broker
SEA
API Key Exposure Responsible Disclosure Critical 2026-04
Self-Hosted Sentry Event Injection Verified

Internal Sentry DSN accepts unauth events enabling log pollution and developer alert fatigue.

CVSS 8.5
MENA Crypto Exchange
MENA
Information Disclosure Responsible Disclosure Critical 2026-04
Exchange Application Full Source Code via Source Maps

Production source maps expose complete exchange logic including private modules.

CVSS 8.5
European Crypto Exchange
EU
Information Disclosure Responsible Disclosure Critical 2026-04
Full Source Code Exposure via Source Maps (Admin Panel)

AstroAfrica admin ships Vue source maps disclosing 96 API endpoints and internal flows.

CVSS 8.5
African Astrology Platform
Africa
Information Disclosure Responsible Disclosure Critical 2026-04
Vite Dev Server Production - Full Source Code Exposure

Production dexpay.io runs vite dev exposing 19+ source files directly.

CVSS 8.5
African P2P Crypto Settlement
Africa
Information Disclosure Responsible Disclosure Critical 2026-04
CORS Misconfiguration on Login API Enables Credential Theft

Login API reflects Origin with credentials allowing a hostile page to capture 44M-user broker login session.

CVSS 8.1
Indian Investment Broker
SEA
CORS Responsible Disclosure Critical 2026-04
Complete API Authentication Bypass (ALL 66 Endpoints)

ASP.NET Core API accepts all requests without validating Authorization header; every endpoint accessible unauth.

CVSS 10.0
African Crypto Trading Platform
Africa
Auth Bypass Responsible Disclosure Critical 2026-03
SQL Injection Full Database Compromise (14.8M records)

Fraud Decision API concatenates verification_id into SQL enabling full extraction of 11 databases.

CVSS 10.0
African KYC/Identity Provider
Africa
SQLi Responsible Disclosure Critical 2026-03
Production MySQL User Created via Stacked Query

Attacker-created MySQL user with full privileges across all databases via stacked-query SQLi.

CVSS 10.0
African KYC/Identity Provider
Africa
RCE Responsible Disclosure Critical 2026-03
Wazuh SIEM API Default Credentials — Full Infrastructure Compromise

Endpoint: https://46.101.230.90:55000

CVSS 10.0
African Crypto Exchange
Africa
Credential Exposure HackerOne Critical 2026-03
[vendor] -- 30K+ Kullaniciya TOPLU ERISIM: DOGRULANMIS VEKTOR ANALIZI

Tarih: 2026-03-20 (Guncellenmis -- Aktif Test Sonuclari) Aciliyet: KRITIK -- Aktif tehdit, 200K+ kullanici risk altinda Durum: 30K hesaba zaten erisilmis. BIRISI AKTIF OLARAK BRUTE FORCE YAPIYOR

CVSS 10.0
Crypto Gaming Platform
Global
CORS Responsible Disclosure Critical 2026-03
CORS HTTP Downgrade Enables 0-Click Crypto Theft via MITM

BitValve accepts http:// origin with credentials on all 40+ endpoints letting in-path attacker drain wallets on HTTP downgrade.

CVSS 9.8
Global P2P Crypto Marketplace
Global
CORS Responsible Disclosure Critical 2026-03
HashiCorp Vault v1.12.1 Production Secrets Manager Public

Production Vault instance reachable publicly, exposing sys/metrics and AppRole endpoints.

CVSS 9.8
SEA Banking API Platform
SEA
Admin Panel Exposure Responsible Disclosure Critical 2026-03
Internal Admin API Publicly Accessible with 44 gRPC Methods

Admin gRPC service reachable without auth exposing 44 methods including user management.

CVSS 9.8
SEA Banking API Platform
SEA
Admin Panel Exposure Responsible Disclosure Critical 2026-03
Eight Dangling CNAME Subdomains Target Backend APIs

Eight CNAMEs point to deleted DigitalOcean apps, takeable to intercept dashboard/admin/staging traffic.

CVSS 9.8
African Crypto Exchange
Africa
Subdomain Takeover Responsible Disclosure Critical 2026-03
Production Widget Uses Dev-Login Backdoor + Commented Access Key

Widget bundle ships '/auth/dev-login' call and commented access-key reveals production backdoor pattern.

CVSS 9.8
African Crypto Exchange
Africa
Auth Bypass Responsible Disclosure Critical 2026-03
SQL Injection via Table Name + 3x Cloudflare WAF Bypass

Bitbns table-name parameter is SQL-injectable and three WAF bypass payloads succeed on production.

CVSS 9.8
Indian Crypto Exchange
SEA
SQLi Responsible Disclosure Critical 2026-03
NoSQL Injection on Login, Admin Login and Signup

Mongo operator injection succeeds on three auth endpoints enabling admin enumeration and auth bypass.

CVSS 9.8
African Fintech Remittance
Africa
NoSQL Injection Responsible Disclosure Critical 2026-03
MinIO S3 CORS Wildcard + Credentials with KYC Buckets Present

obiex minio-api reflects arbitrary origin with credentials and KYC/KYB buckets confirmed via 403 responses.

CVSS 9.8
African Fintech Crypto Exchange
Africa
Cloud Misconfig Responsible Disclosure Critical 2026-03
Production KYB Compliance API Internet Reachable

kyb-api.sigma.obiex.finance publicly reachable without WAF, 42-day uptime.

CVSS 9.8
African Fintech Crypto Exchange
Africa
Admin Panel Exposure Responsible Disclosure Critical 2026-03
Coolify PaaS Deployment Panel Publicly Accessible

sigma.obiex.finance hosts Coolify deployment console with wildcard CORS controlling all services.

CVSS 9.8
African Fintech Crypto Exchange
Africa
Admin Panel Exposure Responsible Disclosure Critical 2026-03
Jenkins Admin Credentials (Base64) + Build Trigger Token

la3eb Jenkins exposes Base64-encoded admin credential and build trigger token publicly.

CVSS 9.8
Saudi Gaming Marketplace
MENA
Credential Exposure Responsible Disclosure Critical 2026-03
Admin Panel + 30 Admin API Endpoints Fully Open

enjoygm admin panel reachable publicly with 30 privileged API routes and wildcard CORS.

CVSS 9.8
Gaming Recharge Platform
SEA
Admin Panel Exposure Responsible Disclosure Critical 2026-03
Admin User Hashes Exposed via GetAdmins

GET /User/GetAdmins returns 4 admin accounts with ASP.NET Identity password hashes.

CVSS 9.8
African Crypto Trading Platform
Africa
Information Disclosure Responsible Disclosure Critical 2026-03
Deposit Address Hijack via AddCryptoWallet

Unauth POST /CryptoWallet/AddCryptoWallet redirects all customer BTC/USDT deposits to attacker address.

CVSS 9.8
African Crypto Trading Platform
Africa
Business Logic Responsible Disclosure Critical 2026-03
Unauthenticated KYC Data Access (Mass PII)

/verification-details and /data endpoints expose complete KYC records unauth (5.8M BVN + 2.75M verifications).

CVSS 9.8
African KYC/Identity Provider
Africa
Access Control Responsible Disclosure Critical 2026-03
SSRF Full Data Exfiltration via 303 Redirect Chain

Checkout.com Apple Pay integration allows 303 redirect chain for OOB SSRF exfiltrating origin IP + metadata.

CVSS 9.8
EU Gaming Marketplace
EU
SSRF Responsible Disclosure Critical 2026-03
Blind XXE via Altenar XML - K8s Token + File Exfiltration

Altenar game integration accepts XML with external entities; K8s service account JWT + pod hostname exfiltrated.

CVSS 9.8
EU iGaming Operator
EU
SSRF Responsible Disclosure Critical 2026-03
Pusher E2E Encryption Key Hardcoded Full Trade Surveillance

256-bit HMAC key in JS enables subscribing private-global_private channel monitoring all trades.

CVSS 9.8
Indian Crypto Exchange
SEA
Credential Exposure Responsible Disclosure Critical 2026-03
Password Reset Token Leaked in Response Body (Full ATO)

Password reset API returns the reset code and token in response body enabling mass account takeover via email enumeration.

CVSS 9.8
Gaming Marketplace
SEA
Broken Authentication Responsible Disclosure Critical 2026-03
Outdated Camera Firmware with Multiple Known CVEs (V3.4.87-modify)

Device runs 2018 firmware vulnerable to known authentication bypass and RCE CVEs without vendor patch path.

CVSS 9.8
CCTV Infrastructure
Global
Information Disclosure Responsible Disclosure Critical 2026-03
Unauthenticated Admin Wallet Transaction History

Admin wallet transaction endpoint returns platform-wide financial history without authentication.

CVSS 9.8
African Crypto Exchange
Africa
Access Control Responsible Disclosure Critical 2026-03
Unauthenticated Admin Wallet Balance Per-Customer IDOR

Admin wallet balance endpoint accepts arbitrary customer IDs without auth revealing holdings.

CVSS 9.8
African Crypto Exchange
Africa
IDOR Responsible Disclosure Critical 2026-03
OTP Brute Force Account Takeover (No Rate Limit)

OTP verification endpoint accepts unlimited attempts with no lockout enabling account takeover.

CVSS 9.8
African Crypto Exchange
Africa
Broken Authentication Responsible Disclosure Critical 2026-03
Unauthenticated Webhook Callback - Deposit Forgery

Primary payment callback endpoint accepts arbitrary payloads without signature validation enabling deposit forgery.

CVSS 9.8
African Fintech
Africa
Webhook Forgery Responsible Disclosure Critical 2026-03
Eleven Unauthenticated Payment Callbacks (PawaPay/Peach/Encryptus/ChoiceBank/SasaPay/Fonbnk/Tanda)

Eleven different provider callback endpoints accept forged payloads across all zones enabling payment manipulation.

CVSS 9.8
African Fintech
Africa
Webhook Forgery Responsible Disclosure Critical 2026-03
Facebook/Apple Social Login Full Account Takeover (No Token Validation)

Social login endpoint accepts any provided token without validating with Facebook/Apple enabling full account takeover by email.

CVSS 9.8
MENA Travel Fintech
MENA
Auth Bypass Responsible Disclosure Critical 2026-03
HashiCorp Vault Staging Unsealed and Publicly Accessible

Staging Vault instance is unsealed, public, with UI enabled exposing secret management plane.

CVSS 9.8
LATAM Crypto Exchange
LATAM
Cloud Misconfig Responsible Disclosure Critical 2026-03
OpenSearch Security Alerts — 10,000+ Events Readable

Endpoint: https://guards.[vendor] (via kibanaserver:kibanaserver)

CVSS 9.8
African Crypto Exchange
Africa
Credential Exposure HackerOne Critical 2026-03
Production RCE Chain via Wazuh Agent Group Configuration Injection

Through the Wazuh API, an attacker can achieve Remote Code Execution on production by: 1. Creating a new agent group 2. Uploading a configuration with localfile commands 3. Assigning the production agent to that group 4. Restarting the agent to apply the configuration

CVSS 9.8
African Crypto Exchange
Africa
RCE HackerOne Critical 2026-03
Metabase Analytics Setup Token Exposed - Full Internal Config Leak

Vulnerable Endpoint: https://analytics.[vendor]/api/session/properties

CVSS 9.8
Crypto Gaming Platform
Global
Admin Panel Exposure Responsible Disclosure Critical 2026-03
Email OTP Bypass via API Token — Enables Unauthorized Withdrawals

This is the core vulnerability that makes fund theft possible. When a user withdraws crypto through the website, they must enter a 6-digit code sent to their email (email OTP). However, when using an API token (generated via /auth-http/auth/business/generate-token), this email OTP check is completely skipped. The server accepts an empty security

CVSS 9.8
Crypto Gaming Platform
Global
Auth Bypass Responsible Disclosure Critical 2026-03
Unauthenticated Xbox Order Creation on Internal API (redeem-cards.com)

The internal Xbox order fulfillment API at redeem-cards.com is accessible from the public internet without any authentication. The UserType: [vendor]Bot HTTP header bypasses all authentication, granting direct access to order creation logic that reaches the DecideXboxPreOrder() function -- one step from triggering real monetary transactions on Mi

CVSS 9.8
EU Gaming Key Marketplace
EU
Business Logic Responsible Disclosure Critical 2026-03
Full Account Takeover via Password Reset Brute Force + XFF Bypass

Any user's password can be reset without authentication, CAPTCHA, or rate limiting. The password reset code brute force endpoint has zero rate limiting -- 300+ consecutive requests were tested with 0 blocked. Combined with X-Forwarded-For bypass, the attack is completely unlimited

CVSS 9.8
EU Gaming Key Marketplace
EU
Broken Authentication Responsible Disclosure Critical 2026-03
Eski PIN sorulmadi (dogrudan yeni PIN set ediliyor)

curl -s -X POST "https://grpc-global-service-web-envoy.use[vendor]/business_banking.backend.protos.global.proto.KycManagementService/FetchAllKycLevels" \ -H "Content-Type: application/grpc-web-text" \ -H "Accept: application/grpc-web-text" \ -H "X-Grpc-Web: 1" \ -d 'AAAAAAA='

CVSS 9.8
African Payment Processor
Africa
Broken Authentication Responsible Disclosure Critical 2026-03
Bcrypt Password Hash Leaked in Registration Response AND JWT Token

POST /api/auth/register endpointi basarili kayit sonrasinda kullanicinin bcrypt password hash'ini hem JWT token payload'inda hem de response body'sinde dondurur. Ayrica GET /api/auth/me endpointi de authenticated kullanicinin password hash'ini response'da dondurur. Bu bir fintech platformunda felaket seviyesinde bir guvenlik acigi

CVSS 9.8
African Remittance Platform
Africa
JWT Issues Responsible Disclosure Critical 2026-03
[redacted] Full Report

[redacted] Infrastructure Security Assessment — Full Report Researcher: Atilla Mammadli (atillamemmedli@[target]) Target: [redacted].io and associated infrastructure Critical: 10 | High: 6 | Medium: 16 | Low/Info: 28+

CVSS 9.8
DeFi Lending/DEX Protocol
Global
Information Disclosure Responsible Disclosure Critical 2026-03
VPN Superuser Account Compromise via Weak Credentials (CRITICAL)

Finding 27: VPN Superuser Account Compromise via Weak Credentials (CRITICAL) Status: PROVEN - TOKEN OBTAINED The VPN admin account `candra@[redacted].com` uses a [redacted]ially guessable password `[redacted]123!` which grants `superuser` role access to the VPN management API. Combined

CVSS 9.8
SEA Crypto Exchange
SEA
Credential Exposure Responsible Disclosure Critical 2026-03
[redacted] 2012.55 CVE Research

[redacted] SSH 2012.55 - CVE ve Exploit Arastirmasi Hedef Versiyon: [redacted] sshd 2012.55 Amac: Authorized internal network security audit Kaynak: NVD (NIST), [redacted] CHANGES log, ExploitDB, GitHub

CVSS 9.8
SSH Infrastructure
Global
RCE Responsible Disclosure Critical 2026-03
[redacted] My Default Creds Report

[redacted] (my.[redacted].com) — Default Admin Credentials on Magento REST API Target: my.[redacted].com ([redacted] / Azerconnect) Report To: informationsecurity@[target] Severity: CRITICAL (CVSS 9.8 — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVSS 9.8
Telecom Operator
MENA
Default Creds Responsible Disclosure Critical 2026-03
K-3: Transaction Automation API with Broken Authentication (CRITICAL)

Finding K-3: Transaction Automation API with Broken Authentication (CRITICAL) Endpoint: `http://[ip]/` (port 80, same server as [redacted]) Summary: A Transaction Automation API running on the same server as [redacted] accepts ANY Bearer token value for authentication. The

CVSS 9.8
African Neobank
Africa
Admin Panel Exposure Responsible Disclosure Critical 2026-03
Zero Click Exploit

[redacted] Finance - Zero-Click Wallet Drain Exploit Analysis Target: [redacted].finance (mobilelab.[redacted].africa + [redacted]bridge.[redacted].finance) Type: Authorized Bug Bounty - Maximum Impact Chain Analysis Status: CHAIN PROVEN - Multiple 0-click and 1-click wallet drain vectors identified

CVSS 9.8
African DeFi Protocol
Africa
Rate Limit Bypass Responsible Disclosure Critical 2026-03
[redacted] SSH 2012.55 - Multiple Critical CVEs (14+ Years Old)

Finding 3: [redacted] SSH 2012.55 - Multiple Critical CVEs (14+ Years Old) CVSS Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H SSH daemon'u [redacted] 2012.55, 14+ yillik ve en az 8 bilinen CVE'ye karsi savunmasiz. Bunlar arasinda remote code execution (CVE-2016-7406) ve authenticated R

CVSS 9.8
CCTV Infrastructure
Global
RCE Responsible Disclosure Critical 2026-03
Translation Write + CDN Publish (Supply Chain Attack)

Finding 2: Translation Write + CDN Publish (Supply Chain Attack) Type: CWE-94 (Supply Chain Compromise) Step 4 — Confirmed on live site: GCS file modification timestamp updated to `2026-03-23T10:14:49.721Z` during our test. All values were restored immediately after verification.

CVSS 9.8
Global Crypto Exchange
Global
Information Disclosure Responsible Disclosure Critical 2026-03
Critical Oss Sts Finding

CRITICAL: Unauthenticated STS Token Generation → Full OSS Bucket Read/Write Access Target: [redacted].store (Nigerian gift card P2P trading platform, ~1.3M users) Status: Authorized Penetration Test Unauthenticated Alibaba Cloud STS Token Generation via getOssToken API Leads to Full Re

CVSS 9.8
SEA Crypto Exchange
SEA
API Key Exposure Responsible Disclosure Critical 2026-03
Ato Chain Verified

[redacted] ([redacted].az) - Full Account Takeover Chain Verification Target: https://api.[redacted].az (Production API) Classification: CRITICAL - Full Account Takeover (CVSS 9.8) Status: FULLY VERIFIED on production

CVSS 9.8
EU iGaming Operator
EU
Rate Limit Bypass Responsible Disclosure Critical 2026-03
Google OAuth CSRF via Empty State Parameter

BitValve OAuth flow omits state parameter enabling CSRF-based account takeover via attacker-supplied code.

CVSS 9.6
Global P2P Crypto Marketplace
Global
Broken Authentication Responsible Disclosure Critical 2026-03
Apple OAuth CSRF via Static 'apple' State Parameter

Apple OAuth always sets state=apple allowing reliable CSRF account linkage on victim sessions.

CVSS 9.6
Global P2P Crypto Marketplace
Global
Broken Authentication Responsible Disclosure Critical 2026-03
Google OAuth Client SECRET Exposed

la3eb OAuth client secret leak allows forging Sign-in-with-Google assertions.

CVSS 9.6
Saudi Gaming Marketplace
MENA
Credential Exposure Responsible Disclosure Critical 2026-03
Unauthenticated Invoice API Endpoints (request-void/cancel/mark-as-paid)

7 invoice manipulation endpoints accept requests without any auth token; any UUID enables cancel/refund/mark-paid actions.

CVSS 9.6
European Crypto Payment Gateway
EU
Access Control Responsible Disclosure Critical 2026-03
Zero-Price Primer Production Payment Tokens

Guest endpoint issues 0 EUR Primer production tokens with full card tokenization.

CVSS 9.6
Gaming Marketplace
EU
Business Logic Responsible Disclosure Critical 2026-03
Guest Order IDOR + Credential Theft Chain

byGuestAccessId endpoint skips auth returning 10 credential field types.

CVSS 9.6
Gaming Marketplace
EU
IDOR Responsible Disclosure Critical 2026-03
Private Channel Auth Bypass via OTP + HMAC

globalPrivateChannelKey returns rotating OTP; HMAC computed locally to sign channel auth.

CVSS 9.6
Indian Crypto Exchange
SEA
Auth Bypass Responsible Disclosure Critical 2026-03
CORS Wildcard + localStorage Bearer Token = Full Cross-Origin Account Takeover Chain

The [vendor] Vue.js SPA stores the user's authentication Bearer token in localStorage under the key accessToken. Combined with the CORS wildcard () on sls.[vendor] that allows Authorization header in cross-origin requests, and the DELETE method enabled on /user/account, this creates a full account takeover and destruction chain exploitable

CVSS 9.6
SEA Gaming Marketplace
SEA
CORS HackerOne Critical 2026-03
MinIO Images Bucket Anonymous WRITE (Supply Chain)

blix.gg MinIO images bucket allows anonymous object upload to 38,219 public assets (1.3GB).

CVSS 9.5
Gaming Marketplace
EU
Cloud Misconfig Responsible Disclosure Critical 2026-03
Twitter/X Brand Account Takeover (119K Followers)

la3eb.com OAuth 1.0a flow allows X account session takeover with 119K-follower brand handle.

CVSS 9.5
Saudi Gaming Marketplace
MENA
Access Control Responsible Disclosure Critical 2026-03
Complete Environment Config Dump (20+ API Keys)

Single JS bundle leaks 20+ service API keys including Checkout.com sandbox, Lokalise, Firebase anonymous.

CVSS 9.5
Saudi Gaming Marketplace
MENA
Credential Exposure Responsible Disclosure Critical 2026-03
Fonbnk Third-Party Callback Forgery (ATEN System)

Fonbnk callback accepts empty or arbitrary payloads with unvalidated signature enabling ATEN system abuse.

CVSS 9.4
African Fintech
Africa
Webhook Forgery Responsible Disclosure Critical 2026-03
Unauthenticated Transaction CSV Download via DownloadTransactions

DownloadTransactions gRPC method returns CSV transaction data without a token after progressive field disclosure.

CVSS 9.3
SEA Banking API Platform
SEA
BFLA Responsible Disclosure Critical 2026-03
Cloudflare WAF Complete Bypass via Wageon Origin IP

wageon.io white-label brand resolves to AWS origin bypassing CF.

CVSS 9.3
EU iGaming Operator
EU
Cloud Misconfig Responsible Disclosure Critical 2026-03
CORS Origin Reflection with Credentials on All 928 REST API Routes

Every REST route reflects arbitrary Origin with credentials enabling cross-origin session hijack across the storefront.

CVSS 9.3
Gaming Marketplace
NA
CORS Responsible Disclosure Critical 2026-03
Vite Dev Server Source Code Exposure on Integrator Dashboard

Integrator dashboard runs Vite dev server in production exposing full React source, routes and env config.

CVSS 9.3
African Fintech
Africa
Information Disclosure Responsible Disclosure Critical 2026-03
Unregistered Staging Domain Takeover (traderjoexyz.dev)

Staging API base URL points to an unregistered .dev domain; claiming it hijacks staging frontend traffic.

CVSS 9.3
DeFi DEX Protocol
Global
Subdomain Takeover Responsible Disclosure Critical 2026-03
Payment OTP Brute Force -- Zain/Simpaisa Zero Rate Limit

Payment OTP verification endpoints have no effective rate limiting. Zain allows 185 requests per IP without any block, Simpaisa allows 50+ requests. Combined with XFF bypass, the entire OTP keyspace can be brute-forced

CVSS 9.3
EU Gaming Key Marketplace
EU
Broken Authentication Responsible Disclosure Critical 2026-03
Security Finding

1. Hardcoded API Signature (auth.crud.js) - Internal IP: `[ip]` (Alibaba Cloud, staging/dev backend) - Hardcoded Signature: `X-TCDX-SIGNATURE: salamtothemoon` - used for admin authentication - Endpoint: `POST /admin/auth` with email/password

CVSS 9.3
SEA Fintech
SEA
Information Disclosure Responsible Disclosure Critical 2026-03
Round6 Deep Exploitation

1. Refund Chain: Public API creds ([redacted]) -> Token -> invoice_id enum -> Unauthorized refund execution 2. Account Takeover Chain: Email enum (login differential) -> Reset flood (no rate limit) -> Token brute-force -> IMT operator account takeover -> Cross-border payment data 3.

CVSS 9.3
Turkish Payment Gateway
MENA
Information Disclosure Responsible Disclosure Critical 2026-03
[redacted] SSRF Azure Infrastructure

SSRF Azure Infrastructure Deep Exploitation - [redacted].money Hedef: [redacted].money ([redacted] Money (Pty) Ltd) Zafiyet: SSRF via `validateApplePayMerchant` GraphQL Mutation Severity: CRITICAL (Infrastructure Mapping + Database Discovery + Key Vault Discovery)

CVSS 9.3
African Payment Gateway
Africa
SSRF Responsible Disclosure Critical 2026-03
Reverse Authentication Logic on Notification/EscrowPayout [CRITICAL]

Finding 1: Reverse Authentication Logic on Notification/EscrowPayout [CRITICAL] Endpoint: POST /api/Notification/EscrowPayout Notification/EscrowPayout endpoint'inde authentication logic'i TERS calisiyor. `ApiKey` header gonderilMEdiginde endpoint "Success!" donuyor. ApiKey heade

CVSS 9.3
African DeFi Protocol
Africa
Auth Bypass Responsible Disclosure Critical 2026-03
[redacted] Deep Dive V2

- Existing email: "Password reset link has been sent to your e-mail address." - Non-existing email: "Active user could not be found." No authentication is required. No rate limiting observed (beyond the global IP-based rate limit). reCAPTCHA is not enforced. | support@[redacted].com

CVSS 9.3
Gaming Marketplace
MENA
Broken Authentication Responsible Disclosure Critical 2026-03
African Fintech Mass Scan

African Crypto/Fintech Platform Mass Scan Results Scope: 20 African crypto/fintech platforms Method: Passive reconnaissance, subdomain enumeration, configuration exposure, API discovery 1. [target] / [target] -- MULTI-VECTOR COMPROMISE

CVSS 9.3
African Fintech Mass Scan
Africa
Information Disclosure Responsible Disclosure Critical 2026-03
Crypto Exchange Mass Scan

Crypto Exchange Mass Scan - 2026-03-22 20+ Platform Vulnerability Assessment VERIFIED FINDINGS (3 Platforms) 1. [redacted] -- VERIFIED CRITICAL (Vietnamese Crypto Exchange, ~1.39M users)

CVSS 9.3
Crypto Exchange Mass Scan
Global
Information Disclosure Responsible Disclosure Critical 2026-03
Firebase Realtime Database PUBLIC READ Access [CRITICAL]

Finding 1: Firebase Realtime Database PUBLIC READ Access [CRITICAL] - URL: `https://[target]/.json` - Impact: Full database readable without authentication (562KB) - 80 production bank configurations (codes, logos, names)

CVSS 9.3
Crypto Fintech Mass Scan
Global
Firebase Misconfig Responsible Disclosure Critical 2026-03
Local Network Mdns Upnp Discovery

mDNS/Bonjour ve UPnP Servis Kesfi Raporu Test Makinasi: [ip] (MacBook Pro, Mac16,8, macOS Darwin 25.2.0) Yetkilendirme: Authorized pentest [ip]/24 yerel aginda mDNS/Bonjour ve UPnP/SSDP protokolleri kullanilarak servis ve cihaz kesfesi yapildi. Toplamda 8 benz

CVSS 9.3
Local Network Scan
Global
Auth Bypass Responsible Disclosure Critical 2026-03
Subdomain Information Disclosure (LOW)

Finding 5: Subdomain Information Disclosure (LOW) Kesfedilen subdomain'ler ve durumlar: - `api.blix.gg` - 502 (backend down) - `api-dev.blix.gg` - timeout (DNS var, service yok)

CVSS 9.3
KYC Mass Scan
Global
Information Disclosure Responsible Disclosure Critical 2026-03
[redacted] Billing Findings Proven

[redacted] Code Billing/Auth Security Assessment — PROVEN FINDINGS [redacted] VDP — Authorized Security Research Hedef: [redacted] Code CLI v2.1.74, [redacted] API Kapsam: Billing bypass, auth bypass, client-side manipulation

CVSS 9.3
AI SaaS Provider
NA
Auth Bypass Responsible Disclosure Critical 2026-03
Disclosure'lar

- [UpdateAccountPermission Exploit](https://[target]/blog/[redacted]-wallet-exploit-updateaccountpermission) - [14,500 Wallets at Risk](https://[target]/news/[redacted]-addresses-risk-silent-hijacking) - [$500M Multisig Vulnerability](https://[target]/news/[redacted]-multis

CVSS 9.3
L1 Smart Contract
Global
RCE HackerOne Critical 2026-03
Mass Scanner Prompt V2

Mass Scanner Prompt v2 — COPY BELOW INTO NEW SESSION You are conducting authorized bug bounty security research on digital game/gift card marketplace platforms. You have ONE job: find LETHAL vulnerabilities and PROVE they exist with real HTTP responses. WHAT I CARE ABOUT (NOTHING

CVSS 9.3
Mass Scan
Global
Subdomain Takeover Responsible Disclosure Critical 2026-03
CRITICAL - Full Stack Trace Disclosure with GoCD CI/CD Path Exposure

Finding 2: CRITICAL - Full Stack Trace Disclosure with GoCD CI/CD Path Exposure Summary: IMT backend API'leri, kimlik dogrulama hatalarinda tam .NET stack trace ifsa etmektedir. Stack trace'ler GoCD CI/CD pipeline yollarini, kaynak kod dosya adlarini ve satir numaralarini icerir.

CVSS 9.3
Turkish Payment Gateway
MENA
Access Control Responsible Disclosure Critical 2026-03
[CRITICAL]: OIDC Discovery Exposes Internal Architecture + Admin Impersonation Grant Type

Finding 3 [CRITICAL]: OIDC Discovery Exposes Internal Architecture + Admin Impersonation Grant Type `secure.[redacted].money` ve `secure-staging.[redacted].money` OIDC discovery endpoint'leri production'da 26, staging'de 85 OAuth scope ifsa ediyor. Staging'de `admin-oidc-impersonation` g

CVSS 9.3
African Payment Gateway
Africa
Broken Authentication Responsible Disclosure Critical 2026-03
[redacted] Final Exploit

[redacted].com - FINAL Penetration Test Report Authorized Bug Bounty Security Assessment - 2026-03-16 Target: [redacted].com ([redacted] - Gift Card E-Commerce) Stack: WordPress 6.x + WooCommerce + PHP 7.4.33 (EOL) + Apache + cPanel (CloudLinux/StableServer)

CVSS 9.3
Gaming Marketplace
EU
Rate Limit Bypass Responsible Disclosure Critical 2026-03
[redacted] Security Assessment Report 2026

The following critical credentials are hardcoded in the JS bundle: Security Config File (Publicly Accessible) These values are used as custom headers in login requests: | JWT Secret | `YOUR_VERY_CONFIDENTIAL_SECRET_FOR_SIGNING_JWT_TOKENS!!!` | Mock auth (Fuse framework) |

CVSS 9.3
African Fintech
Africa
JWT Issues Responsible Disclosure Critical 2026-03
5x [redacted] Database Instances FULLY ACCESSIBLE [CRITICAL - MEGA]

Finding 0: 5x [redacted] Database Instances FULLY ACCESSIBLE [CRITICAL - MEGA] - Severity: CRITICAL (CVSS 9.8) - Impact: 5 separate [redacted] PostgreSQL databases for internal operations dashboards are publicly accessible with anon JWT keys hardcoded in publicly-hosted JS files. Com

CVSS 9.3
Crypto Fintech Mass Scan
Global
JWT Issues Responsible Disclosure Critical 2026-03
KYC Db Scan

KYC & Database Exposure Scan — 2026-03-17 Objective: Find HTTP 200 with ACTUAL real data (user records, KYC documents, DB contents) Result: NO verified data access found across 100+ platforms scanned Regions: Nigeria, Turkey, Southeast Asia, Latin America, Eastern Europe, Global

CVSS 9.3
KYC Mass Scan
Global
S3 Misconfig Responsible Disclosure Critical 2026-03
[redacted] Billing Research

[redacted] Billing/Usage Bypass Research Responsible Disclosure — [redacted] VDP Araştırmacı: Atilla (atilla0283@hackerone) Amaç: Billing/usage enforcement bypass zafiyetleri tespit etmek

CVSS 9.3
AI SaaS Provider
NA
Race Condition HackerOne Critical 2026-03
CRITICAL - 367-Endpoint API Specification Exposure (4x [redacted] UI Public)

Finding 1: CRITICAL - 367-Endpoint API Specification Exposure (4x [redacted] UI Public) Summary: [redacted]'in cross-border para transferi (IMT) altyapisi 4 adet [redacted] UI/JSON spec dosyasini kimlik dogrulama olmadan internete acik birakmistir. Toplam 367 API endpoint'i (240 Accounting

CVSS 9.3
Turkish Payment Gateway
MENA
Auth Bypass Responsible Disclosure Critical 2026-03
[CRITICAL]: CORS Origin Reflection + Credentials on GraphQL API

Finding 1 [CRITICAL]: CORS Origin Reflection + Credentials on GraphQL API Production (`api.[redacted].money`) ve staging (`api-staging.[redacted].money`) GraphQL API endpoint'leri, `Access-Control-Allow-Origin` header'ında gönderilen herhangi bir `Origin` değerini yansıtıyor ve `Access-C

CVSS 9.3
African Payment Gateway
Africa
Credential Exposure Responsible Disclosure Critical 2026-03
ThirdParty App Key Renewal Without Authentication [CRITICAL]

Finding 5: ThirdParty App Key Renewal Without Authentication [CRITICAL] Endpoint: POST /api/ThirdParty/App/RenewKeys ThirdParty App key renewal endpoint'i JWT auth gerektirmiyor. "User Not Found" hatasi donuyor (401 degil) - bu, auth katmaninin bypass edildigini ve business logic

CVSS 9.3
African DeFi Protocol
Africa
Information Disclosure Responsible Disclosure Critical 2026-03
[redacted] Rtsp Audit

[redacted] Kamera RTSP Guvenlik Denetimi Raporu Hedef: [ip] ([redacted] NVR/IP Kamera) Kapsam: Yetkili lokal ag pentest | Cihaz Turu | [redacted] NVR veya IP Kamera |

CVSS 9.3
CCTV Infrastructure
Global
Auth Bypass HackerOne Critical 2026-03
The Tolgee XLIFF import endpoint does not disable external entity processing:

The Tolgee XLIFF import endpoint does not disable external entity processing: After import + apply, the file content is stored as a translation value and readable via API. | File | Content | Criticality | |------|---------|-------------|

CVSS 9.3
Global Crypto Exchange
Global
RCE Responsible Disclosure Critical 2026-03
Unsigned validity Window Metadata in ERC-4337 Wallet Signature

validUntil/validAfter are appended to userOp.signature but never hashed, so any relayer can alter the validity window without invalidating the signer's ECDSA signature.

CVSS 9.1
Ethereum Attestation Protocol
Global
Broken Authentication Code4rena Critical 2026-03
Ownership Slot Mismatch Bricks Smart Wallet After Claim Transition

Wallet stores owner in both custom and OZ Ownable slots, and owner() switches source based on isClaimed, leaving the wallet ownerless after the two-step claim.

CVSS 9.1
Ethereum Attestation Protocol
Global
Access Control Code4rena Critical 2026-03
KYC Document Bucket Public Access Leaks User Identity Documents

Bucket lists and serves KYC front_image, liveness video and selfie images for registered users.

CVSS 9.1
African Crypto Exchange
Africa
S3 Misconfig Responsible Disclosure Critical 2026-03
8 Internal Services Publicly Accessible including Grafana and Admin

Eight internal services reachable publicly including analytics, admin portal and staging env.

CVSS 9.1
African Fintech Neobank
Africa
Admin Panel Exposure Responsible Disclosure Critical 2026-03
CORS Origin Reflection + credentials:true on 7 APIs (ATO Chain)

Busha 7 hosts reflect arbitrary origin with credentials, enabling cross-origin authenticated reads of 41 endpoints including PII.

CVSS 9.1
African Crypto Exchange
Africa
CORS Responsible Disclosure Critical 2026-03
DigitalOcean Spaces Production Credentials Hardcoded

Bitmama production JS bundle exposes DigitalOcean Spaces key and secret valid for account-level actions.

CVSS 9.1
African Crypto Exchange
Africa
Credential Exposure Responsible Disclosure Critical 2026-03
Staging DO Spaces Credentials + Admin Panel Source Code Exposed

Staging admin panel ships 26MB source map and embedded DO Spaces key.

CVSS 9.1
African Crypto Exchange
Africa
Credential Exposure Responsible Disclosure Critical 2026-03
Enterprise API Tokens Exposed in Public Postman Documentation

Public Postman collection hosts enterprise bearer tokens tied to live Heroku backends.

CVSS 9.1
African Crypto Exchange
Africa
Credential Exposure Responsible Disclosure Critical 2026-03
n8n Workflow Automation Platform Exposed

Self-hosted n8n v2.7.2 reachable publicly with API endpoints exposed.

CVSS 9.1
African Crypto Exchange
Africa
Admin Panel Exposure Responsible Disclosure Critical 2026-03
Unauthenticated Database Dump via Public test.php

globaladmin.bitbns.com/test.php returns raw DB dump without auth.

CVSS 9.1
Indian Crypto Exchange
SEA
Admin Panel Exposure Responsible Disclosure Critical 2026-03
Unauthenticated Database Dump via admin CRM test.php

admin.bitbns.com/bitbns/crm/test.php exposes DB dump unauthenticated.

CVSS 9.1
Indian Crypto Exchange
SEA
Admin Panel Exposure Responsible Disclosure Critical 2026-03
Two Freshdesk Subdomain Takeover Targets

Two Freshdesk-pointing subdomains show dangling CNAMEs allowing takeover.

CVSS 9.1
Indian Crypto Exchange
SEA
Subdomain Takeover Responsible Disclosure Critical 2026-03
Flutterwave SECRET Key + Encryption Key Exposed in Production JS

Changera/Payborda JS exposes Flutterwave secret and AES encryption key used for payments.

CVSS 9.1
African Fintech Remittance
Africa
API Key Exposure Responsible Disclosure Critical 2026-03
Roqqu Unsigned Cloudinary Upload to KYC Document Folder

Cloudinary preset allows unsigned uploads to KYC folder enabling attacker-uploaded proofs.

CVSS 9.1
African Crypto Exchange
Africa
Cloud Misconfig Responsible Disclosure Critical 2026-03
CORS Origin Reflection + Credentials Enables Full ATO

Cardtonic API reflects origin including null with credentials across all endpoints.

CVSS 9.1
African Fintech Remittance
Africa
CORS Responsible Disclosure Critical 2026-03
SignalR ChatHub Unauthenticated JWT Token Issuance

ChatHub issues 1-hour JWTs unauthenticated enabling session identity forging.

CVSS 9.1
Gaming Top-Up Platform
Global
JWT Issues Responsible Disclosure Critical 2026-03
CORS Origin Reflection + Credentials = Full ATO (Null Origin)

usenosh.com reflects origin including null enabling iframe-sandbox ATO chain.

CVSS 9.1
Nigerian Gift Card Marketplace
Africa
CORS Responsible Disclosure Critical 2026-03
Two AWS S3 Buckets Unauthenticated Object Access

gcbuying buckets deny listing but permit direct-object read enabling object enumeration via key guessing.

CVSS 9.1
Nigerian Gift Card Marketplace
Africa
S3 Misconfig Responsible Disclosure Critical 2026-03
CORS Wildcard on buffbuff Gaming Gateway

api.buffbuff.top ACAO * + credentials enables zero-click ATO.

CVSS 9.1
Gaming Marketplace
Global
CORS Responsible Disclosure Critical 2026-03
Spring Boot Admin Panel Publicly Reachable

kefu89757 admin panel accepts brute-force logins over Akamai without WAF rules.

CVSS 9.1
Asian Gift-Card Marketplace
SEA
Admin Panel Exposure Responsible Disclosure Critical 2026-03
Multiple Payment Processors Hardcoded

PayPal, Airwallex, Antom, PayerMax, Asiabill credentials in JS bundles.

CVSS 9.1
Asian Gift-Card Marketplace
SEA
Credential Exposure Responsible Disclosure Critical 2026-03
Production API Key + Client ID Leaked in Merchant Panel JS

REACT_APP_API_KEY + CLIENT_ID bundled in merchant panel allowing unauth access to production services.

CVSS 9.1
Central African Crypto Fintech
Africa
Credential Exposure Responsible Disclosure Critical 2026-03
Cloudflare WAF Complete Bypass via Origin IP

Origin IP 188.245.49.12 reachable bypassing CF WAF allowing unrestricted backend access.

CVSS 9.1
EU Gaming Marketplace
EU
Cloud Misconfig Responsible Disclosure Critical 2026-03
Passbolt Full Config + GPG Key Exfiltration via SSRF

Passbolt CE 5.9.0 self-registration + admin GPG key + email exfiltrated via SSRF.

CVSS 9.1
EU Gaming Marketplace
EU
Credential Exposure Responsible Disclosure Critical 2026-03
SumSub KYC Webhook Forgery - No HMAC Validation

KYC webhook accepts forged POSTs without X-Payload-Digest enabling AML bypass for any account.

CVSS 9.1
EU iGaming Operator
EU
KYC Bypass Responsible Disclosure Critical 2026-03
Unauthenticated Refund Claim via UUID

Full PII exposure + wallet hijack via refund-claim endpoint; 3.6M UUID/hr brute force with no rate limit.

CVSS 9.1
European Crypto Payment Gateway
EU
Business Logic Responsible Disclosure Critical 2026-03
Shopware6 Plugin Webhook No Token Validation

Callback handler has no token/HMAC validation; CSRF explicitly disabled. Attacker can forge order status updates without any auth.

CVSS 9.1
European Crypto Payment Processor
EU
Webhook Forgery Responsible Disclosure Critical 2026-03
CSRF Protection Bypass via Hardcoded Fallback Token

Angular fallback XSRF token hardcoded; full CSRF bypass enabling guest-token chain.

CVSS 9.1
Gaming Marketplace
EU
Access Control Responsible Disclosure Critical 2026-03
Django DEBUG=True on stream subdomain

stream.flitpay.com exposes 175 production settings including DB hostname/username.

CVSS 9.1
Indian Crypto Exchange
SEA
Information Disclosure Responsible Disclosure Critical 2026-03
21.6 GB Public debug.log Exposes Payment Credentials and Server Paths

Publicly accessible debug.log of 21.6 GB leaks payment gateway credentials, server file paths and broken S2S webhook details.

CVSS 9.1
Gaming Marketplace
NA
Information Disclosure Responsible Disclosure Critical 2026-03
RSA Private Key Exposed in HTML Source

Production HTML embeds an RSA private key usable to decrypt or forge server-side operations.

CVSS 9.1
Gaming Marketplace
SEA
Credential Exposure Responsible Disclosure Critical 2026-03
Google OAuth Client Secret Exposed in HTML

Google OAuth client secret hard-coded in HTML permits SSO flow takeover or spoofed server exchange.

CVSS 9.1
Gaming Marketplace
SEA
Credential Exposure Responsible Disclosure Critical 2026-03
Seven Unauthenticated Payment Webhook Endpoints (PayPal/Stripe/Coinbase/Skrill/Payssion)

Multiple payment webhooks lack signature validation enabling forged deposit notifications for seven different payment rails.

CVSS 9.1
Gaming Marketplace
SEA
Webhook Forgery Responsible Disclosure Critical 2026-03
Laravel Horizon Dashboard Unauthenticated Read + Write

Laravel Horizon reachable without auth permitting queue inspection and job manipulation.

CVSS 9.1
Gaming Marketplace
EU
Admin Panel Exposure Responsible Disclosure Critical 2026-03
Mass Customer IDOR Exposes 60,623+ Users PII

Customer endpoint enumerable by sequential ID discloses 60K+ user PII including KYC and wallet data.

CVSS 9.1
African Crypto Exchange
Africa
IDOR Responsible Disclosure Critical 2026-03
CORS Origin Reflection on Production API Enables ATO

Production API reflects any Origin header with credentials allowing cross-origin account takeover chain.

CVSS 9.1
African Fintech
Africa
CORS Responsible Disclosure Critical 2026-03
Payment Provider Toggle Enables Remote DoS

Provider enable/disable admin endpoint reachable without admin check allowing attacker to disable all 11 payment providers causing platform-wide DoS.

CVSS 9.1
African Fintech
Africa
Business Logic Responsible Disclosure Critical 2026-03
Tanda Webhook BullMQ/Redis Infrastructure Leak via Content-Type

Manipulating Content-Type on Tanda webhook leaks internal BullMQ/Redis error details exposing infrastructure.

CVSS 9.1
African Fintech
Africa
Information Disclosure Responsible Disclosure Critical 2026-03
17.1MB Source Map Exposes Complete Admin Dashboard Source

Admin dashboard ships a 17MB source map revealing 180 internal admin endpoints and business flows.

CVSS 9.1
African Payment Gateway
Africa
Information Disclosure Responsible Disclosure Critical 2026-03
CORS Origin Reflection with Credentials (Account Takeover)

P2P trading API reflects arbitrary Origin with credentials enabling ATO of users visiting attacker site.

CVSS 9.1
African P2P Crypto Platform
Africa
CORS Responsible Disclosure Critical 2026-03
Unauthenticated Mass Customer PII Exposure via GraphQL

GraphQL endpoint returns enumerable customer PII including addresses and loyalty data without authentication.

CVSS 9.1
MENA Travel Fintech
MENA
GraphQL Issues Responsible Disclosure Critical 2026-03
Direct HLS Stream Access Without Authentication

Premium content HLS master and segment URLs directly accessible without auth bypassing paid subscription.

CVSS 9.1
CIS Streaming Platform
MENA
Access Control Responsible Disclosure Critical 2026-03
Phone Verification Set to Mock Mode in Production

Production phone verification service configured to mock mode allowing any code to pass during registration.

CVSS 9.1
LATAM Crypto Exchange
LATAM
Broken Authentication Responsible Disclosure Critical 2026-03
Auth0 Open Registration Enables Unlimited Account Creation

Auth0 tenant allows public signups with email enumeration and arbitrary password reset.

CVSS 9.1
LATAM Crypto Exchange
LATAM
Broken Authentication Responsible Disclosure Critical 2026-03
Monad RPC Debug Namespace Enabled Without API Key

Monad RPC exposes debug_traceCall/debug_traceBlockByNumber without authentication enabling MEV sandwich attacks and pre-image extraction on DEX swaps.

CVSS 9.1
DeFi DEX Protocol
Global
Oracle Manipulation Responsible Disclosure Critical 2026-03
API Authorization Keys Hardcoded in JavaScript

Frontend bundle embeds API authorization keys usable against admin endpoints.

CVSS 9.1
African DeFi Platform
Africa
Credential Exposure Responsible Disclosure Critical 2026-03
CRITICAL - Supabase Admin Password Exposed via Unauthenticated Database Access (bybit.[vendor])

Vulnerable Endpoint: https://kntlvmafkdfzneiugdck.supabase.co/rest/v1/admin_settings

CVSS 9.1
African Payment Processor
Africa
Cloud Misconfig Responsible Disclosure Critical 2026-03
CRITICAL - CORS Wildcard with Credentials on Production API

Vulnerable Endpoints: - https://api.[vendor] (Production API) - https://business-banking.[vendor] (Business Banking API)

CVSS 9.1
African Payment Processor
Africa
CORS Responsible Disclosure Critical 2026-03
Email Verification Token Brute Force - Account Takeover

POST /api/auth/verify-email endpointi 6 karakterlik verification token kabul eder. Bu endpoint'te HICBIR rate limiting uygulanmamis. Saldirgan, herhangi bir kullanicinin email verification token'ini brute force ederek hesabini verify edebilir ve bu fintech platformunda islem yapabilir

CVSS 9.1
African Remittance Platform
Africa
Broken Authentication Responsible Disclosure Critical 2026-03
CORS Wildcard + Credentials on currency-api.[vendor]

currency-api.[vendor] endpointi Access-Control-Allow-Origin: ile birlikte Access-Control-Allow-Credentials: true set ediyor. Bu, tarayici tarafindan her zaman uygulanmasa da (spec'e gore bu kombinasyon engellenmelidir), bazi eski tarayicilar veya yanlis yapilandirilmis proxy'ler bunu izin verebilir. Daha onemlisi, bu yapilandirma guvenlik bi

CVSS 9.1
African Remittance Platform
Africa
CORS Responsible Disclosure Critical 2026-03
CORS Wildcard on Financial/Checkout Endpoints Enables Cross-Origin Purchase and Balance Theft

Beyond the user profile endpoints (Finding 13), the SLS API also exposes financial and checkout endpoints with CORS wildcard (), including checkout/buyNow/buy, store-credit/get-balance, userBar/getCustomerScWor (store credit/wallet), and site/getAIChatSessionToken. Combined with the localStorage token storage (Finding 17), an attacker with a sto

CVSS 9.1
SEA Gaming Marketplace
SEA
CORS HackerOne Critical 2026-03
Sentry DSN Exposure + Event Injection (Stored XSS via Error Events)

The self-hosted Sentry instance at apm.[vendor] leaks its DSN (Data Source Name) key in the login page's __initialData JavaScript object. This DSN allows any unauthenticated attacker to inject arbitrary error events, including crafted XSS payloads, into the Sentry dashboard. When an administrator views these injected events, the XSS

CVSS 9.1
NA Gift Card Supplier
NA
XSS Responsible Disclosure Critical 2026-03
Laravel Horizon Dashboard -- Unauthenticated Full Access

Endpoint: https://sandbox.[vendor]/horizon

CVSS 9.1
EU Digital Goods Marketplace
EU
Admin Panel Exposure Responsible Disclosure Critical 2026-03
Queue Manipulation via CSRF Token Extraction (Job Retry + Batch Retry)

POST endpoints on Horizon require CSRF token, but the token is freely obtainable from the Horizon page itself (which is unauthenticated). By first fetching the page to get session cookies + XSRF-TOKEN, then including the decoded XSRF-TOKEN in the X-XSRF-TOKEN header, all POST operations succeed. This enables

CVSS 9.1
EU Digital Goods Marketplace
EU
Admin Panel Exposure Responsible Disclosure Critical 2026-03
Predictive Audience API Exposed - Unauthenticated IDOR + Swagger + Pipeline Execution

[vendor]' Predictive Audience API is deployed on Azure App Service (pa-api-prod.azurewebsites.net) completely outside of Cloudflare WAF protection. The API has NO authentication whatsoever, exposes full Swagger/OpenAPI documentation, allows unauthenticated IDOR across all client IDs (user segmentation data, churn predictions, LTV data), an

CVSS 9.1
Gaming Marketplace
NA
IDOR Responsible Disclosure Critical 2026-03
Strapi API Token Leaked in Client-Side JavaScript

Vulnerable Endpoint: https://[vendor] (HTML source, __NUXT__ config)

CVSS 9.1
EU Gaming Marketplace
EU
Credential Exposure Responsible Disclosure Critical 2026-03
K-1: [redacted] Setup-Token Exposed (CRITICAL)

Finding K-1: [redacted] Setup-Token Exposed (CRITICAL) Endpoint: `https://[redacted] com/api/session/properties` Additionally accessible on direct IP (bypassing any WAF):

CVSS 9.1
African Neobank
Africa
Admin Panel Exposure Responsible Disclosure Critical 2026-03
B — LSLB API Unauthenticated Business Data Exposure (78 Production Records)

Finding 0B — LSLB API Unauthenticated Business Data Exposure (78 Production Records) CVSS: 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N) The LSLB (Lagos State Lotteries Board) permit management API at `api-prod.lslb.[redacted].co` returns 78 production business records (Niger

CVSS 9.1
African KYC Provider
Africa
IDOR Responsible Disclosure Critical 2026-03
Sea Mena Turkey Scan

SEA / MENA / Turkey Crypto-Fintech-Betting Platform Scan Scope: Southeast Asia, Middle East, Turkey — crypto exchanges, fintech, betting platforms Method: Automated reconnaissance (subdomain enum, .env, [redacted], Actuator, GraphQL, CORS, source maps, S3, [redacted], KYC dirs) | | Plat

CVSS 9.1
SEA/MENA Mass Scan
MENA
Information Disclosure Responsible Disclosure Critical 2026-03
512-bit RSA Key for Login Encryption ([redacted]ially Factorable)

Finding 2: 512-bit RSA Key for Login Encryption ([redacted]ially Factorable) CVSS Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Login islemi icin kullanilan RSA anahtari sadece 512-bit uzunlugunda. 512-bit RSA 1999 yilinda faktorize edildi (RSA-155). Modern donanim ile dakikalar icinde k

CVSS 9.1
CCTV Infrastructure
Global
Information Disclosure Responsible Disclosure Critical 2026-03
Unauthenticated Mass User Data Leak via Chat Messages Endpoint

Finding 7: Unauthenticated Mass User Data Leak via Chat Messages Endpoint Severity: Critical (CVSS 9.1 - AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) The `/api/messages/` endpoint returns 1,000 chat messages from 492 unique users without ANY authentication. Each message includes the user

CVSS 9.1
NA Online Casino
NA
Broken Authentication Responsible Disclosure Critical 2026-03
Crypto Exchange Scan

Crypto Exchange Security Scan - 2026-03-23 Authorized Penetration Testing Report Targets: 10 cryptocurrency exchanges with public bug bounty/responsible disclosure programs Method: Subdomain enumeration (crt.sh), API/endpoint discovery, source map analysis, credential extraction,

CVSS 9.1
Crypto Exchange Scan
Global
Information Disclosure Responsible Disclosure Critical 2026-03
Final Deep Results

[redacted].store Final Deep Dive -- All Findings Target: [redacted].store / [target] Bu final deep dive fazinda onceki tapdiqlar uzerine 7 yeni kritik ve yuksek severity bulgu ortaya cixarildi. Toplam etkile 1.44M istifadeci, 197K fatura kaydi, 69K email adresi, 851K degerlendirme ve

CVSS 9.1
SEA Crypto Exchange
SEA
CORS Responsible Disclosure Critical 2026-03
Full [redacted] API Documentation Publicly Exposed (CRITICAL)

Finding 3: Full [redacted] API Documentation Publicly Exposed (CRITICAL) Endpoint: `https://api.[redacted].az/[redacted]/index.html` The complete [redacted]/OpenAPI documentation for the OneXTwo CRM API is publicly accessible, exposing all 135 API endpoints with full request/response schema

CVSS 9.1
EU iGaming Operator
EU
Information Disclosure Responsible Disclosure Critical 2026-03
C — PEP/AML Service OpenAPI Spec & Endpoint Disclosure (Production)

Finding 0C — PEP/AML Service OpenAPI Spec & Endpoint Disclosure (Production) CVSS: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) `pep-dom.svc.[redacted].co` (Domestic PEP Service) exposes its complete OpenAPI specification publicly, revealing 6+ PEP screening, conviction chec

CVSS 9.1
African KYC Provider
Africa
Information Disclosure Responsible Disclosure Critical 2026-03
Login Rate Limit Bypass via X-Forwarded-For Header Spoofing

Finding 1: Login Rate Limit Bypass via X-Forwarded-For Header Spoofing Severity: CRITICAL (CVSS 9.1 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) Summary: Django backend'i rate limiting icin client IP adresini `X-Forwarded-For` header'indan aliyor. Cloudflare arkasinda oldugu i

CVSS 9.1
NA Online Casino
NA
Rate Limit Bypass Responsible Disclosure Critical 2026-03
Wildcard CORS Policy on Financial API

Finding 5: Wildcard CORS Policy on Financial API The production API at `api.[redacted].ng` returns `Access-Control-Allow-Origin: ` on all endpoints, including admin and financial transaction APIs. The application uses Bearer token authentication stored in `localStorage`, which is

CVSS 9.1
Nigerian Payment Provider
Africa
XSS Responsible Disclosure Critical 2026-03
— Unauthenticated ML Anomaly Detection Engine + [redacted] UI on Production

Finding 0 — Unauthenticated ML Anomaly Detection Engine + [redacted] UI on Production CVSS: 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) The KYC/AML risk scoring service (FastAPI/Python) exposes [redacted] UI and full OpenAPI specification on BOTH development AND production. On t

CVSS 9.1
African KYC Provider
Africa
Information Disclosure Responsible Disclosure Critical 2026-03
CORS Misconfiguration — Arbitrary Origin Reflection with Credentials (CRITICAL)

Finding 1: CORS Misconfiguration — Arbitrary Origin Reflection with Credentials (CRITICAL) `api.[redacted].com` reflects ANY `Origin` header value in `Access-Control-Allow-Origin` with `Access-Control-Allow-Credentials: true`. This allows any malicious website to make authenticated

CVSS 9.1
Gaming Marketplace
EU
CORS Responsible Disclosure Critical 2026-03
Deep Exploitation

[redacted].[target] - Deep Penetration Test Report Target: [redacted].[target] (International Money Transfer Platform) Type: Authorized Penetration Testing Engagement [redacted]'in International Money Transfer (IMT) altyapisinda 10 guvenlik bulgusu tespit edildi: 1 Critical, 3 High, 4 Medium, 2 Low

CVSS 9.1
Turkish Payment Gateway
MENA
CORS Responsible Disclosure Critical 2026-03
[redacted] OAuth OIDC Exploitation

`testClientCreateDirectDeposit` mutation'i, normalde test ortami icin tasarlanmis olmasina ragmen, PRODUCTION GraphQL API'sinde aktif ve herhangi bir ek yetki kontrolu olmadan calistirilabiyor. Mutation basarili response dondurdu (`TestClientCreateDirectDepositPayload`). Ek test

CVSS 9.1
African Payment Gateway
Africa
Webhook Forgery Responsible Disclosure Critical 2026-03
Google OAuth hosted_domain Bypass Potential

OAuth client lacks server-side hosted_domain check, attacker can craft token with arbitrary hd claim.

CVSS 9.0
SEA Banking API Platform
SEA
Broken Authentication Responsible Disclosure Critical 2026-03
CRM 17+ Unauthenticated Financial Admin Actions

CRM exposes 17+ admin actions (wallet credit, KYC approve) without authentication.

CVSS 9.0
Indian Crypto Exchange
SEA
BFLA Responsible Disclosure Critical 2026-03
Roqqu AES-256-CTR Encryption Key Exposed Full API Traffic Decryption

Static AES-256-CTR key found in JS bundle decrypts all encrypted API traffic.

CVSS 9.0
African Crypto Exchange
Africa
Credential Exposure Responsible Disclosure Critical 2026-03
IDOR on User-Specific Endpoints (No Ownership Check)

Several user endpoints accept arbitrary userId enabling cross-tenant reads.

CVSS 9.0
African Fintech Remittance
Africa
IDOR Responsible Disclosure Critical 2026-03
Client-Side Password Hashing With Exposed Salt + PBKDF2 1000

CoinCola hashes passwords client-side with exposed salt and weak 1000-iteration PBKDF2 enabling rapid cracking.

CVSS 9.0
Global P2P Crypto Marketplace
Global
Broken Authentication Responsible Disclosure Critical 2026-03
JWT Session Secret Leaked Enables Token Forge

nosh.ng JWT secret discovered in public artifact allowing arbitrary user session forging.

CVSS 9.0
Nigerian Gift Card Marketplace
Africa
JWT Issues Responsible Disclosure Critical 2026-03
SSRF to Internal GKE Services

Finding 4: SSRF to Internal GKE Services HashiCorp Vault — Unsealed, Full Info Disclosure Vault `/v1/sys/internal/ui/mounts`: | Service | Port | Protocol | Status |

CVSS 9.0
Global Crypto Exchange
Global
SSRF Responsible Disclosure Critical 2026-03
Password Hash Exposure on Registration

Registration response echoes server bcrypt password hash which attacker can crack offline.

CVSS 8.7
African Crypto Exchange
Africa
Credential Exposure Responsible Disclosure Critical 2026-03
180 Admin API Endpoints Exposed via Source Map

Reconstructed source reveals complete admin API surface including merchant, settlement and payout operations.

CVSS 8.7
African Payment Gateway
Africa
Information Disclosure Responsible Disclosure Critical 2026-03
Akamai mPulse + Origin IP Bypass

Origin IP 43.199.67.100 reachable bypassing Cloudflare/Akamai protection.

CVSS 8.6
Asian Gift-Card Marketplace
SEA
Cloud Misconfig Responsible Disclosure Critical 2026-03
Admin GraphQL updateTransaction / createManualBatch Schema Exposure

Admin GraphQL endpoint introspection reveals 18 admin types and financial mutation signatures.

CVSS 8.6
European Crypto Payment Gateway
EU
GraphQL Issues Responsible Disclosure Critical 2026-03
RBAC Structure Full Exposure (11 Roles)

RBAC role/permission endpoint unauthenticated reveals complete privilege taxonomy across 11 admin roles.

CVSS 8.6
African Crypto Exchange
Africa
Information Disclosure Responsible Disclosure Critical 2026-03
Full Source Code Exposure via Source Maps (Admin + Customer)

Customer and admin bundles expose .map files revealing complete TypeScript source of 126 files across services.

CVSS 8.6
African Crypto Exchange
Africa
Information Disclosure Responsible Disclosure Critical 2026-03
Full Admin Source Code Exposure via Source Maps

Production admin ships source maps revealing complete admin business logic.

CVSS 8.6
African DeFi Platform
Africa
Information Disclosure Responsible Disclosure Critical 2026-03
Grafana /metrics Exposes Complete Infrastructure Telemetry

4735-line Prometheus dump reveals datasources, dashboards and admin identities.

CVSS 8.5
African Fintech Neobank
Africa
Information Disclosure Responsible Disclosure Critical 2026-03
Payborda Dashboard Source Maps Expose 1492 Files

1492 source files (165 app files, 6.8MB) exposed via source maps including encryption logic.

CVSS 8.5
African Fintech Remittance
Africa
Information Disclosure Responsible Disclosure Critical 2026-03
ASP.NET Dev API Stack Trace + Source Code Path Disclosure

gamejus.com dev API leaks MSSQL column names and H:\Projects\ paths via stack trace.

CVSS 8.5
Gaming Top-Up Platform
Global
Information Disclosure Responsible Disclosure Critical 2026-03
Admin JS Leaks 120+ API Endpoints Including KYC and Bybit Auto-Sell

gcbuying admin JS enumerates 120+ admin routes including KYC mgmt and Bybit integration.

CVSS 8.5
Nigerian Gift Card Marketplace
Africa
Information Disclosure Responsible Disclosure Critical 2026-03
WebAuthn Passkey Credential ID Mass Leakage

Passkey credential IDs returned enumerably enabling fingerprinting and replay scenarios across 2FA system.

CVSS 8.1
African Crypto Exchange
Africa
Information Disclosure Responsible Disclosure Critical 2026-03
withdrawOtp Stored Plaintext Leaked via admin/viewDetail

Withdrawal OTP stored unhashed and returned by admin/viewDetail enabling withdrawal replay.

CVSS 9.8
SEA P2P Crypto Exchange
SEA
Credential Exposure Responsible Disclosure High 2026-04
admin/viewDetail Accepts Leaked twoFAToken as Auth

admin/viewDetail authenticates on twoFAToken alone which is recoverable via NoSQL injection, exposing admin profile.

CVSS 9.8
SEA P2P Crypto Exchange
SEA
Auth Bypass Responsible Disclosure High 2026-04
Full Stack Trace Disclosure in Production Crypto API

Invalid apiKey triggers full stack trace leaking framework versions, internal file paths and DB model names.

CVSS 9.8
SEA P2P Crypto Exchange
SEA
Information Disclosure Responsible Disclosure High 2026-04
TOTP OTP Verify Endpoint Brute Force With Minimal Rate Limiting

Verify endpoint permits ~5 tries before soft lockout; chained with OTP generate enables realistic OTP guessing.

CVSS 9.3
Indian Investment Broker
SEA
Rate Limit Bypass Responsible Disclosure High 2026-04
TOTP 2FA Secret Exposed in Plaintext via Profile API

Authenticated user can retrieve their TOTP secret seed in plaintext, allowing attackers with session hijack to clone 2FA indefinitely.

CVSS 9.1
European Payment Gateway
EU
Credential Exposure Responsible Disclosure High 2026-04
Keycloak Admin Console Publicly Accessible

Keycloak admin UI reachable without IP restriction and with insecure grant types enabled.

CVSS 8.8
SEA Investment Platform
SEA
Admin Panel Exposure Responsible Disclosure High 2026-04
API CORS Wildcard + Mass Assignment on Registration [CRITICAL]

Vulnerable Endpoint: POST https://app.[vendor]/api/register

CVSS 8.8
Crypto Exchange Platform
Global
Mass Assignment HackerOne High 2026-04
Deep Scan Findings

The endpoint accepts a JSON body with `email` and `phone` fields, and returns a signed JWT token containing those exact values. No validation is performed: - Any email/phone combination accepted - Token expiry is approximately 24 hours 3. Generate token for arbitrary user:

CVSS 8.8
MENA Crypto Exchange
MENA
JWT Issues Responsible Disclosure High 2026-04
Client Bank Account Details Manipulation via Unprotected Update API

Authenticated user can modify arbitrary client bank details through an unrestricted endpoint, redirecting payouts to attacker accounts.

CVSS 8.6
European Payment Gateway
EU
BFLA Responsible Disclosure High 2026-04
Unauthenticated Payment Event Injection via Partner Callback

Partner callback endpoint has no signature check so attackers can inject arbitrary payment events for any merchant.

CVSS 8.6
European Payment Gateway
EU
Webhook Forgery Responsible Disclosure High 2026-04
Signed PPM Investor Contracts Public in startups-bucket

S3 bucket exposes signed Private Placement Memorandum contracts with investor signatures.

CVSS 8.6
Series B African Fintech
Africa
S3 Misconfig Responsible Disclosure High 2026-04
Vite Dev Server in Production Source Disclosure

takephlight subdomain runs vite dev server exposing /@vite/client, /@fs/ paths.

CVSS 8.6
Series B African Fintech
Africa
Information Disclosure Responsible Disclosure High 2026-04
Real-Time KYC Data Leakage via Kafka

Kafka topics stream real-time KYC submissions unencrypted to anonymous Kafka UI readers.

CVSS 8.6
African Fintech Marketplace
Africa
KYC Bypass Responsible Disclosure High 2026-04
Swagger UI / Full API Specification Public on 3 Subdomains [CRITICAL]

Vulnerable Endpoints: - https://xchangeapi.[vendor]/api - https://instbtc.[vendor]/api - https://awstron.[vendor]/api

CVSS 8.6
Crypto Exchange Platform
Global
Business Logic Responsible Disclosure High 2026-04
SumSub Webhook Without Signature Verification

Vulnerable Endpoint: https://test.[vendor]/kyc/sumsub_webhook/

CVSS 8.6
EU Crypto Exchange
EU
KYC Bypass HackerOne High 2026-04
Expo OTA Staging Channel Publicly Accessible

The Expo EAS Update staging channel is publicly accessible, exposing the development/test server configuration and allowing download of staging JavaScript bundles

CVSS 8.6
EU Crypto Exchange
EU
Business Logic Responsible Disclosure High 2026-04
CRITICAL - Supabase HawkVibes HR Platform with 48 Tables (Employee Performance, Salary, Compensation)

A second Supabase instance at hawkvibes.[vendor] exposes 48 database tables including compensations, salary_ranges, salary_ranges_private, employee_feedback, performance_commentaries, employee_scores, penalties, and audit_logs. While currently empty (possibly new deployment), the schema is fully accessible via anon key with CORS wildcard

CVSS 8.6
European B2B Spend Management
EU
Cloud Misconfig Responsible Disclosure High 2026-04
VIP Wallet Access Control Bypass

CVSS 8.6
Crypto Payment Processor
Global
Access Control Responsible Disclosure High 2026-04
VIP Wallet Access Control Bypass (Non-VIP->VIP)

Total: 12 Critical + 6 High + 3 Medium = 21 unique findings

CVSS 8.6
Crypto Payment Processor
Global
Access Control Responsible Disclosure High 2026-04
Live Payment Webhook Hijack to Attacker-Controlled URL

Authenticated user can overwrite live webhook URL for all events, redirecting all merchant notifications to attacker-controlled endpoint.

CVSS 8.5
European Payment Gateway
EU
Webhook Forgery Responsible Disclosure High 2026-04
Admin Panel Zero Server-Side Authentication

Admin pages rely exclusively on client-side redirects allowing direct URL access.

CVSS 8.5
African Crypto Gift Card Platform
Africa
Auth Bypass Responsible Disclosure High 2026-04
Druid SQL Monitor Public on 13 Endpoints Across 3 Domains

Alibaba Druid SQL monitoring UI exposed publicly on 13 endpoints.

CVSS 8.5
Gaming Marketplace
SEA
Admin Panel Exposure Responsible Disclosure High 2026-04
ArgoCD Production Unauthenticated Settings Exposure

Production ArgoCD v3.0.11 exposes settings including execEnabled:true and Lua health checks.

CVSS 8.5
African Neobank
Africa
Admin Panel Exposure Responsible Disclosure High 2026-04
CORS Wildcard With Credentials on Production Financial APIs

All production financial APIs return ACAO: * enabling cross-origin credentialed requests and account takeover chains.

CVSS 8.1
European Payment Gateway
EU
CORS Responsible Disclosure High 2026-04
CORS Origin Reflection With Credentials on Payment API

API reflects arbitrary Origin with Allow-Credentials: true, allowing full cross-origin session theft.

CVSS 8.1
European Payment Gateway
EU
CORS Responsible Disclosure High 2026-04
2FA Bypass Grants Full Dashboard Without Verification Step

After password login the user reaches the merchant dashboard without completing the 2FA challenge, bypassing the second factor.

CVSS 8.1
European Payment Gateway
EU
Auth Bypass Responsible Disclosure High 2026-04
Business Logic Flaw: Cancelled Purchase Re-Marked as Paid

Cancelled purchase can be re-transitioned to paid via mark_as_paid without validation, causing goods release without payment.

CVSS 8.1
European Payment Gateway
EU
Business Logic Responsible Disclosure High 2026-04
CORS Wildcard With Permissive Headers on API

All origins accepted with credentials and Authorization reflected, enabling credentialed cross-origin attacks.

CVSS 8.1
SEA P2P Crypto Exchange
SEA
CORS Responsible Disclosure High 2026-04
Fixed Bcrypt Salt Makes Identical Passwords Hash Identically

Static salt reuse across users allows rainbow-table style precomputation and common-password cracking.

CVSS 8.1
SEA P2P Crypto Exchange
SEA
Broken Authentication Responsible Disclosure High 2026-04
Pre-Auth Bypass on Accounts and Order Submit APIs

Order submit and accounts endpoints accept requests without valid JWT enabling trade parameter discovery.

CVSS 8.1
Indian Crypto Exchange
SEA
Auth Bypass Responsible Disclosure High 2026-04
CORS Wildcard + Credentials True on Four API Services

Four API subdomains return ACAO * and Allow-Credentials true, bypassing same-origin policy.

CVSS 8.1
MENA Crypto Exchange
MENA
CORS Responsible Disclosure High 2026-04
lenda-app - Firestore Open with User Data

lenda-app Firestore readable unauth exposing lending user records.

CVSS 8.1
African Fintech Firebase Cohort
Africa
Firebase Misconfig Responsible Disclosure High 2026-04
Dispute Approval Admin API Without Auth

POST /trade/disputes/approve/{id} on admin-api reachable with weak/bypassable auth.

CVSS 8.1
African P2P Crypto Settlement
Africa
Access Control Responsible Disclosure High 2026-04
Rate Manipulation via PATCH /rate

Admin PATCH /rate accessible via predictable token enabling rate manipulation.

CVSS 8.1
African P2P Crypto Settlement
Africa
Business Logic Responsible Disclosure High 2026-04
2FA Token Brute Force No Rate Limiting

2FA endpoint accepts unlimited attempts enabling brute force.

CVSS 8.1
African Payment Platform
Africa
Rate Limit Bypass Responsible Disclosure High 2026-04
Mass KYC File Metadata Exposure (342+ Files)

/files endpoint returns all platform KYC documents metadata with pagination.

CVSS 8.1
West African Crypto Exchange
Africa
Information Disclosure Responsible Disclosure High 2026-04
Unrestricted Registration + OTP Brute Force Chain

Zero rate limit on DO direct origin OTP endpoint enables mass account creation/takeover.

CVSS 8.1
West African Crypto Exchange
Africa
Rate Limit Bypass Responsible Disclosure High 2026-04
Cloudflare Turnstile Server-Side Validation Missing

Auth endpoints accept any or missing Turnstile token because server-side validation is absent.

CVSS 8.1
European iGaming Platform
EU
Broken Authentication Private Engagement High 2026-04
No Rate Limiting on PIN Verification and Login

PIN and login endpoints accept unlimited attempts allowing brute force for account compromise.

CVSS 8.1
EU EdTech Platform
EU
Rate Limit Bypass Responsible Disclosure High 2026-04
[vendor] - P2P Partner, Race Condition, Financial Endpoint Security Test Report

Tarih: 2026-03-23 Hedef: [vendor] (Vietnam merkezli kripto borsasi) User ID: 1925403 (eagle8265934 / resadsabir5@gmail.com) Yetkilendirme: Authorized Bug Bounty Stack: Next.js + Node.js/Express + MongoDB + Socket.IO + Cloudflare

CVSS 8.1
SEA Crypto Exchange
SEA
Race Condition Responsible Disclosure High 2026-04
CORS Misconfiguration - Access-Control-Allow-Origin: with Sensitive Data

The API returns Access-Control-Allow-Origin: on ALL responses, including those containing PII bank data. Combined with the IDOR (Finding 1), this means any website can read any user's bank information via JavaScript cross-origin requests

CVSS 8.1
SEA Crypto Exchange
SEA
CORS Responsible Disclosure High 2026-04
Strapi CMS Unauthenticated Blog Content Modification

> NEW FINDING

CVSS 8.1
African SME Lender
Africa
XSS Responsible Disclosure High 2026-04
JWT twoFAToken Contains Plaintext Admin Password

Decoded twoFAToken JWT payload embeds admin plaintext password, bypassing hashing protections.

CVSS 8.0
SEA P2P Crypto Exchange
SEA
JWT Issues Responsible Disclosure High 2026-04
Hidden Admin Dashboard Route Exposed

Undocumented admin route discoverable via source map reaches authenticated admin UI.

CVSS 8.0
Indian Crypto Exchange
SEA
Admin Panel Exposure Responsible Disclosure High 2026-04
Hardcoded API Keys and Secrets in Client-Side JavaScript

Multiple third-party API keys exposed in JS including analytics, push and object-store with verified active status.

CVSS 8.0
African Crypto Aggregator
Africa
API Key Exposure Responsible Disclosure High 2026-04
Universal CORS Wildcard on 392 API Endpoints

All 392 PHP API endpoints return ACAO * enabling cross-origin reads of authenticated data.

CVSS 8.0
African Crypto Gift Card Platform
Africa
CORS Responsible Disclosure High 2026-04
16+ Spring Boot Actuator Endpoints Exposed on 8 Domains

Spring Boot actuator endpoints allow env dump and heap snapshots on 8 domains.

CVSS 8.0
Gaming Marketplace
SEA
Admin Panel Exposure Responsible Disclosure High 2026-04
OTP Rate Limiting Set to Zero

OTP endpoint has no throttle enabling SMS bomb and brute force.

CVSS 8.0
Gaming Marketplace
SEA
Rate Limit Bypass Responsible Disclosure High 2026-04
SigNoz Enterprise Monitoring Platform Public Exposure [HIGH]

Finding 5: SigNoz Enterprise Monitoring Platform Public Exposure [HIGH] Summary: signoz.[redacted].ng adresinde SigNoz v0.115.0 Enterprise Edition monitoring platformu public internet'e acik. Version bilgisi ve setup durumu unauthenticated olarak ogrenilebiliyor. Platform traces, lo

CVSS 7.8
Nigerian Neobank
Africa
Auth Bypass Responsible Disclosure High 2026-04
Stored XSS via Feedback Form (HIGH - CVSS 7.3)

Finding 16: Stored XSS via Feedback Form (HIGH - CVSS 7.3) Vulnerable Endpoint: `POST https://thor.[redacted].com/api/feedback` Type: Stored Cross-Site Scripting (CWE-79) Admin reviews feedback in Nova -> XSS fires -> admin session compromise.

CVSS 7.8
African Crypto Exchange
Africa
XSS Responsible Disclosure High 2026-04
HIGH - Unauthenticated Currency Data Exposure

Finding 3: HIGH - Unauthenticated Currency Data Exposure URL: `GET https://api.[redacted].site/v1/misc/fiat-currencies`

CVSS 7.8
Mixed Platforms
Global
Information Disclosure Responsible Disclosure High 2026-04
Mass Db Scan

Mass Database/Admin Panel Scan Results Objective: Find platforms with exposed [redacted], phpMyAdmin, Adminer, or Firebase RTDB with real user data Regions: Southeast Asia, Middle East, Eastern Europe, Africa | [redacted] instances found | 6 |

CVSS 7.8
Mass DB Scan
Global
Admin Panel Exposure Responsible Disclosure High 2026-04
Spring Boot Actuator + [redacted] UI Exposure (bydatawelive.[redacted].ng) [HIGH]

Finding 4: Spring Boot Actuator + [redacted] UI Exposure (bydatawelive.[redacted].ng) [HIGH] Summary: bydatawelive.[redacted].ng adresinde "Topupbox" (Zeedlabs) airtime/data vending servisi calisiyor. Spring Boot Actuator endpoint'leri ve [redacted] UI public erisime acik. Actuator health/in

CVSS 7.8
Nigerian Neobank
Africa
Information Disclosure Responsible Disclosure High 2026-04
Security Finding

Only the `Ocp-Apim-Subscription-Key` header is required - no authentication token needed. - PROD: `[target]` - PROD: `[target]` - DEV: `c

CVSS 7.8
African Remittance Provider
Africa
Cloud Misconfig Responsible Disclosure High 2026-04
Stored XSS via Bank Account Fields (HIGH - CVSS 7.6)

Finding 15: Stored XSS via Bank Account Fields (HIGH - CVSS 7.6) Vulnerable Endpoint: `POST https://thor.[redacted].com/api/banks` Type: Stored Cross-Site Scripting (CWE-79) Same as Finding 14 - when admin views user's bank account d[redacted]s in Nova panel, XSS executes. Can be combine

CVSS 7.8
African Crypto Exchange
Africa
XSS Responsible Disclosure High 2026-04
HIGH - Agent Portal Source Maps Exposed Across Country Instances

Finding 3: HIGH - Agent Portal Source Maps Exposed Across Country Instances The [redacted] Agent Portal at `agents.[redacted].com` and country-specific instances (`bf.agents.[redacted].com`, `ci.agents.[redacted].com`, etc.) serve source maps for all JavaScript bundles. - Multi-country deployment (bf, c

CVSS 7.8
African Neobank
Africa
Information Disclosure Responsible Disclosure High 2026-04
JWT Exploit Results

Critical Discovery: Device tokens pass BOTH web AND admin auth middleware | Auth Method | web/transactions | admin/users | web/configs | admin/teams | |---------------------|-----------------|-------------|-------------|-------------| | No auth | 401 | 401 | 401 | 401 |

CVSS 7.8
Nigerian Payment Provider
Africa
JWT Issues Responsible Disclosure High 2026-04
WSO2 API Manager Publisher Console + DevPortal Public Access [HIGH]

Finding 3: WSO2 API Manager Publisher Console + DevPortal Public Access [HIGH] Summary: apiconsole.[redacted].ng adresinde WSO2 API Manager Publisher Console ve DevPortal public internet'e acik. Publisher API 401 donuyor (auth gerekli) ancak Publisher UI, DevPortal UI, settings dosy

CVSS 7.8
Nigerian Neobank
Africa
Rate Limit Bypass Responsible Disclosure High 2026-04
Session Not Invalidated After Password Change on Payment Gateway

Password change does not terminate existing sessions, allowing stolen-token reuse indefinitely.

CVSS 7.5
European Payment Gateway
EU
Broken Authentication Responsible Disclosure High 2026-04
Full Application Source Code Exposure via Public Source Maps

Auth and profile apps expose 18.5MB source maps (2227 files) disclosing full auth flow, KYC logic, OAuth config and 50+ API endpoints.

CVSS 7.5
European Payment Gateway
EU
Information Disclosure Responsible Disclosure High 2026-04
Authentication Bypass on Consumer Financing Order Endpoints

Financing order endpoints accessible without auth, exposing order data and enabling potential abuse of BNPL flow.

CVSS 7.5
European Payment Gateway
EU
Auth Bypass Responsible Disclosure High 2026-04
HTML Email Injection via Purchase Receipts Enables Phishing

Product name field is rendered in receipt HTML emails without encoding allowing arbitrary phishing payloads from merchant-branded sender.

CVSS 7.5
European Payment Gateway
EU
Information Disclosure Responsible Disclosure High 2026-04
Arbitrary Live API Key Creation Without Password Confirmation

Authenticated session can mint new live API keys without re-auth, enabling persistent access after session hijack.

CVSS 7.5
European Payment Gateway
EU
Broken Authentication Responsible Disclosure High 2026-04
Zero-Amount Preauthorization Combined With mark_as_paid

Zero-amount preauth then marked paid completes an order without a real payment capture.

CVSS 7.5
European Payment Gateway
EU
Business Logic Responsible Disclosure High 2026-04
Live API Key Secret Exposed in Plaintext via List Endpoint

/api/keys endpoint returns secret keys in plaintext on listing, violating key-display-once policy.

CVSS 7.5
European Payment Gateway
EU
Credential Exposure Responsible Disclosure High 2026-04
Billing Invoice Abuse via mark_as_paid Without Real Payment

Merchant can create invoices and mark them paid internally to inflate revenue figures or trigger delivery without payment.

CVSS 7.5
European Payment Gateway
EU
Business Logic Responsible Disclosure High 2026-04
Unauthenticated Socket.IO Real-Time Stream

Socket.IO endpoint broadcasts real-time trade notifications and user presence without requiring auth.

CVSS 7.5
SEA P2P Crypto Exchange
SEA
WebSocket Issues Responsible Disclosure High 2026-04
Unauthenticated Invoice Creation via IDOR

Invoice creation endpoint skips userId ownership check, allowing arbitrary invoices against any target.

CVSS 7.5
SEA P2P Crypto Exchange
SEA
IDOR Responsible Disclosure High 2026-04
ReKYC Encryption Equals No Encryption (Fixed Static Key)

ReKYC module ships with deterministic encryption key in APK, allowing decryption of any intercepted ReKYC payload.

CVSS 7.5
Indian Investment Broker
SEA
Credential Exposure Responsible Disclosure High 2026-04
Ledger Service Kong Gateway Balance API Unauthorized Access

Ledger balance API reachable via Kong without proper identity propagation allowing partial data retrieval.

CVSS 7.5
Indian Investment Broker
SEA
Access Control Responsible Disclosure High 2026-04
Unauthenticated Discovery Config Exposes 287 Keys and 89 Internal Hosts

Discovery config endpoint returns zlib-compressed map of 287 keys and 89 internal production hostnames.

CVSS 7.5
Indian Investment Broker
SEA
Information Disclosure Responsible Disclosure High 2026-04
SmartAPI Source Maps Exposed (6.2MB Full Frontend)

SmartAPI developer portal ships source maps disclosing 47 internal API endpoints and auth flow.

CVSS 7.5
Indian Investment Broker
SEA
Information Disclosure Responsible Disclosure High 2026-04
UAT Trading Platform Exposed on Direct EC2 With Live Routes

UAT trade host reachable on direct EC2 IP with 384 internal URLs and exposed robots.txt.

CVSS 7.5
Indian Investment Broker
SEA
Admin Panel Exposure Responsible Disclosure High 2026-04
Hardcoded AES Key smartapi2024 + Full Source via Source Map

Static AES key in SmartAPI portal decrypts all API calls, combined with source map leaks.

CVSS 7.5
Indian Investment Broker
SEA
Credential Exposure Responsible Disclosure High 2026-04
HyperVerge KYC SDK Production Credentials in APK

Production and UAT HyperVerge appId+secret in APK allow direct KYC workflow invocation and analytics ingestion.

CVSS 7.5
Indian Investment Broker
SEA
API Key Exposure Responsible Disclosure High 2026-04
Exported Push Intent Enables Arbitrary Deep Link and WebView Routing

Exported push-notification intent accepts attacker-controlled URL and forwards into authenticated TWA/WebView.

CVSS 7.5
Indian Investment Broker
SEA
Deeplink Hijacking Responsible Disclosure High 2026-04
App-Link Wrappers With Nested link= Parameter Bypass Origin Control

Allowed wrapper domain forwards nested link= param into TWA context skipping origin validation.

CVSS 7.5
Indian Investment Broker
SEA
Deeplink Hijacking Responsible Disclosure High 2026-04
Java Trading Application JAR Publicly Downloadable

Stock trading JNLP/JAR downloadable anonymously, exposing outdated libs vulnerable to deserialization CVEs.

CVSS 7.5
SEA Investment Platform
SEA
Information Disclosure Responsible Disclosure High 2026-04
Backup-Prioritas Admin Panel Full Source Code Exposure

Backup admin panel source maps leak investor management flows and session logic.

CVSS 7.5
SEA Investment Platform
SEA
Information Disclosure Responsible Disclosure High 2026-04
OTC Source Map Exposes 856 Files and Razorpay Key

Production OTC bundle ships source map with 856 files and Razorpay public key.

CVSS 7.5
Indian Crypto Exchange
SEA
Information Disclosure Responsible Disclosure High 2026-04
Exchange Source Maps Reveal 1337 Files and Admin JWT

Exchange UI source map includes developer admin JWT and credentials in code comments.

CVSS 7.5
Indian Crypto Exchange
SEA
Information Disclosure Responsible Disclosure High 2026-04
Wildcard CORS on Exchange API With Credentials

Public exchange API reflects ACAO with credentials enabling cross-origin trade APIs.

CVSS 7.5
Indian Crypto Exchange
SEA
CORS Responsible Disclosure High 2026-04
CORS Wildcard on API Backend

All API endpoints reflect ACAO * allowing cross-origin reads of authenticated user data.

CVSS 7.5
EU Crypto ATM Operator
EU
CORS Responsible Disclosure High 2026-04
Admin Dashboard Publicly Accessible With Full Route Exposure

Admin SPA reachable without IP allowlist and ships route map to all admin modules.

CVSS 7.5
African Crypto Aggregator
Africa
Admin Panel Exposure Responsible Disclosure High 2026-04
Development and Staging Environments Publicly Accessible

Multiple dev/staging hosts serve identical codebase to prod, usable as test lab for exploits.

CVSS 7.5
African Crypto Aggregator
Africa
Admin Panel Exposure Responsible Disclosure High 2026-04
Admin Panel Publicly Accessible With Full Frontend Source

Admin panel reachable publicly and ships 753KB of frontend source revealing admin routes.

CVSS 7.5
MENA Crypto Exchange
MENA
Admin Panel Exposure Responsible Disclosure High 2026-04
Rancher Dashboard UI Publicly Accessible

Rancher UI publicly reachable, disclosing K8s/Rancher versions and cluster inventory.

CVSS 7.5
MENA Crypto Exchange
MENA
Admin Panel Exposure Responsible Disclosure High 2026-04
CRM Admin Panel Publicly Accessible

Bitdenex CRM admin reachable without IP allowlist, exposing internal dashboard.

CVSS 7.5
MENA Crypto Exchange
MENA
Admin Panel Exposure Responsible Disclosure High 2026-04
Full Application Source Code Exposure via Source Maps

bitexlive.com ships .map files exposing full JS application.

CVSS 7.5
SEA Crypto Exchange
SEA
Information Disclosure Responsible Disclosure High 2026-04
Unauthenticated Sidekiq Dashboard

coinome.com exposes legacy Sidekiq v5.0.4 dashboard without auth revealing job queues.

CVSS 7.5
Indian Crypto Exchange
SEA
Admin Panel Exposure Responsible Disclosure High 2026-04
18+ Production Backend Microservices Exposed

koinpark.com exposes 18+ internal microservices directly to the internet.

CVSS 7.5
Indian Crypto Exchange
SEA
Admin Panel Exposure Responsible Disclosure High 2026-04
Insufficient Rate Limiting on OTP Verification

OTP verify endpoint permits enough attempts to brute force 6-digit code in minutes.

CVSS 7.5
African Fintech Neobank
Africa
Rate Limit Bypass Responsible Disclosure High 2026-04
Full Source Map Exposure 48.6MB Production Build

Production Next.js build ships source maps totaling 48.6MB exposing internal modules.

CVSS 7.5
African Fintech Expense Platform
Africa
Information Disclosure Responsible Disclosure High 2026-04
Multiple Secret Keys Exposed in Production JS Bundle

Production JS reveals multiple API secrets used in critical flows.

CVSS 7.5
African Fintech Expense Platform
Africa
Credential Exposure Responsible Disclosure High 2026-04
Zoho OAuth Client Secret Exposed With Full API Scope

Zoho OAuth client secret present in bundle with full scope enabling potential mailbox access.

CVSS 7.5
African Fintech Expense Platform
Africa
Credential Exposure Responsible Disclosure High 2026-04
Mono Connect LIVE Keys Exposed (Banking Data Access)

Mono Connect live keys leaked allowing widget impersonation and social-engineering tied to customer bank accounts.

CVSS 7.5
African Fintech Expense Platform
Africa
API Key Exposure Responsible Disclosure High 2026-04
File Upload Extension Whitelist Bypass Potential

Upload endpoints validate via allowlist matching but handle case/extension parsing unsafely.

CVSS 7.5
African Crypto Gift Card Platform
Africa
File Upload Responsible Disclosure High 2026-04
Swagger-UI Exposed on 3 Domains

Production Swagger UI exposed revealing full API contract.

CVSS 7.5
Gaming Marketplace
SEA
Information Disclosure Responsible Disclosure High 2026-04
Admin Panel Source Map Exposed

Billions.network admin panel ships source map revealing 96 API endpoints.

CVSS 7.5
Web3 Reputation Protocol
Global
Information Disclosure Responsible Disclosure High 2026-04
Ngrok Dev URL Leak in Production + CORS Wildcard

PocketBits production ships ngrok dev URL with CORS wildcard leak.

CVSS 7.5
Indian Crypto Exchange
SEA
CORS Responsible Disclosure High 2026-04
Client Registration Credentials Present in Production JS

Production JS embeds client registration credentials accepted by server (500 ISE, not 401).

CVSS 7.5
Indian Crypto Exchange
SEA
Credential Exposure Responsible Disclosure High 2026-04
Admin Panel + Swagger API Docs + KYC Microservice Exposure

Admin panel and Swagger for KYC microservice reachable publicly.

CVSS 7.5
Indian Crypto Exchange
SEA
Admin Panel Exposure Responsible Disclosure High 2026-04
Swagger API Docs + Laravel Ignition Active in Production

Laravel Ignition endpoint live with Swagger docs exposed in production environment.

CVSS 7.5
Indian Crypto Exchange
SEA
Information Disclosure Responsible Disclosure High 2026-04
Uploadcare/Mono/Coinbase Pay API Keys Exposed

Multiple payment and CDN keys bundled in frontend.

CVSS 7.5
African Crypto Infrastructure
Africa
API Key Exposure Responsible Disclosure High 2026-04
Widget Bundle Source Map Exposure

Public widget source map leaks integration patterns.

CVSS 7.5
African Crypto Infrastructure
Africa
Information Disclosure Responsible Disclosure High 2026-04
Firebase Storage KYC Document Listing (7 KYC)

flipex-app bucket allows unauthenticated listing of UAT/KYC_DOCUMENTS/ folder.

CVSS 7.5
African Crypto Trading Mobile App
Africa
Firebase Misconfig Responsible Disclosure High 2026-04
Admin Panel Source Map Exposure (555 Files)

admin.dtunes.ng exposes 1.4MB source map revealing 60+ admin API endpoints.

CVSS 7.5
African Digital Platform
Africa
Information Disclosure Responsible Disclosure High 2026-04
splitpay-app - Storage Open

splitpay-app Firebase Storage allows anonymous reads.

CVSS 7.5
African Fintech Firebase Cohort
Africa
Firebase Misconfig Responsible Disclosure High 2026-04
Metabase Setup-Token Leakage via /api/session/properties

pricepally Metabase exposes setup-token + AWS EC2 IP via unauthenticated endpoint.

CVSS 7.5
African Fintech Metabase Cohort
Africa
Credential Exposure Responsible Disclosure High 2026-04
Firestore Unauthenticated Access

Firestore collections readable without auth due to default rules.

CVSS 7.5
African Investment Fintech
Africa
Firebase Misconfig Responsible Disclosure High 2026-04
DMS Open Signup via Google OAuth

ISO Document Management System accepts Google OAuth signup from any gmail account.

CVSS 7.5
African Investment Fintech
Africa
Access Control Responsible Disclosure High 2026-04
Password Reset Token Brute Force No Rate Limit

Password reset token brute-forceable with no throttle.

CVSS 7.5
African Payment Platform
Africa
Rate Limit Bypass Responsible Disclosure High 2026-04
Paystack Live Key Exposed in Frontend

pk_live Paystack key embedded in production bundle.

CVSS 7.5
African Pharma B2B Platform
Africa
Credential Exposure Responsible Disclosure High 2026-04
Patient Medical Data Endpoints Discoverable

/api/telimedicine/patient endpoint discoverable through debug route list.

CVSS 7.5
African Pharma B2B Platform
Africa
Information Disclosure Responsible Disclosure High 2026-04
OTC Subdomain CNAME Misconfiguration (Bubble.io)

otc.cryptal.com points to Bubble.io without valid app; takeover feasible.

CVSS 7.5
European Crypto Exchange
EU
Subdomain Takeover Responsible Disclosure High 2026-04
Shyft Mainnet RPC API Key Hardcoded

config.ts exposes Shyft mainnet RPC key used for both RPC and sender URL.

CVSS 7.5
L1 Smart Contract
Global
API Key Exposure Responsible Disclosure High 2026-04
Helius Mainnet RPC Key + DAS Enhanced API Key

Helius RPC and DAS enhanced API key bundled in frontend; usable for 3 endpoints.

CVSS 7.5
L1 Smart Contract
Global
API Key Exposure Responsible Disclosure High 2026-04
Aux00 Internal Django Dashboard Login Exposed

aux00 internal Django dashboard reachable publicly with login form.

CVSS 7.5
LATAM Crypto Platform
LATAM
Admin Panel Exposure Responsible Disclosure High 2026-04
Staging Exchange App + API Docs Public

stg.notbank.exchange and stg.apidoc public with full staging schema.

CVSS 7.5
LATAM Crypto Platform
LATAM
Information Disclosure Responsible Disclosure High 2026-04
Development API Publicly Accessible in Production

api-test2 dev API and dev S3 bucket referenced in production bundle and reachable without auth.

CVSS 7.5
MENA Regulated Crypto Exchange
MENA
Cloud Misconfig Responsible Disclosure High 2026-04
Zero Rate Limiting on All Authentication Endpoints

Login, registration and 2FA endpoints have no rate limit enabling parallel brute force.

CVSS 7.5
European iGaming Platform
EU
Rate Limit Bypass Private Engagement High 2026-04
Mass User PII Exposure (544 Users) via Admin Search

User search API returns full 544-user list with PII including phone numbers without authorization.

CVSS 7.5
EU EdTech Platform
EU
Information Disclosure Responsible Disclosure High 2026-04
Event Registration PII Mass Dump - 659 Records

Event registration endpoint allows unauthenticated pagination through 659 attendee records with emails and phone numbers.

CVSS 7.5
EU EdTech Platform
EU
Information Disclosure Responsible Disclosure High 2026-04
Full Source Code Exposure via Source Maps

540 application source files recoverable from production source maps revealing HMAC keys and flows.

CVSS 7.5
West African B2B Fintech
Africa
Information Disclosure Responsible Disclosure High 2026-04
Unauthenticated Payment Token Generation Endpoint

Payment token generation endpoint accessible without auth enabling unauthorized checkout session creation.

CVSS 7.5
West African B2B Fintech
Africa
Access Control Responsible Disclosure High 2026-04
Admin Panel Source Code Exposure via Source Map

Admin panel ships 364KB source map leaking 22 source files and admin flows.

CVSS 7.5
LATAM Crypto Platform
LATAM
Information Disclosure Responsible Disclosure High 2026-04
Metabase Setup Token Exposed (bi.agrotoken)

Third LATAM Metabase tenant exposes live setup token.

CVSS 7.5
LATAM Crypto Platform
LATAM
Cloud Misconfig Responsible Disclosure High 2026-04
env.js/config.js Files Expose Internal Service Architecture

Public config JS reveals internal service map and API keys.

CVSS 7.5
African Digital Bank
Africa
Information Disclosure Responsible Disclosure High 2026-04
HIGH - Auth Staging Source Map Exposure (5.7MB, 348 Files, Full Auth Logic)

The staging authentication portal at auth-staging.[vendor] serves source maps containing complete TypeScript source code for the authentication system, including Cognito configuration, MFA flows, card security code validation, password reset logic, and embedded staging credentials

CVSS 7.5
European B2B Spend Management
EU
Information Disclosure Responsible Disclosure High 2026-04
GitLab Open Public Registration

> NEW FINDING

CVSS 7.5
African SME Lender
Africa
GraphQL Issues Responsible Disclosure High 2026-04
[vendor] Multi-Tenant Isolation Assessment

Target: [vendor] (HashCash Consultants LLC) Scope: Cross-broker tenant isolation across 1,928 white-label broker instances

CVSS 7.5
Global Crypto Exchange
Global
S3 Misconfig Responsible Disclosure High 2026-04
Move Pusher authentication to server-side only

CVSS 7.5
African Payment Gateway
Africa
Information Disclosure Responsible Disclosure High 2026-04
IdentityRadar Full Source Code Exposure via Source Map

Vulnerable Endpoint: https://radar.[vendor]/static/js/main.ce51035c.js.map Size: 8,657,100 bytes (8.6 MB) / 1,268 source files / 173 application source files

CVSS 7.5
African Identity Verification
Africa
Information Disclosure Responsible Disclosure High 2026-04
WordPress Directory Listing Exposes 3,567+ Upload Files (HIGH)

Finding 3: WordPress Directory Listing Exposes 3,567+ Upload Files (HIGH) Severity: High (CVSS 7.5 - AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) Summary: The WordPress blog at blog.[redacted].com has Apache directory listing enabled for the entire `/wp-content/uploads/` directory tree. Thi

CVSS 7.5
MENA Fintech
MENA
Information Disclosure Responsible Disclosure High 2026-04
OData Metadata & Internal Architecture Exposure (HIGH)

Finding 3: OData Metadata & Internal Architecture Exposure (HIGH) The OData v4 metadata endpoints on both production and development API gateways are publicly accessible with only the subscription key (no bearer token required). These endpoints expose the complete database schema

CVSS 7.5
African Remittance Provider
Africa
Cloud Misconfig Responsible Disclosure High 2026-04
Unauthenticated API Endpoints Expose Business Data (HIGH)

Finding 4: Unauthenticated API Endpoints Expose Business Data (HIGH) Severity: High (CVSS 7.5 - AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) Summary: Multiple API v2 endpoints on both hiftigh.[redacted].com and [target] return business-critical data without any authentication,

CVSS 7.5
MENA Fintech
MENA
IDOR Responsible Disclosure High 2026-04
(NEW): Complete Admin Console Architecture Leak via JavaScript Source Maps

Finding 11 (NEW): Complete Admin Console Architecture Leak via JavaScript Source Maps Severity: HIGH (CVSS 7.5 - AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) The admin console at `console.[redacted].ng` exposes unobfuscated JavaScript bundles containing the complete admin API endpoint map

CVSS 7.5
Nigerian Payment Provider
Africa
Information Disclosure Responsible Disclosure High 2026-04
Massive Source Map Exposure Across 3 Applications (HIGH)

Finding 1: Massive Source Map Exposure Across 3 Applications (HIGH) - `https://app.[redacted].com/main.2ef2e977bb5dc9ba.js.map` (9.6 MB, 502 sources, 33 app files) - `https://admin.[redacted].com/main-P7MYWRXZ.js.map` (364 KB, 22 sources, 10 app files) - `https://ramp.manteca

CVSS 7.5
LATAM Crypto Platform
LATAM
Information Disclosure Responsible Disclosure High 2026-04
Admin Login Approval Status IDOR -- Unauthenticated Monitoring (HIGH)

Finding 2: Admin Login Approval Status IDOR -- Unauthenticated Monitoring (HIGH) Severity: High (CVSS 7.5 - AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) Summary: The endpoint `GET /login/check-approval/{id}` on hiftigh.[redacted].com returns the status of admin login approval requests witho

CVSS 7.5
MENA Fintech
MENA
IDOR Responsible Disclosure High 2026-04
CORS Wildcard on v2 API

v2-api.dtunes.ng returns ACAO:* which combined with AES key enables cross-origin session hijack.

CVSS 7.4
African Digital Platform
Africa
CORS Responsible Disclosure High 2026-04
Google reCAPTCHA Secret Key Exposed in Frontend

VITE_GOOGLE_RECAPTCHA_SECRET_KEY hardcoded in production SPA; bot-protection bypass.

CVSS 7.4
Crypto Payment Infrastructure
Global
Credential Exposure Responsible Disclosure High 2026-04
OAuth Endpoints Operating Over HTTP

OAuth authorization/token endpoints served over plain HTTP exposing tokens to network observers.

CVSS 7.4
EU EdTech Platform
EU
Broken Authentication Responsible Disclosure High 2026-04
Amplitude API Write Access Enables Event Injection

Amplitude API key with write permissions leaked permits injection of arbitrary analytics events to poison user profiles.

CVSS 7.3
European iGaming Platform
EU
API Key Exposure Private Engagement High 2026-04
n8n Workflow Automation Platform Publicly Accessible

n8n workflow platform reachable without auth allowing workflow inspection and webhook trigger abuse.

CVSS 7.3
African Digital Bank
Africa
Admin Panel Exposure Responsible Disclosure High 2026-04
Admin Panel Publicly Accessible with Dev Tools Enabled (HIGH)

Finding 2: Admin Panel Publicly Accessible with Dev Tools Enabled (HIGH) Affected Component: `https://admin.[redacted].com` Summary: The Manteca admin panel (admin.[redacted].com) is publicly accessible without any network-level restriction. The admin panel includes developme

CVSS 7.3
LATAM Crypto Platform
LATAM
Information Disclosure Responsible Disclosure High 2026-04
Seven Internal Microservice APIs Exposed on Public Internet

Backend microservices intended for internal VPC are reachable publicly with minimal auth, expanding attack surface.

CVSS 7.2
European Payment Gateway
EU
Admin Panel Exposure Responsible Disclosure High 2026-04
Demo Environment Open Signup With Full Banking Access

Demo ourSpell instance allows open registration with full ecommerce/banking admin, leaking product architecture.

CVSS 7.2
European Payment Gateway
EU
Admin Panel Exposure Responsible Disclosure High 2026-04
TWA JavaScript Bridge Launches Arbitrary URLs Inside Auth Context

TWA JS bridge exposes openUrl method without allowlist, usable by embedded ads or nested iframes.

CVSS 7.2
Indian Investment Broker
SEA
Deeplink Hijacking Responsible Disclosure High 2026-04
Django Admin Panel Exposed on Production API

Vulnerable Endpoint: https://api.[vendor]/admin/login/ Server: CPython/3.10.20, WSGIServer/0.2, Django (latest dark_mode CSS)

CVSS 7.2
African Identity Verification
Africa
Admin Panel Exposure Responsible Disclosure High 2026-04
No Rate Limiting on Authentication Endpoints Enables Brute Force

Login, reset, and verification endpoints have no throttle enabling password/OTP brute force and credential stuffing.

CVSS 7.1
European Payment Gateway
EU
Rate Limit Bypass Responsible Disclosure High 2026-04
Staging Environment dev.* Exposed to Internet

Staging host is publicly reachable exposing pre-release vulnerabilities to attackers.

CVSS 7.1
European iGaming Platform
EU
Information Disclosure Private Engagement High 2026-04
Hardcoded X-PrivateKey smartapi_zRzIJ3bN Used Across API Calls

Static privateKey identifier leaked enables signature replay against SmartAPI trading endpoints.

CVSS 7.0
Indian Investment Broker
SEA
API Key Exposure Responsible Disclosure High 2026-04
Cleartext Traffic Allowed to Market Data Servers in APK

Network security config allows cleartext HTTP to market-data hosts enabling MITM on hostile networks.

CVSS 7.0
Indian Investment Broker
SEA
Broken Authentication Responsible Disclosure High 2026-04
Complete APK Environment Configuration Files Exposed

flows.json and env configs bundled in APK enumerate 50+ KYC and payment endpoints per environment.

CVSS 7.0
Indian Investment Broker
SEA
Information Disclosure Responsible Disclosure High 2026-04
Generic WebView Fragments Trust Raw Argument URLs

Multiple WebView fragments accept arg-supplied URL without origin check, enabling phishing inside authenticated app.

CVSS 7.0
Indian Investment Broker
SEA
Deeplink Hijacking Responsible Disclosure High 2026-04
JWT Cookie Security Completely Disabled

Session JWT cookie lacks HttpOnly, Secure, SameSite, allowing XSS-based theft and replay.

CVSS 7.0
Indian Crypto Exchange
SEA
Broken Authentication Responsible Disclosure High 2026-04
OTC API Accepts Hardcoded localhost:3003 as CORS Origin

Hardcoded dev origin allowed with credentials lets attackers host malicious page on attacker-controlled localhost binding.

CVSS 7.0
Indian Crypto Exchange
SEA
CORS Responsible Disclosure High 2026-04
CodeIgniter 3.1.0 Backend Exposed with User Guide Online

EOL CodeIgniter backend exposes default pages and user guide identifying CVE-vulnerable version.

CVSS 7.0
Indian Crypto Exchange
SEA
Information Disclosure Responsible Disclosure High 2026-04
Unprotected API Backend Without WAF or CDN

Public API origin reachable directly with Apache/Ubuntu banner and no rate limiting.

CVSS 7.0
EU Crypto ATM Operator
EU
Cloud Misconfig Responsible Disclosure High 2026-04
Self-Hosted Sentry Event Injection (Exchange)

Self-hosted Sentry DSN accepts unauth events enabling log pollution.

CVSS 7.0
European Crypto Exchange
EU
Information Disclosure Responsible Disclosure High 2026-04
Braze SDK API Key and Multiple Third-Party Credentials Exposed

Braze and other analytics keys in JS allow impersonating the app to push notifications and read analytics.

CVSS 7.0
European Crypto Exchange
EU
API Key Exposure Responsible Disclosure High 2026-04
Unauthenticated Username Enumeration via Public API

Differential responses on username lookup expose account existence feeding password spraying.

CVSS 7.0
African Fintech Neobank
Africa
Information Disclosure Responsible Disclosure High 2026-04
Debug Mode Enabled on Production API Endpoints

Debug flag leaks verbose SQL errors and stack traces in production.

CVSS 7.0
African Crypto Gift Card Platform
Africa
Information Disclosure Responsible Disclosure High 2026-04
WooCommerce Plugin Callback Missing Signature Verification + SSL Off

Official WooCommerce payment plugin skips callback signature validation and ships with SSL verification disabled.

CVSS 6.5
European Payment Gateway
EU
Webhook Forgery Responsible Disclosure High 2026-04
Metabase v0.57.3 Public + Google OAuth Config Exposed

metabase.eversend.co exposes Google OAuth client ID and version enabling targeted attacks.

CVSS 6.5
African Neobank
Africa
Admin Panel Exposure Responsible Disclosure High 2026-04
Keycloak 25+ Public Configuration Exposure

auth subdomain exposes Keycloak realms and internal configuration.

CVSS 6.5
European Crypto Exchange
EU
Information Disclosure Responsible Disclosure High 2026-04
Sentry DSN + Event Injection Production Project

Sentry DSN hardcoded and accepts forged events into production project.

CVSS 6.5
MENA Regulated Crypto Exchange
MENA
Credential Exposure Responsible Disclosure High 2026-04
Admin Account Takeover via OTP Brute Force

Finding 6: Admin Account Takeover via OTP Brute Force The OTP verification endpoints accept unlimited attempts without rate limiting or account lockout. Combined with Finding 3 (unauthenticated device token) and Finding 7 (email enumeration), an attacker can complete a full admin

CVSS 8.8
Nigerian Payment Provider
Africa
Rate Limit Bypass Responsible Disclosure High 2026-03
CORS Origin Reflection + Credentials on Server Management Panel (CRITICAL)

Finding 1: CORS Origin Reflection + Credentials on Server Management Panel (CRITICAL) CRITICAL (CVSS 8.8) — AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H platform.[redacted].com üzerindeki Tenantos server management paneli, gelen HER Origin header'ını `Access-Control-Allow-Origin` response h

CVSS 8.8
Web Hosting Provider
EU
Credential Exposure Responsible Disclosure High 2026-03
CRITICAL - CORS Wildcard + Credentials:true

business-banking.[vendor] API'si tum endpointlerinde Access-Control-Allow-Origin: ve Access-Control-Allow-Credentials: true header'larini birlikte dondurmektedir

CVSS 8.7
African Payment Processor
Africa
CORS Responsible Disclosure High 2026-03
Google 2FA TOTP Secret Exposed in Plaintext via Profile API

When a user enables Google Authenticator 2FA, their TOTP secret key is stored on the server. The problem is that this secret is returned in the API response when fetching the user's profile. Anyone with access to the user's token can read this secret, generate valid 2FA codes, and disable 2FA entirely

CVSS 8.7
Crypto Gaming Platform
Global
Business Logic Responsible Disclosure High 2026-03
Swap Limit Order No OTP -- Funds Locked Without Verification

Swap Limit Order No OTP -- Funds Locked Without Verification

CVSS 8.7
Crypto Gaming Platform
Global
Credential Exposure Responsible Disclosure High 2026-03
SQL Injection on LIMIT Clause of Trade Endpoint

Trade endpoint appends user-controlled LIMIT clause parameter allowing time-based SQLi.

CVSS 8.6
Indian Crypto Exchange
SEA
SQLi Responsible Disclosure High 2026-03
SSRF IP Format Bypass - No SSRF Filter

No SSRF filter exists; IP format variations all bypass.

CVSS 8.6
EU Gaming Marketplace
EU
SSRF Responsible Disclosure High 2026-03
Telefon numarasi ekrani

curl -s -o phone_number.jpg "https://firebasestorage.googleapis.com/v0/b/business-banking-93cc1.appspot.com/o/account-details%2F1749634011035.png?alt=media"

CVSS 8.6
African Payment Processor
Africa
Firebase Misconfig Responsible Disclosure High 2026-03
DeveloperExceptionPage Enabled in Production (redeem-cards.com)

ASP.NET Core DeveloperExceptionPageMiddleware is enabled in production. Every unhandled exception returns complete .NET stack traces with source file paths, line numbers, method signatures, the entire middleware pipeline, all HTTP request headers (including real IPs), and internal application architecture

CVSS 8.6
EU Gaming Key Marketplace
EU
Information Disclosure Responsible Disclosure High 2026-03
Unauthenticated Debug Endpoint Leaks Internal Service Configuration

The debug endpoint returns the complete request/response object of a server-side HTTP call to redeem-cards.com, exposing internal service credentials (UserType: [vendor]Bot), admin names (emre), the internal API URL, and server-to-server communication patterns -- all without authentication

CVSS 8.6
EU Gaming Key Marketplace
EU
Credential Exposure Responsible Disclosure High 2026-03
Sandbox Horizon Dashboard Unauthenticated

=== Subdomains (21 via crt.sh) === www.[vendor] - 200 - Laravel + Livewire + Alpine.js (PRODUCTION) api.[vendor] - 403 - API Gateway (Cloudflare protected, IP restricted) sandbox.[vendor] - 200 - Laravel (DEBUG ON, HORIZON OPEN) document.[vendor] - 200 - Postman Documenter (API docs) cdn.[vendor] - 403 - CDN (Cloudf

CVSS 8.6
EU Digital Goods Marketplace
EU
Admin Panel Exposure Responsible Disclosure High 2026-03
PostgreSQL Database Information Disclosure

Endpoint: https://sandbox.[vendor]/api/v2/publishers

CVSS 8.6
EU Digital Goods Marketplace
EU
Information Disclosure Responsible Disclosure High 2026-03
Email Enumeration via Password Reset

/v2/auth/password-reset/start endpoint'i, verilen e-posta adresinin sistemde kayitli olup olmadigini acikca belirten hata mesajlari dondurmektedir. Rate limit sadece 5 request/window oldugu icin sinirli, ancak birden fazla IP kullanilarak veya X-Forwarded-For manipulasyonu ile bypass edilebilir

CVSS 8.6
African Crypto Exchange
Africa
Broken Authentication Responsible Disclosure High 2026-03
(CRITICAL): Internal API Documentation Leaks Production Partner API Architecture

The ReadMe-hosted API documentation at documentation.[vendor] exposes the complete Partner API architecture including 42+ endpoints, internal test URLs ([vendor].test:8010), a Postman workspace ID, and internal subdomain (kdhyuobbnv.[vendor].com). Combined with Finding 1, this provides a complete attack map

CVSS 8.6
African Crypto Exchange
Africa
Admin Panel Exposure Responsible Disclosure High 2026-03
CRITICAL -- Unauthenticated Order Status IDOR -- 6.2M+ Sipariste Mass Enumeration ve Real-Time Cart Monitoring

/ajax/get-order-status endpoint'i herhangi bir authentication veya authorization kontrolu olmadan, herhangi bir order_id icin siparis durumunu (status, refund_status) dondurur. ~6,210,000+ siparis numarasi enumerate edilebilir. 5 farkli status tipi ifsa edilmektedir: completed, expired, in_cart, sent, apply_refund. Real-time in_cart status izlem

CVSS 8.6
Gaming Marketplace
Global
IDOR HackerOne High 2026-03
Game Tools API Mass Data Exfiltration -- 724 Business Records via IDOR

Deep analysis of the Game Tools Backend API (app-gametools-api-proc.azurewebsites.net) reveals that 5 distinct data endpoints are completely unauthenticated and IDOR-vulnerable, exposing a total of 724+ business records including [vendor]' complete pricing algorithm parameters (value multipliers per game feature), monthly Average Order Val

CVSS 8.6
Gaming Marketplace
NA
IDOR Responsible Disclosure High 2026-03
Strapi CMS Open Registration with JWT Issuance

Vulnerable Endpoint: https://strapi.[vendor]/api/auth/local/register

CVSS 8.6
EU Gaming Marketplace
EU
JWT Issues Responsible Disclosure High 2026-03
Moonbase Admin Panel Source Code Exposure via CF Access Bypass

Moonbase Internal Admin Panel (4.5MB JavaScript) Exposed Without Authentication via [vendor] — Full Backoffice Architecture, 8 Admin Emails, 9 Internal API URLs, 200+ Admin Routes, Gorra Fraud System Config

CVSS 8.6
LATAM Crypto Platform
LATAM
Admin Panel Exposure HackerOne High 2026-03
K-2: Vite Development Server Exposed in Production (CRITICAL)

Finding K-2: Vite Development Server Exposed in Production (CRITICAL) Endpoint: `https://integrator.[redacted].com/` Summary: A Vite development server is running in production, exposing the complete application source code including TypeScript files, configuration, package.json,

CVSS 8.6
African Neobank
Africa
Information Disclosure Responsible Disclosure High 2026-03
Docker Registry Unauthenticated Full Catalog Access

Public Docker registry lists 29 repositories including google/cloud-sdk and golang with all tags.

CVSS 8.5
SEA Banking API Platform
SEA
Admin Panel Exposure Responsible Disclosure High 2026-03
Partner API Full Account Management via Public NPM Package

Public NPM package documents partner API including signing scheme and endpoints.

CVSS 8.5
Indian Crypto Exchange
SEA
Credential Exposure Responsible Disclosure High 2026-03
Subdomain Takeover on bello Marketing Subdomain (Railway Dangling)

Abandoned Railway deployment leaves CNAME dangling, permitting takeover to serve attacker content under bitafrika brand.

CVSS 8.2
African Crypto Exchange
Africa
Subdomain Takeover Responsible Disclosure High 2026-03
Source Map Exposure 71MB with AWS Keys + Payment Keys

71MB of production source code served publicly including AWS credentials and payment keys.

CVSS 8.2
African KYC/Identity Provider
Africa
Information Disclosure Responsible Disclosure High 2026-03
HashiCorp Vault Leaks Internal K8s Infrastructure and OIDC

Vault unauthenticated endpoints leak OIDC role names, Google OAuth client and root generation status.

CVSS 8.2
LATAM Crypto Exchange
LATAM
Information Disclosure Responsible Disclosure High 2026-03
HashiCorp Vault Unsealed and Publicly Accessible

Production Vault instance is unsealed and reachable over internet exposing secret management surface.

CVSS 8.2
African Gift Card Platform
Africa
Cloud Misconfig Responsible Disclosure High 2026-03
CORS Subdomain Wildcard Trust With Credentials on All Services

Production services accept any *.brankas.com origin with credentials, enabling subdomain-takeover to ATO chain.

CVSS 8.1
SEA Banking API Platform
SEA
CORS Responsible Disclosure High 2026-03
SQL Injection on Page Param + Stored Procedure Discovery

Page parameter allows stored-procedure enumeration via injection.

CVSS 8.1
Indian Crypto Exchange
SEA
SQLi Responsible Disclosure High 2026-03
Wildcard DNS + CORS Reflection Enhances Phishing-to-ATO

Wildcard DNS resolves every subdomain to single IP, combined with permissive CORS chains into ATO.

CVSS 8.1
African Fintech Remittance
Africa
Subdomain Takeover Responsible Disclosure High 2026-03
Race Condition in Financial Operations

Parallel Wallet/Withdraw requests processed concurrently without mutex enabling double-spend.

CVSS 8.1
African Crypto Trading Platform
Africa
Race Condition Responsible Disclosure High 2026-03
Webhook Trigger Forgery on Any Verification

/send-webhook triggers customer webhooks for arbitrary verifications including completed ones.

CVSS 8.1
African KYC/Identity Provider
Africa
Webhook Forgery Responsible Disclosure High 2026-03
CNPS Production API Client Auth Bypass

Hardcoded client credentials on CNPS production API enable authenticated API access.

CVSS 8.1
Central African Crypto Fintech
Africa
Auth Bypass Responsible Disclosure High 2026-03
Hetzner Cloud Metadata Reachable via Vault Misconfig

Hetzner metadata endpoint accessible; Vault direct IP with misconfigured listener.

CVSS 8.1
Central African Crypto Fintech
Africa
Cloud Misconfig Responsible Disclosure High 2026-03
16 Guest Order Endpoints with Zero Authentication

16 guest endpoints enable order takeover, credential theft, dispute fraud.

CVSS 8.1
Gaming Marketplace
EU
Access Control Responsible Disclosure High 2026-03
Race Condition Parallel Primer Tokens (No Mutex)

10/10 parallel Primer production tokens issued in <1s; discountPercent:100 accepted.

CVSS 8.1
Gaming Marketplace
EU
Race Condition Responsible Disclosure High 2026-03
Push Notification Send to All Users via Firebase

Firebase Cloud Messaging endpoint blocked only by missing credential file; otherwise sends to all users.

CVSS 8.1
Indian Crypto Exchange
SEA
Firebase Misconfig Responsible Disclosure High 2026-03
86 Public Pusher Trade Channels Front-Running

86 public trade channels subscribable unauthenticated enabling front-running.

CVSS 8.1
Indian Crypto Exchange
SEA
Business Logic Responsible Disclosure High 2026-03
Strapi CORS Wildcard Origin Reflection with Credentials

Vulnerable Endpoint: https://strapi.[vendor]/ (all endpoints)

CVSS 8.1
EU Gaming Marketplace
EU
CORS Responsible Disclosure High 2026-03
currency-api.[vendor] CORS Wildcard with Credentials

The currency-api.[vendor] endpoint returns Access-Control-Allow-Origin: combined with Access-Control-Allow-Credentials: true. While browsers technically ignore credentials with wildcard origin, the misconfiguration signals a deeper CORS issue. The preflight response also allows Authorization header, meaning authenticated API calls from any o

CVSS 8.1
African Remittance Platform
Africa
CORS Responsible Disclosure High 2026-03
CORS Wildcard on 23+ Authenticated User/Order Endpoints with DELETE Method Allowed

The SLS API at sls.[vendor] exposes 23+ authenticated user and order management endpoints behind a CORS wildcard () policy that also allows the DELETE HTTP method and accepts Authorization/X-Api-Key headers. While Access-Control-Allow-Credentials is not set (preventing cookie-based CSRF), the API uses Bearer token or API key authentication

CVSS 8.1
SEA Gaming Marketplace
SEA
CORS HackerOne High 2026-03
Dev Access Token Backdoor in Source Code

Source map reveals static dev token that is still validated server-side, granting privileged access.

CVSS 8.0
SEA Banking API Platform
SEA
Auth Bypass Responsible Disclosure High 2026-03
Payment Webhook Signature Scheme Fully Disclosed

Signature construction detailed in NPM doc allowing webhook forgery.

CVSS 8.0
Indian Crypto Exchange
SEA
Webhook Forgery Responsible Disclosure High 2026-03
DigitalOcean Spaces Production Credentials Exposed (Changera)

Production DO Spaces access key and secret present in bundle.

CVSS 8.0
African Fintech Remittance
Africa
Credential Exposure Responsible Disclosure High 2026-03
Risevest Admin Panel with KYC Management Exposed

Risevest admin panel reachable revealing KYC workflow and user management.

CVSS 8.0
African Investment Platform
Africa
Admin Panel Exposure Responsible Disclosure High 2026-03
Defguard VPN Panel Exposed 10+ Vulnerabilities (v1.3.1)

Defguard VPN v1.3.1 reachable publicly with 10+ known issues including open redirect and enum.

CVSS 8.0
African Fintech Remittance
Africa
Admin Panel Exposure Responsible Disclosure High 2026-03
Lokalise API Full Access - Translation Manipulation

Exposed Lokalise API token permits editing live translations across brand storefront.

CVSS 8.0
Saudi Gaming Marketplace
MENA
API Key Exposure Responsible Disclosure High 2026-03
vpn.[redacted].com - Admin Panel Source Map + Hardcoded Secret [HIGH]

Finding 1: vpn.[redacted].com - Admin Panel Source Map + Hardcoded Secret [HIGH] `vpn.[redacted].com` serves a full [redacted] Admin Panel (titled "[redacted] Admin" in HTML, `webpackJsonpvpn-governance`). Two source map files are publicly accessible, exposing the complete fronte

CVSS 7.8
SEA Fintech
SEA
Information Disclosure Responsible Disclosure High 2026-03
HIGH - Sub-Merchant PII Disclosure via listSubMerchantPF (VKN/TCKN/Address)

Finding 52: HIGH - Sub-Merchant PII Disclosure via listSubMerchantPF (VKN/TCKN/Address) Severity: High (CVSS 7.5 - AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) Summary: `/ccpayment/api/listSubMerchantPF` endpoint'i, TUM alt-uye isyeri PF kayitlarini VKN (Vergi Kimlik Numarasi), TCKN (TC

CVSS 7.8
Turkish Payment Gateway
MENA
Information Disclosure Responsible Disclosure High 2026-03
[redacted] SSRF Applepay

Apple Pay Web entegrasyonunda, merchant validation islemi icin browser tarafindan saglanan `validationURL` parametresi sunucuya gonderilir ve sunucu bu URL'ye POST istegi yapar. Normalde bu URL yalnizca `[target]` domain'lerine izin vermeli, ancak [redacted]'in imp

CVSS 7.8
African Payment Gateway
Africa
SSRF Responsible Disclosure High 2026-03
[HIGH] - Public API Documentation on [target]

Finding 5 [HIGH] - Public API Documentation on [target] Vulnerable Endpoint: `https://[target]` Summary: The full API reference documentation (Slate-generated) for the [redacted]/TCDX platform is publicly accessible on Alibaba Cloud OSS. The documentation d[redacted]

CVSS 7.8
SEA Crypto Exchange
SEA
Information Disclosure Responsible Disclosure High 2026-03
[HIGH] - [redacted] DSN Exposed + Event Injection Verified

Finding 6 [HIGH] - [redacted] DSN Exposed + Event Injection Verified Summary: The [redacted] DSN is exposed in the compiled JavaScript and accepts arbitrary event injection from any origin. DSN: `https://2f87dbe19e8c72da1531842a99ad4a9f@[target].[redacted].io/4509219002122240` - In

CVSS 7.8
DeFi Lending/DEX Protocol
Global
XSS Responsible Disclosure High 2026-03
— 30+ Production Microservices Publicly Accessible

Finding 2 — 30+ Production Microservices Publicly Accessible CVSS: 6.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:N) 30+ production microservices handling KYC, AML, identity verification, billing, and transaction monitoring are directly accessible from the public internet withou

CVSS 7.8
African KYC Provider
Africa
Auth Bypass Responsible Disclosure High 2026-03
Payment API Endpoints Accessible Without Authentication (HIGH)

Finding 5: Payment API Endpoints Accessible Without Authentication (HIGH) The payment service API exposes sensitive endpoints including order management, refund processing, and balance queries. While a signature is required, the signing key is already exposed (Finding 2). Accessi

CVSS 7.8
Gaming Marketplace
SEA
Access Control Responsible Disclosure High 2026-03
Mass Scan Lethal

Mass Scan — Lethal Findings Summary Total Lethal Findings (6 categories): 0 Only these 6 finding types were searched: 1. Database access (MongoDB, MySQL, PostgreSQL, Redis, MSSQL, CouchDB)

CVSS 7.8
Mass Scan
Global
Information Disclosure Responsible Disclosure High 2026-03
env.js Production Configuration Leak [HIGH]

Finding 3: env.js Production Configuration Leak [HIGH] - URL: `https://[target]/env.js` - Mixpanel token: `7f5f8bc7493a36e52f8b7218315ef5ca` - Flagsmith API key: `GPa6tcN2oZc4VbHzEPC5Yz`

CVSS 7.8
Crypto Fintech Mass Scan
Global
Firebase Misconfig Responsible Disclosure High 2026-03
[redacted] Wr841N Pentest

- `Secure` flag YOK (HTTP uzerinden iletilebilir) - `SameSite` attribute YOK (CSRF'e acik) 1. Ayni WiFi aginda ARP spoofing veya WiFi monitoring 2. HTTP traffic'i yakala (Wireshark/tcpdump)

CVSS 7.8
CCTV Infrastructure
Global
Information Disclosure Responsible Disclosure High 2026-03
Realtime XSS Mass Scan

Realtime Channel XSS Mass Scan Results Objective: Find crypto/fintech platforms where ALL users listen on a SINGLE realtime channel, and we can INJECT XSS via that channel ([target] pattern) Method: Passive JS bundle analysis, source map extraction, Pusher/Ably/[target] ch

CVSS 7.8
Mass XSS Scan
Global
Information Disclosure Responsible Disclosure High 2026-03
GrowthBook Base URL Override ([redacted]_CODE_GB_BASE_URL)

Finding 4: GrowthBook Base URL Override ([redacted]_CODE_GB_BASE_URL) Severity: Medium-High (CVSS 6.5) Summary: The `[redacted]_CODE_GB_BASE_URL` environment variable allows overriding the GrowthBook feature flag service URL. This enables a man-in-the-middle or local proxy to serve arbit

CVSS 7.8
AI SaaS Provider
NA
Information Disclosure Responsible Disclosure High 2026-03
dashboard.[redacted].com - Dashboard Source Map Exposure [HIGH]

Finding 3: dashboard.[redacted].com - Dashboard Source Map Exposure [HIGH] `dashboard.[redacted].com` is [redacted]'s client-facing dashboard for open banking operations. The source map exposes 591 source files with complete business logic for banking operations across Indonesia, Philippi

CVSS 7.8
SEA Fintech
SEA
Information Disclosure Responsible Disclosure High 2026-03
HIGH - CORS Wildcard on ALL 4 IMT Backend APIs (367 Endpoints Affected)

Finding 36: HIGH - CORS Wildcard on ALL 4 IMT Backend APIs (367 Endpoints Affected) Severity: High (CVSS 7.4 - AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N) Summary: 4 IMT backend API'nin TAMAMI `Access-Control-Allow-Origin: ` ve `Access-Control-Expose-Headers: ` ile yapilandirilmistir. B

CVSS 7.8
Turkish Payment Gateway
MENA
CORS Responsible Disclosure High 2026-03
Orm Injection Deep Exploitation

ORM Injection Deep Exploitation Report — [redacted].az Status: VERIFIED — Full password hash extraction demonstrated on production The `/tickets` endpoint on `api.[redacted].az` accepts arbitrary Dynamic LINQ expressions via the `SortField` parameter without authentication. Through a

CVSS 7.8
EU iGaming Operator
EU
SQLi Responsible Disclosure High 2026-03
[HIGH] - Admin Dashboard Full Source Code Exposure via Source Maps

Finding 1 [HIGH] - Admin Dashboard Full Source Code Exposure via Source Maps Summary: The admin dashboard at admin.[redacted].finance exposes JavaScript source maps containing the complete admin panel source code (171 files, 14.6MB total). This reveals all admin API endpoints, authenti

CVSS 7.8
DeFi Lending/DEX Protocol
Global
Information Disclosure Responsible Disclosure High 2026-03
— CORS Origin Reflection on 24+ Microservices (DEV + PRODUCTION)

Finding 1 — CORS Origin Reflection on 24+ Microservices (DEV + PRODUCTION) CVSS: 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N) 24 microservices across both development AND production environments reflect arbitrary Origin headers in their Access-Control-Allow-Origin response,

CVSS 7.8
African KYC Provider
Africa
CORS Responsible Disclosure High 2026-03
Firebase Storage PUBLIC Listing [HIGH]

Finding 2: Firebase Storage PUBLIC Listing [HIGH] - URL: `https://[target]/v0/b/[target]/o` - Impact: 998 files publicly listed (mostly bank logos/icons but includes .DS_Store) - POC: `curl -s "https://[target]

CVSS 7.8
Crypto Fintech Mass Scan
Global
Firebase Misconfig Responsible Disclosure High 2026-03
New Platforms Scan

New Crypto/Fintech Platforms Scan - 2026-03-26 Scan Summary (Round 2 - Crypto Exchanges + African Crypto) Platforms scanned: 30 NEW targets Platforms with critical findings: 1 (coinnest.africa - FULL COMPROMISE)

CVSS 7.8
Mixed Platforms
Global
Information Disclosure Responsible Disclosure High 2026-03
HIGH - ACL Email Enumeration via Login + Forgot Password Differential Response

Finding 34: HIGH - ACL Email Enumeration via Login + Forgot Password Differential Response Severity: High (CVSS 7.5 - AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) Summary: imt-acl.[redacted].[target] uzerindeki `/login` ve `/forgot-password` endpoint'leri, var olan ve var olmayan email adresler

CVSS 7.8
Turkish Payment Gateway
MENA
RCE Responsible Disclosure High 2026-03
[HIGH] - VPN Admin Brute Force: 5 Valid Employee Emails + Zero Rate Limit

Finding 28 [HIGH] - VPN Admin Brute Force: 5 Valid Employee Emails + Zero Rate Limit Summary: [target]/admin/auth endpoint'inde email enumeration ile 5 gecerli VPN admin hesabi tespit edildi. WordPress kullanici bilgileriyle cross-reference yapilarak 2 yeni hesap kesfedild

CVSS 7.8
SEA Crypto Exchange
SEA
Rate Limit Bypass Responsible Disclosure High 2026-03
EMA/Spot Price Divergence Excess Collateral Seizure in Lending Liquidation

Liquidation eligibility uses EMA price but collateral seizure uses spot price with no tolerance check, enabling liquidators to extract excess collateral during price divergence.

CVSS 7.5
Sui L1 Lending Protocol
Global
Oracle Manipulation Sherlock High 2026-03
Rate Limiter DoS via Cross-Segment Outflow Reduction Ineffectiveness

reduce_outflow only adjusts the current segment, so repay in a later segment leaves the limiter saturated, blocking borrows and withdrawals.

CVSS 7.5
Sui L1 Lending Protocol
Global
Business Logic Sherlock High 2026-03
Bridge Fee Quoted From User-Supplied Slippage Minimum

Router quotes bridge fee using attacker-controlled minTrustOut but bridges post-swap amountOut, causing underpaid fees or reverts.

CVSS 7.5
Ethereum Attestation Protocol
Global
Business Logic Code4rena High 2026-03
Legal Documents Bucket Public Listing With 22 User UUIDs

Second bucket exposes 75+ objects and 22 user UUIDs enabling targeted PII correlation.

CVSS 7.5
African Crypto Exchange
Africa
S3 Misconfig Responsible Disclosure High 2026-03
Full Source Code + .git Repository Exposure on Static Site

Static site serves Express.js source and .git config revealing developer GitHub URL and root-process runtime.

CVSS 7.5
African Crypto Exchange
Africa
Information Disclosure Responsible Disclosure High 2026-03
Mass User Enumeration Reveals 232,800+ User Profiles

Unauth trader lookup reveals KYC country vs profile country mismatches and sequential user IDs.

CVSS 7.5
Global P2P Crypto Marketplace
Global
Information Disclosure Responsible Disclosure High 2026-03
Vite Manifest + Source Map Exposure 299 Vue Components

manifest.json downloads reveal 299 Vue component entries and SPA routing table.

CVSS 7.5
Global P2P Crypto Marketplace
Global
Information Disclosure Responsible Disclosure High 2026-03
ArgoCD v2.14.8 Settings Leak with execEnabled:true

ArgoCD settings endpoint exposes execEnabled true and cluster overrides enabling pod exec potential.

CVSS 7.5
SEA Banking API Platform
SEA
Admin Panel Exposure Responsible Disclosure High 2026-03
Source Map Exposure 10 Products 782.5 MB 748 Maps

Ten product frontends serve source maps totaling 782.5MB revealing API logic and internal endpoints.

CVSS 7.5
SEA Banking API Platform
SEA
Information Disclosure Responsible Disclosure High 2026-03
Public GCS Buckets: 6 of 17 Anonymously Listable

Six GCS buckets allow anonymous object listing including transaction artifacts.

CVSS 7.5
SEA Banking API Platform
SEA
Cloud Misconfig Responsible Disclosure High 2026-03
Complete Admin Panel API Architecture Exposed (65+ Endpoints)

Admin JS bundle enumerates 65+ backend endpoints with parameter templates.

CVSS 7.5
African Fintech Neobank
Africa
Information Disclosure Responsible Disclosure High 2026-03
Source Map Exposure on 3 Staging Apps (944 Source Files)

Three staging apps ship maps with 944 source files revealing auth flow and secrets.

CVSS 7.5
African Crypto Exchange
Africa
Information Disclosure Responsible Disclosure High 2026-03
Intercom Identity Verification HMAC Secret Exposed

Intercom HMAC secret allows attacker to generate valid identity hashes for any user ID.

CVSS 7.5
African Crypto Exchange
Africa
Credential Exposure Responsible Disclosure High 2026-03
Metabase v0.57.7.2 Setup Token + API Docs + Reset Oracle

Metabase exposes setup token, 303-endpoint docs, password reset oracle and weak password validator without auth.

CVSS 7.5
African Crypto Exchange
Africa
Admin Panel Exposure Responsible Disclosure High 2026-03
Intercom Identity Verification HMAC Secret Exposed (Bitmama)

Intercom HMAC secret allows generating identity hashes for any user_id.

CVSS 7.5
African Crypto Exchange
Africa
Credential Exposure Responsible Disclosure High 2026-03
Full Application Source Code Exposure via Source Maps (Bitmama)

Dashboard + admin total 1081 source files (36MB) exposed publicly.

CVSS 7.5
African Crypto Exchange
Africa
Information Disclosure Responsible Disclosure High 2026-03
Six API Keys/Secrets Hardcoded in Production JavaScript

Production bundle contains six vendor API keys including real-time messaging and analytics.

CVSS 7.5
African Crypto Exchange
Africa
API Key Exposure Responsible Disclosure High 2026-03
RabbitMQ Management Console Exposed to Internet

Production RabbitMQ Management UI reachable publicly.

CVSS 7.5
African Crypto Exchange
Africa
Admin Panel Exposure Responsible Disclosure High 2026-03
Soketi Self-Hosted Pusher Key Exposed + Real-Time Message Interception

Base64 Pusher key discoverable publicly allowing real-time channel subscription.

CVSS 7.5
African Crypto Exchange
Africa
WebSocket Issues Responsible Disclosure High 2026-03
23MB Source Map Application Code Exposure (2752 Files)

Single app build ships 23MB source map exposing 2752 source files.

CVSS 7.5
African Crypto Exchange
Africa
Information Disclosure Responsible Disclosure High 2026-03
wsorder.bitbns.com CORS Origin Reflection on Trade Engine

Trade engine reflects arbitrary origin with credentials on WebSocket handshake.

CVSS 7.5
Indian Crypto Exchange
SEA
CORS Responsible Disclosure High 2026-03
AES Encryption Secret Key Exposed (Client-Side Crypto Broken)

Single static AES secret used for client-side request encryption disclosed in JS.

CVSS 7.5
African Fintech Remittance
Africa
Credential Exposure Responsible Disclosure High 2026-03
Roqqu KYC System Source Map Exposure

KYC system source map downloadable exposing verification routes.

CVSS 7.5
African Crypto Exchange
Africa
Information Disclosure Responsible Disclosure High 2026-03
Dojah.io Full Application Source Code via Source Maps

Dojah KYC provider ships source maps revealing internal verification logic.

CVSS 7.5
African KYC Provider
Africa
Information Disclosure Responsible Disclosure High 2026-03
Unauthenticated Platform Settings Dump (36 Anomaly Thresholds)

Settings endpoint exposes 36 risk thresholds unauth, enabling fraud-rule evasion.

CVSS 7.5
African Fintech Remittance
Africa
Information Disclosure Responsible Disclosure High 2026-03
3 Admin Source Maps Publicly Accessible (17.9MB Source)

Three admin bundles ship source maps totaling 17.9MB.

CVSS 7.5
African Fintech Remittance
Africa
Information Disclosure Responsible Disclosure High 2026-03
SonarQube v10.6.0 Exposed with CVE-2024-47004

SonarQube version vulnerable to CVE-2024-47004 reachable publicly.

CVSS 7.5
African Fintech Remittance
Africa
Admin Panel Exposure Responsible Disclosure High 2026-03
Swagger UI Publicly Accessible on API Subdomain

api.coincola.com exposes Swagger UI enumerating all routes.

CVSS 7.5
Global P2P Crypto Marketplace
Global
Information Disclosure Responsible Disclosure High 2026-03
Advertisement IDOR Reveals 170K Ads Without Auth

Sequential ad enumeration dumps ~170,000 advertisements including counterparty profile fragments.

CVSS 7.5
Global P2P Crypto Marketplace
Global
IDOR Responsible Disclosure High 2026-03
S3 Bucket coincola.user Exposed

Named user bucket discovered with public metadata reachable.

CVSS 7.5
Global P2P Crypto Marketplace
Global
S3 Misconfig Responsible Disclosure High 2026-03
Alibaba Cloud OSS Bucket PUBLIC READ Confirmed

NoSuchKey (vs AccessDenied) response confirms bucket ACL permits public object read.

CVSS 7.5
Global P2P Crypto Marketplace
Global
Cloud Misconfig Responsible Disclosure High 2026-03
Wazuh SIEM Dashboard Public

Wazuh guards.obiex.finance reachable publicly exposing security telemetry.

CVSS 7.5
African Fintech Crypto Exchange
Africa
Admin Panel Exposure Responsible Disclosure High 2026-03
MinIO Bucket Enumeration Reveals kyc/payments/users

Multiple sensitive buckets (kyc, documents, payments, users, backup) confirmed present via 403.

CVSS 7.5
Gaming Marketplace
EU
Cloud Misconfig Responsible Disclosure High 2026-03
AdminJS Database Admin Panel Publicly Reachable

db-admin.blix.gg hosts AdminJS providing direct DB access via login.

CVSS 7.5
Gaming Marketplace
EU
Admin Panel Exposure Responsible Disclosure High 2026-03
GitLab Open Registration + Pipeline Trigger Token

source.la3eb.com allows public GitLab sign-up giving read access to internal projects.

CVSS 7.5
Saudi Gaming Marketplace
MENA
Admin Panel Exposure Responsible Disclosure High 2026-03
SuperAdmin ID Hardcoded + TOTP URI Pattern Leaked

Hardcoded SuperAdmin ID 19 and TOTP URI pattern leaked enabling targeted 2FA reset.

CVSS 7.5
Gaming Recharge Platform
SEA
Credential Exposure Responsible Disclosure High 2026-03
Grafana v12.3.0 Public + Strapi CMS Admin Public

gcbuying ships Grafana and Strapi CMS admin reachable unauthenticated.

CVSS 7.5
Nigerian Gift Card Marketplace
Africa
Admin Panel Exposure Responsible Disclosure High 2026-03
Internal Azure Backend Exposed

PlayerAuctions toolsadmin Azure backend hostname reachable with decompiled React source (1.9MB).

CVSS 7.5
Global Gaming Marketplace
Global
Admin Panel Exposure Responsible Disclosure High 2026-03
CORS Wildcard on Gateway (Laravel + Auth Header Reflection)

gateway.smile.one allows any origin with Authorization header exposure.

CVSS 7.5
SEA Game Recharge Platform
SEA
CORS Responsible Disclosure High 2026-03
Dev Environment Public With K8s Horizon Endpoints

prestmit.io Laravel dev exposes Horizon queue endpoints and no reset throttle.

CVSS 7.5
African Crypto Swap Platform
Africa
Admin Panel Exposure Responsible Disclosure High 2026-03
Sonata Admin Panel + Web Debug Toolbar Exposed

hot.game exposes Sonata /admin/login and Symfony _wdt toolbar in production.

CVSS 7.5
Gaming Marketplace
Global
Admin Panel Exposure Responsible Disclosure High 2026-03
Laravel Ignition Endpoints Active (CVE-2021-3129 Potential)

zeusx.com ships Ignition endpoints enabling potential RCE per CVE-2021-3129.

CVSS 7.5
Game Top-Up Platform
Global
Information Disclosure Responsible Disclosure High 2026-03
Operation Admin Panel Publicly Reachable

cardgoal.com operation admin UI reachable without IP restriction.

CVSS 7.5
Gaming Marketplace
SEA
Admin Panel Exposure Responsible Disclosure High 2026-03
Telegram Document Upload Abuse

Unauth /Document/UploadFileToTelegram enables spam/abuse through platform bot.

CVSS 7.5
African Crypto Trading Platform
Africa
File Upload Responsible Disclosure High 2026-03
Google OAuth Client ID Exposed + Admin SSO Loopholes

Production Google OAuth client id embedded; admin SSO reachable over origin.

CVSS 7.5
Asian Gift-Card Marketplace
SEA
Credential Exposure Responsible Disclosure High 2026-03
Tencent COS Bucket Public Listing

Multiple Tencent COS buckets allow anonymous listing exposing order files.

CVSS 7.5
Asian Gift-Card Marketplace
SEA
Cloud Misconfig Responsible Disclosure High 2026-03
PIM Admin Panel WASM DLL Source Code Disclosure

Blazor WebAssembly DLLs decompilable exposing 70+ internal admin routes + game key architecture.

CVSS 7.5
EU Gaming Marketplace
EU
Information Disclosure Responsible Disclosure High 2026-03
Prometheus Metrics 14,754 Lines Exposure

14,754-line Prometheus metrics endpoint reveals DB names, routes, backends.

CVSS 7.5
EU iGaming Operator
EU
Information Disclosure Responsible Disclosure High 2026-03
AWS ElastiCache Internal IP Leaked via Actuator

Actuator metrics leak Redis ElastiCache internal IP endpoint.

CVSS 7.5
EU iGaming Operator
EU
Information Disclosure Responsible Disclosure High 2026-03
WordPress REST API CORS Origin Reflection + credentials:true

353 routes reflect any Origin and allow credentials, enabling cross-origin account takeover.

CVSS 7.5
European Crypto Payment Gateway
EU
CORS Responsible Disclosure High 2026-03
Shopware6 Webhook CSRF Protection Disabled

Webhook endpoint explicitly opts out of CSRF protection, compounding the absent token validation.

CVSS 7.5
European Crypto Payment Processor
EU
Access Control Responsible Disclosure High 2026-03
Missing HMAC/Signature Across All Plugins

No cryptographic signature header on webhook callbacks across 6 e-commerce plugins; unlike Stripe/PayPal.

CVSS 7.5
European Crypto Payment Processor
EU
Webhook Forgery Responsible Disclosure High 2026-03
GraphQL Introspection Cluster Finding

Multiple crypto exchanges expose full GraphQL introspection enabling schema extraction.

CVSS 7.5
Global Crypto Broker Cluster
Global
GraphQL Issues Responsible Disclosure High 2026-03
Infura API Key Exposed on Minor Exchange

Production Infura key embedded in client SPA and valid for mainnet requests.

CVSS 7.5
Global Crypto Broker Cluster
Global
API Key Exposure Responsible Disclosure High 2026-03
Laravel Nova Admin Panel Staging Exposes 65+ Resource Models

Public Laravel Nova admin staging discloses complete resource model inventory across user, trade and wallet domains.

CVSS 7.5
Nigerian Gift Card Platform
Africa
Admin Panel Exposure Responsible Disclosure High 2026-03
Nova Admin Source Maps Publicly Accessible (9.9MB, 1574 files)

Production Nova bundles ship with .map files revealing 1574 source files and internal API client code.

CVSS 7.5
Nigerian Gift Card Platform
Africa
Information Disclosure Responsible Disclosure High 2026-03
Kubernetes KEDA HTTP Add-on Metadata Exposure via Headers

KEDA HTTPScaledObject emits x-keda-http-cold-start headers exposing cluster internal routing metadata.

CVSS 7.5
Nigerian Gift Card Platform
Africa
Information Disclosure Responsible Disclosure High 2026-03
Hardcoded AES-CBC Initialization Vector Across Devices

Firmware ships identical AES-CBC IV across fleet enabling cross-device ciphertext manipulation.

CVSS 7.5
CCTV Infrastructure
Global
Credential Exposure Responsible Disclosure High 2026-03
Session Key Architecture Disclosed in Source

Source map reveals session key rotation logic and internal key derivation parameters.

CVSS 7.5
African Payment Gateway
Africa
Credential Exposure Responsible Disclosure High 2026-03
Full Source Code Exposure via Source Maps (670 Files)

Production build emits source maps reconstructing 670 TypeScript files with business logic.

CVSS 7.5
African P2P Crypto Platform
Africa
Information Disclosure Responsible Disclosure High 2026-03
Unauthenticated OTP Flooding via GraphQL getLoyaltyOtp

GraphQL mutation permits unlimited OTP send to arbitrary accounts enabling SMS bombing.

CVSS 7.5
MENA Travel Fintech
MENA
Rate Limit Bypass Responsible Disclosure High 2026-03
Spring Boot Actuator /actuator/health Exposes Infrastructure

Actuator health subpaths reveal database type, circuit breaker state and internal hostnames.

CVSS 7.5
EU Student Banking Fintech
EU
Information Disclosure Responsible Disclosure High 2026-03
Internal Production Load Balancer Accessible from Internet

Internal LB with prod-lb hostname is reachable publicly bypassing API gateway security controls.

CVSS 7.5
EU Student Banking Fintech
EU
Cloud Misconfig Responsible Disclosure High 2026-03
Pre-Auth User Existence Oracle via /v3/customers/{id}

Differential 401 vs 404 responses reveal whether a numeric customer ID exists enabling mass enumeration.

CVSS 7.5
EU Student Banking Fintech
EU
Information Disclosure Responsible Disclosure High 2026-03
Unauthenticated Aion Banking Configuration Disclosure

Public configuration endpoint leaks AML high-risk country list and banking agreement metadata.

CVSS 7.5
EU Student Banking Fintech
EU
Information Disclosure Responsible Disclosure High 2026-03
Broken Access Control on All Content APIs

All content APIs return catalogue and stream URLs without authentication.

CVSS 7.5
CIS Streaming Platform
MENA
Access Control Responsible Disclosure High 2026-03
Admin Control Tower Source Map Exposure (123 Files)

Admin Tower panel ships source maps revealing internal compliance, auth and payments endpoints.

CVSS 7.5
LATAM Crypto Exchange
LATAM
Information Disclosure Responsible Disclosure High 2026-03
Complete Internal SDK Extracted - 166 Endpoints

Malcolm SDK embedded in bundle reveals 166 internal endpoints across 48 service classes.

CVSS 7.5
LATAM Crypto Exchange
LATAM
Information Disclosure Responsible Disclosure High 2026-03
Sentry DSN Exposed with Event Injection

Sentry DSN in client accepts arbitrary events enabling log pollution and admin phishing via crafted payloads.

CVSS 7.5
DeFi DEX Protocol
Global
Information Disclosure Responsible Disclosure High 2026-03
CF Pages Branch Deployments Publicly Accessible

Cloudflare Pages preview builds served without access policy expose pre-release staging configurations.

CVSS 7.5
DeFi DEX Protocol
Global
Information Disclosure Responsible Disclosure High 2026-03
Kubernetes Internal Service Name Leak via Envoy Headers

Envoy decorator headers leak Kubernetes internal service names revealing cluster service map.

CVSS 7.5
DeFi DEX Protocol
Global
Information Disclosure Responsible Disclosure High 2026-03
Internal API Documentation on Public Apidog

Internal API documentation published to public Apidog workspace exposing architecture.

CVSS 7.5
African Gift Card Platform
Africa
Information Disclosure Responsible Disclosure High 2026-03
OpenVPN-AS Server Publicly Accessible

OpenVPN access server reachable from internet enabling credential stuffing for corporate VPN access.

CVSS 7.5
African Utility Payment Platform
Africa
Admin Panel Exposure Responsible Disclosure High 2026-03
Admin Panels Publicly Accessible

Admin dashboards lack IP restriction and expose login portals to internet.

CVSS 7.5
African DeFi Platform
Africa
Admin Panel Exposure Responsible Disclosure High 2026-03
Production Source Maps Exposed

Crypto investment platform emits production source maps exposing frontend source.

CVSS 7.5
European Crypto Investment Platform
EU
Information Disclosure Responsible Disclosure High 2026-03
Admin Staging Panel Exposed

Staging admin panel reachable without IP restriction with pre-release features exposed.

CVSS 7.5
African Remittance Platform
Africa
Admin Panel Exposure Responsible Disclosure High 2026-03
Email Enumeration via Registration API

POST /api/auth/register endpointi mevcut ve mevcut olmayan email adresleri icin farkli hata mesajlari donduruyor. Bu, saldirganin platform uzerindeki tum kayitli kullanicilarin email adreslerini dogrulayabilmesini saglar

CVSS 7.5
African Remittance Platform
Africa
Business Logic Responsible Disclosure High 2026-03
Okta DEV Tenant Serving Production Authentication

The production login portal at login.[vendor] is backed by an Okta tenant named my-[vendor]-dev, explicitly indicating a DEVELOPMENT environment is serving production authentication. The admin panel at my-[vendor]-dev-admin.okta.com is accessible and redirects to OIDC SSO login

CVSS 7.5
SEA Gaming Marketplace
SEA
Admin Panel Exposure HackerOne High 2026-03
Subdomain Takeover: img.[vendor] (Dangling WP Engine CNAME)

The subdomain img.[vendor] has a CNAME record pointing to 2y6hw8438dr81ty1hegbtle9.wpengine.netdna-cdn.com which no longer resolves (SERVFAIL). This dangling CNAME allows an attacker to claim the WP Engine CDN endpoint and serve arbitrary content under the [vendor] domain

CVSS 7.5
NA Gift Card Supplier
NA
Subdomain Takeover Responsible Disclosure High 2026-03
Laravel Telescope Debug Dashboard Publicly Accessible on Staging

The staging environment at staging.[vendor] exposes Laravel Telescope at /telescope without any authentication. Telescope is a debug/monitoring tool that records HTTP requests, database queries, exceptions, mail, cache operations, Redis commands, scheduled tasks, model changes, and more. This provides an attacker with deep visibility into the a

CVSS 7.5
SEA E-Commerce Platform
SEA
Broken Authentication Responsible Disclosure High 2026-03
Disable WP_DEBUG in production

<FilesMatch "\.(save|bak|old|orig|swp|~)$"> Require all denied </FilesMatch>

CVSS 7.5
SEA E-Commerce Platform
SEA
Information Disclosure Responsible Disclosure High 2026-03
Source Map Exposure - Full Application Source Code (HIGH)

Finding 4: Source Map Exposure - Full Application Source Code (HIGH) JavaScript source maps (.js.map) are exposed on ALL environments (production, staging, admin, agent), revealing the complete application source code including API endpoints, authentication logic, business logic,

CVSS 7.5
EU iGaming Operator
EU
Information Disclosure Responsible Disclosure High 2026-03
Gambling Web3 Scan

Gambling / Web3 / Gaming Marketplace Mass Scan - 2026-03-29 40+ gambling, betting, NFT, Web3, and gaming marketplace platforms scanned. 5 platforms with verified data exposure findings. Total: 3 HIGH + 4 MEDIUM + 3 LOW = 10 verified findings.

CVSS 7.5
Global Casino/DeFi
Global
Information Disclosure Responsible Disclosure High 2026-03
Local Network Arp Audit

Test Makinasi: [ip] (macOS Darwin 25.2.0, en0) Yetkilendirme: Authorized pentest [ip]/24 yerel agindan 6 guvenlik bulgusu tespit edildi. En kritik bulgu, test makinasinda IP forwarding'in aktif olmasi ve gateway ARP kaydinin statik (permanent) olarak tanimlanm

CVSS 7.5
Local Network Scan
Global
RCE Responsible Disclosure High 2026-03
Me Tr Scan

Orta Dogu ve Turkiye Kripto/Fintech/Bahis Platformlari - Veri Sizintisi Taramasi Scope: ME/TR kripto borsalari, fintech, odeme sistemleri, bahis platformlari Toplam Taranan Hedef: 80+ platform, 10 hedef derinlemesine tarama | Platform | Bulgu | Severity | Detay |

CVSS 7.5
MENA/TR Mass Scan
MENA
CORS Responsible Disclosure High 2026-03
User Enumeration via Password Reset Endpoint

Finding 3: User Enumeration via Password Reset Endpoint Severity: HIGH (CVSS 7.5 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) Summary: `password_reset/` endpoint'i kayitli ve kayitsiz email adresleri icin FARKLI yanit donduruyor. Kayitli email icin `{"status":"OK"}`, kayitsiz

CVSS 7.5
NA Online Casino
NA
Rate Limit Bypass Responsible Disclosure High 2026-03
MinIO S3 Bucket Public Listing - `images` Bucket (HIGH)

Finding 2: MinIO S3 Bucket Public Listing - `images` Bucket (HIGH) URL: https://cdn.blix.gg/images/ `images` bucket'i anonymous listing'e acik. S3 ListBucketResult XML formatinda tum dosyalar listeleniyor. 1000+ obje (IsTruncated: true), owner ID exposed. - collection/ - CS2 kole

CVSS 7.5
KYC Mass Scan
Global
S3 Misconfig Responsible Disclosure High 2026-03
Tolgee User/Organization Data Exposure

Finding 5: Tolgee User/Organization Data Exposure Type: CWE-200 (Information Exposure) 6 Entravel Developers — Full Profiles (NO MFA on any account) | ID | Name | Email | Role | MFA |

CVSS 7.5
Global Crypto Exchange
Global
Broken Authentication Responsible Disclosure High 2026-03
Svix Webhook Dashboard Token Leak via webhookLogin Query

Finding 1: Svix Webhook Dashboard Token Leak via webhookLogin Query `webhookLogin` GraphQL query'si Svix webhook yonetim platformuna tam erisim saglayan API token ve one-time login URL donduruyor. Bu token ile: - Tum webhook endpoint'leri listelenebilir - Webhook mesaj gecmisi (p

CVSS 7.5
African Payment Gateway
Africa
Credential Exposure Responsible Disclosure High 2026-03
SSL Certificate Pinning Keys + Internal Config Exposed via Public API

Finding 41: SSL Certificate Pinning Keys + Internal Config Exposed via Public API Endpoint: `GET https://www.[redacted].com/v1/common/system-config` Status: VERIFIED - Data returned without authentication The exchange's public `/v1/common/system-config` endpoint returns critical

CVSS 7.5
SEA Crypto Exchange
SEA
WebSocket Issues Responsible Disclosure High 2026-03
Unrestricted File Upload with PHP Short Tag Injection (HIGH)

Finding 1: Unrestricted File Upload with PHP Short Tag Injection (HIGH) CVSS: 7.5 (High) - AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N The `/Faq/uploadFeedbackImg.html` endpoint accepts file uploads with the field name `feedback_img`. While it restricts file extensions to image types (jp

CVSS 7.5
Gaming Marketplace
SEA
File Upload Responsible Disclosure High 2026-03
No HTTPS - All Credentials in Plaintext Over HTTP

Finding 4: No HTTPS - All Credentials in Plaintext Over HTTP CVSS Vector: AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N Router yonetim paneli HTTPS destegi sunmuyor. RSA+AES encryption client-side yapilsa da, 512-bit RSA kolayca kirilabildigi icin (Finding 2), pratikte tum credential'lar p

CVSS 7.5
CCTV Infrastructure
Global
Credential Exposure Responsible Disclosure High 2026-03
[redacted]_BASE_URL Override for API Endpoint Hijacking

Finding 5: [redacted]_BASE_URL Override for API Endpoint Hijacking Severity: High (CVSS 7.5) - already documented but noteworthy Summary: The `[redacted]_BASE_URL` environment variable (found active in `~/.zshrc`) allows complete API endpoint redirection. Combined with `[redacted]_A

CVSS 7.5
AI SaaS Provider
NA
RCE Responsible Disclosure High 2026-03
168 Gaming Platform Credentials Exposed via Public Endpoint

Finding 2: 168 Gaming Platform Credentials Exposed via Public Endpoint Severity: High (CVSS 7.5 - AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) The endpoint `/api/products/demo-accounts` returns 168 plaintext username/password combinations for 36 different gaming platforms without any aut

CVSS 7.5
NA Online Casino
NA
Credential Exposure Responsible Disclosure High 2026-03
22/26 Scopes Granted with Empty Client Secret

Finding 2: 22/26 Scopes Granted with Empty Client Secret Test client ID `test-195944A9-E957-4532-B574-D37BD5FD9297` bos client_secret ile 26 scope'un 22'sini grant ediyor. Bu scope'lar `pci_unsafe`, `client_vault_manage`, `client_vault_proxy`, `client_disbursement`, `client_merch

CVSS 7.5
African Payment Gateway
Africa
Credential Exposure Responsible Disclosure High 2026-03
Cloudflare WAF Bypass via Direct Origin IP Access

Origin IP reachable directly, bypassing WAF rules on all API endpoints.

CVSS 7.4
African Crypto Exchange
Africa
Cloud Misconfig Responsible Disclosure High 2026-03
HTTP Basic Auth Fallback with Credentials in SessionStorage

Device accepts HTTP Basic fallback and stores AES-encrypted credentials in sessionStorage subject to XSS exfil.

CVSS 7.4
CCTV Infrastructure
Global
Broken Authentication Responsible Disclosure High 2026-03
Wildcard DNS btmops.xyz Exposes Complete Infrastructure Topology

Wildcard DNS resolves every subdomain to a single Caddy host revealing all hosted services.

CVSS 7.3
African Crypto Exchange
Africa
Information Disclosure Responsible Disclosure High 2026-03
Segment Analytics Write Key Exposed — Event Injection Verified

Segment Write Key (2hfUaoiBcaEUEyqjaYb5biu56ARGjcL3) Hardcoded in Client JS — Arbitrary Event/User Injection into [vendor]Analytics Pipeline

CVSS 7.3
LATAM Crypto Platform
LATAM
Credential Exposure HackerOne High 2026-03
Security Finding

FINDING 21: Smart Contract -- Rounding Direction Error in Withdraw (MEDIUM) All four `_withdrawSomeX()` functions use `.add(1)` (ceiling rounding), withdrawing 1 extra token unit from lenders per withdrawal. This benefits the withdrawer at the vault's expense. FINDING 22: Verbose

CVSS 7.3
African DeFi Protocol
Africa
Reentrancy Responsible Disclosure High 2026-03
Hardcoded AES Key Derivation Salt Shared Across All Devices

All camera units share the same AES key-derivation salt, weakening password-based secrets platform-wide.

CVSS 7.2
CCTV Infrastructure
Global
Credential Exposure Responsible Disclosure High 2026-03
Chatwoot Super Admin Panel Publicly Accessible

The Chatwoot instance at support.[vendor] exposes its Super Admin login panel at /super_admin/sign_in without any IP restriction or additional authentication layer. The Super Admin panel provides full control over all Chatwoot accounts, agents, conversations, and configuration

CVSS 7.2
NA Gift Card Supplier
NA
Admin Panel Exposure Responsible Disclosure High 2026-03
LiteSpeed WebAdmin Console Publicly Exposed (HIGH)

Finding 3: LiteSpeed WebAdmin Console Publicly Exposed (HIGH) Origin sunucu ([ip]) üzerinde LiteSpeed WebAdmin Console port 7080'de herhangi bir IP kısıtlaması olmadan internet'e açık. Brute-force saldırısı ile admin erişimi elde edilebilir. `https://[ip]:7080/l

CVSS 7.2
Web Hosting Provider
EU
Default Creds Responsible Disclosure High 2026-03
Sentry DSN Exposure + Event Injection 2 Projects

Dashboard and Pay production Sentry DSN keys exposed allowing event injection and quota exhaustion.

CVSS 7.1
European Crypto Payment Gateway
EU
Credential Exposure Responsible Disclosure High 2026-03
Internal Admin Redirect URI Leaked

OAuth redirect URI for internal admin SSO leaked permitting phishing-style redirect abuse.

CVSS 7.1
African Payment Gateway
Africa
Information Disclosure Responsible Disclosure High 2026-03
Avalanche RPC CORS Wildcard with Credentials

Avalanche RPC proxy returns wildcard Origin with credentials enabling cross-origin RPC calls from any site.

CVSS 7.1
DeFi DEX Protocol
Global
CORS Responsible Disclosure High 2026-03
ADL Safety Mechanism Neutralized via Trivial Repayment in EMode Group

Activation checks global reserve debt while deactivation checks emode-group debt, so any small repay deactivates ADL prematurely.

CVSS 7.0
Sui L1 Lending Protocol
Global
Business Logic Sherlock High 2026-03
WordPress XMLRPC Brute Force Amplification

wp xmlrpc.php returns verbose auth errors with no lockout, enabling fast password brute force.

CVSS 7.0
Global P2P Crypto Marketplace
Global
Rate Limit Bypass Responsible Disclosure High 2026-03
gRPC Reflection on All Production Services (200+ Endpoints)

Reflection enabled on every production gRPC service disclosing 200+ RPC methods.

CVSS 7.0
SEA Banking API Platform
SEA
Information Disclosure Responsible Disclosure High 2026-03
Grafana 12.0.0 Public /metrics Exposes 39 Users and 23 Datasources

Unauth /metrics endpoint leaks user inventory and datasource topology.

CVSS 7.0
SEA Banking API Platform
SEA
Information Disclosure Responsible Disclosure High 2026-03
Production Runtime Config Exposed via /config Endpoints

Multiple services expose /config endpoints returning sensitive runtime configuration.

CVSS 7.0
SEA Banking API Platform
SEA
Information Disclosure Responsible Disclosure High 2026-03
Feature Toggle Bypass via Query Parameters

Query param ?ff=xyz enables hidden product features bypassing server-side toggle.

CVSS 7.0
SEA Banking API Platform
SEA
Business Logic Responsible Disclosure High 2026-03
Sentry DSN Exposed in Admin Panel Event Injection Verified

Admin Sentry DSN accepts arbitrary crash events, enabling operator-facing log poisoning.

CVSS 7.0
African Fintech Neobank
Africa
Information Disclosure Responsible Disclosure High 2026-03
Firebase Configuration Exposed With Full Project Details

Web app leaks Firebase web config enabling direct Firestore queries.

CVSS 7.0
African Fintech Neobank
Africa
Firebase Misconfig Responsible Disclosure High 2026-03
Airtable API Key With CREATE Permissions on 7 Bases

Airtable key grants write access to seven business-critical bases via exposed secret.

CVSS 7.0
African Crypto Exchange
Africa
API Key Exposure Responsible Disclosure High 2026-03
Bull Board Job Queue Metrics Unauthenticated

Bull Board exposes queue metrics unauth leaking internal job parameters.

CVSS 7.0
African Fintech Remittance
Africa
Admin Panel Exposure Responsible Disclosure High 2026-03
Azure AD Tenant + Client ID Leak

PlayerAuctions admin JS leaks Azure AD tenant and client IDs.

CVSS 7.0
Global Gaming Marketplace
Global
Credential Exposure Responsible Disclosure High 2026-03
Merchant Integration API Docs Fully Open

Merchant docs enumerate signing scheme and endpoint list without auth.

CVSS 7.0
SEA Game Recharge Platform
SEA
Information Disclosure Responsible Disclosure High 2026-03
5 AWS S3 Buckets Including cdn-user-photo

zeusx.com references 5 S3 buckets including one named for user photos / KYC.

CVSS 7.0
Game Top-Up Platform
Global
S3 Misconfig Responsible Disclosure High 2026-03
Swagger API + Postman Collection Fully Open

kopazar.com exposes Swagger docs and Postman collection revealing full API shape.

CVSS 7.0
Turkish E-Pin Marketplace
EU
Information Disclosure Responsible Disclosure High 2026-03
PAYMAPI Payment API Documentation Fully Open

epin.com.tr exposes PAYMAPI documentation listing all payment endpoints.

CVSS 7.0
Turkish Payment Processor
EU
Information Disclosure Responsible Disclosure High 2026-03
Grafana Faro APM Key Valid – Telemetry Injection Verified

Client-side APM key accepts arbitrary telemetry enabling alert fatigue and alert-based phishing.

CVSS 6.5
SEA Banking API Platform
SEA
Information Disclosure Responsible Disclosure High 2026-03
Bugsnag and Datadog Client Tokens in Source Map

Observability client tokens leaked enabling abuse of monitoring SaaS billing.

CVSS 6.5
African Payment Gateway
Africa
API Key Exposure Responsible Disclosure High 2026-03
Document Upload and Payment Endpoints Accept Unauthenticated Requests

Multiple KYC document and payment endpoints return 500 instead of 401 indicating missing auth check upstream.

CVSS 6.5
EU Student Banking Fintech
EU
Access Control Responsible Disclosure High 2026-03
Partner Portal Source Map Exposure

Partner portal ships source maps revealing internal partner API configuration.

CVSS 5.3
LATAM Crypto Platform
LATAM
Information Disclosure Responsible Disclosure High 2026-03
Mailigen Webhook Signature Bypass on Payment Gateway

Mailigen webhook accepts unsigned payloads, allowing attackers to inject email events and alter subscriber state.

CVSS 7.5
European Payment Gateway
EU
Webhook Forgery Responsible Disclosure Medium 2026-04
Payment Gateway Admin Panel Publicly Accessible

Ginger admin panel reachable from the internet without IP allowlist, exposing privileged administration UI.

CVSS 7.5
European Payment Gateway
EU
Admin Panel Exposure Responsible Disclosure Medium 2026-04
Unprotected KYC Webhook (SumSub)

The SumSub KYC webhook endpoint accepts POST requests without signature verification on both PROD and TEST

CVSS 6.8
EU Crypto Exchange
EU
KYC Bypass HackerOne Medium 2026-04
Development Configuration Exposed in Production Frontend

dev.*, auth-test.*, localhost URLs embedded in production build reveal internal staging hosts and environment layout.

CVSS 6.5
European Payment Gateway
EU
Information Disclosure Responsible Disclosure Medium 2026-04
AWS Cognito UserPoolId and ClientId Hardcoded in Frontend

Cognito pool and client IDs shipped in frontend allow unauthenticated signup and enumeration against the user pool.

CVSS 6.5
European Payment Gateway
EU
Credential Exposure Responsible Disclosure Medium 2026-04
Sub-Cent Product Pricing via Decimal Quantity Manipulation

Decimal quantity in line items rounds prices below cent, enabling goods purchase at trivial value.

CVSS 6.5
European Payment Gateway
EU
Business Logic Responsible Disclosure Medium 2026-04
Internal Worldline Gateway Endpoints Publicly Accessible

Internal Worldline integration endpoints exposed on public API subdomain, leaking partner architecture.

CVSS 6.5
European Payment Gateway
EU
Admin Panel Exposure Responsible Disclosure Medium 2026-04
Outdated Software Stack With Known CVEs

commons-collections, commons-beanutils, iText, JasperReports all pinned to versions with public RCE CVEs.

CVSS 6.5
SEA Investment Platform
SEA
Information Disclosure Responsible Disclosure Medium 2026-04
2FA Disable Without Password Confirmation

2FA disable endpoint accepts session alone without password re-entry.

CVSS 6.5
Indian Crypto Exchange
SEA
Broken Authentication Responsible Disclosure Medium 2026-04
Password Reset Hash Code Disclosure in Response

Reset-password endpoint returns the reset hash in the JSON response enabling takeover via email-log exposure.

CVSS 6.5
Indian Crypto Exchange
SEA
Broken Authentication Responsible Disclosure Medium 2026-04
Cloudinary Unsigned Upload Configuration Exposed

Cloudinary preset configured for unsigned upload allowing arbitrary asset ingestion under brand domain.

CVSS 6.5
African Crypto Aggregator
Africa
Cloud Misconfig Responsible Disclosure Medium 2026-04
Unauthenticated Trade API With Full Asset Configuration

Trade API endpoint lists all configured assets and parameters without auth.

CVSS 6.5
MENA Crypto Exchange
MENA
Information Disclosure Responsible Disclosure Medium 2026-04
Firebase Configuration With Multiple Google API Keys

Firebase config JSON enumerates all Google Cloud API keys used by the exchange.

CVSS 6.5
European Crypto Exchange
EU
Firebase Misconfig Responsible Disclosure Medium 2026-04
Admin Panel Public Without IP Restriction

Admin panel reachable publicly without IP allowlist or SSO.

CVSS 6.5
Web3 Reputation Protocol
Global
Admin Panel Exposure Responsible Disclosure Medium 2026-04
CORS Wildcard on API Backends

Multiple backends return Access-Control-Allow-Origin:* enabling cross-origin abuse.

CVSS 6.5
African P2P Crypto Settlement
Africa
CORS Responsible Disclosure Medium 2026-04
Dokploy Admin Panel Exposed tRPC Procedures

Dokploy panel reachable with tRPC procedures valid.

CVSS 6.5
African Payment Platform
Africa
Admin Panel Exposure Responsible Disclosure Medium 2026-04
S3 Bucket Public Listing Production User Content

production-gameflip-listing-photo bucket proxied via CloudFront with open listing.

CVSS 6.5
Gaming Marketplace
NA
S3 Misconfig Responsible Disclosure Medium 2026-04
CORS Wildcard with Secret-Token Header

API returns wildcard CORS and allows x-secret-token header exposing hardcoded secret to any origin.

CVSS 6.5
West African B2B Fintech
Africa
CORS Responsible Disclosure Medium 2026-04
Full Firebase Config Exposed

❌ No hardcoded Django admin passwords - ❌ No database connection strings (PostgreSQL/Redis) - ❌ No AWS AKIA access keys - ❌ No JWT secret keys - ❌ No Cognito/Amplify pool IDs in APK (loaded via native confi

CVSS 6.5
EU Crypto Exchange
EU
Firebase Misconfig Responsible Disclosure Medium 2026-04
Bank Inquiry Endpoint - Server-Side Bank Account Validation (No Auth)

The bank inquiry endpoint performs server-side validation of bank account numbers against Indonesia's banking network, without authentication. This can be abused to validate/verify arbitrary bank account numbers

CVSS 6.5
SEA Crypto Exchange
SEA
Business Logic Responsible Disclosure Medium 2026-04
Race Condition in Withdrawal Rate Limit

/api/auth/withdraw-balance endpoint-inde 5 deqiqelik rate limit var. Amma 10 eyni zamanli request gonderildikde, 1-i rate limit check-ini bypass edir ve sonraki validation merehlesine catir. Bu, withdrawal-in parallel islenildiyini ve TOCTOU (Time-of-Check-to-Time-of-Use) race condition-un movcud oldugunu gosterir

CVSS 6.5
Crypto Payment Processor
Global
Rate Limit Bypass Responsible Disclosure Medium 2026-04
Origin IP Disclosure via Traefik (153.92.211.157) [MEDIUM]

Vulnerable Component: Origin server 153.92.211.157 (Hostinger, Manchester UK)

CVSS 6.5
Crypto Exchange Platform
Global
Business Logic Responsible Disclosure Medium 2026-04
[target] Admin Panel Not Behind Cloudflare -- Direct IP Exposed (MEDIUM)

Finding 5: [target] Admin Panel Not Behind Cloudflare -- Direct IP Exposed (MEDIUM) Severity: Medium (CVSS 6.5 - AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L) Summary: The admin panel at [target] resolves directly to IP [ip] (not proxied through Cloudflare),

CVSS 6.5
MENA Fintech
MENA
CORS Responsible Disclosure Medium 2026-04
Deep Exploit Results

1. D[redacted]ed error messages: Tells attacker exactly how many attempts remain 2. No CAPTCHA: Automated brute force possible 3. No IP-based rate limiting: Multiple emails can be tested from same IP 4. Corporate login same issue: `/corporate/auth/login` also vulnerable

CVSS 6.5
African Remittance Provider
Africa
Rate Limit Bypass Responsible Disclosure Medium 2026-04
7 Staging API Microservices Publicly Accessible

Seven staging API subdomains reachable without authentication.

CVSS 6.3
African Neobank
Africa
Cloud Misconfig Responsible Disclosure Medium 2026-04
Stored XSS via Product Name in Purchase Creation

Product name propagates unescaped into merchant dashboard and receipts, allowing stored XSS against merchants.

CVSS 6.1
European Payment Gateway
EU
XSS Responsible Disclosure Medium 2026-04
Prototype Pollution via __proto__ Key

Finding 4: Prototype Pollution via __proto__ Key Injecting `__proto__` as a JSON key crashes the token generation: Response: Empty / no token returned. This indicates the `__proto__` key causes a server-side error during `jwt.sign()` or object processing, which could be: 1. A DoS

CVSS 5.8
Nigerian Payment Provider
Africa
Prototype Pollution Responsible Disclosure Medium 2026-04
Multiple Laravel API Gateway Instances with Debug Information [MEDIUM]

Finding 6: Multiple Laravel API Gateway Instances with Debug Information [MEDIUM] Summary: apigateway.[redacted].ng ve apigateway.prod.[redacted].ng adreslerinde Laravel API Gateway'leri public erisime acik. Her ikisinde de default Laravel welcome page gosteriliyor, login formları mevc

CVSS 5.8
Nigerian Neobank
Africa
Information Disclosure Responsible Disclosure Medium 2026-04
MEDIUM - Exposed Admin and Internal Endpoints (403 vs 404)

Finding 5: MEDIUM - Exposed Admin and Internal Endpoints (403 vs 404) Multiple admin and internal management endpoints exist and respond with 403 Forbidden instead of 404 Not Found, confirming their existence. These endpoints may become accessible through authentication bypass. -

CVSS 5.8
EU iGaming Operator
EU
Information Disclosure Responsible Disclosure Medium 2026-04
Findings Deep

| `/var/log/nginx/access.log` | 25 MB | All HTTP requests, IPs, User-Agents, paths | | `/var/log/nginx/error.log` | 315 KB | Server errors | | `/var/www/pegasus/storage/logs/laravel.log` | 236 KB | Laravel errors, stack traces, internal paths | | 14x rotated/gzipped access logs |

CVSS 5.8
African Crypto Exchange
Africa
Information Disclosure Responsible Disclosure Medium 2026-04
MEDIUM - WordPress REST API with 215 Routes

Finding 5: MEDIUM - WordPress REST API with 215 Routes URL: `https://trade.[redacted].site/wp-json/` - PHP 7.4.33 (EOL since November 2022) - WordPress with RankMath SEO plugin

CVSS 5.8
Mixed Platforms
Global
Information Disclosure Responsible Disclosure Medium 2026-04
736 Real User ObjectIDs Exposed via DO Spaces

Finding 5: 736 Real User ObjectIDs Exposed via DO Spaces The DO Spaces bucket (`[redacted].[target]`) has public listing enabled, exposing 988 files with 736 unique MongoDB ObjectIDs from user profile photos: These ObjectIDs can be injected into the `_id`, `

CVSS 5.8
Nigerian Payment Provider
Africa
JWT Issues Responsible Disclosure Medium 2026-04
— CVSS 10.0 — GCE Root Shell (SSH Key Injection)

Finding 3 — CVSS 10.0 — GCE Root Shell (SSH Key Injection) Sunucu: `website-cms` ([ip], us-central1-a, Debian 12) Yöntem: `[redacted]-lupin` SA (roles/owner) → Compute Engine `setMetadata` → SSH key enjeksiyon → root | `/var/www/html/proxy/.env` | `JWT_SECRET=714a7ea9a0ef4d788

CVSS 5.8
African Remittance Provider
Africa
Credential Exposure Responsible Disclosure Medium 2026-04
MEDIUM - S3 Bucket Discovery ([redacted]-documents)

Finding 5: MEDIUM - S3 Bucket Discovery ([redacted]-documents) The S3 bucket `[redacted]-documents` exists and returns 403 (access denied but not 404), confirming its existence. - 167 subdomains discovered via crt.sh - [redacted] Organization: o407766 (shared across Flex + support app)

CVSS 5.8
African Neobank
Africa
Information Disclosure Responsible Disclosure Medium 2026-04
MEDIUM - WordPress User Enumeration

Finding 4: MEDIUM - WordPress User Enumeration URL: `GET https://trade.[redacted].site/wp-json/wp/v2/users` - ID 5: Adul Hassan (slug: hazzan)

CVSS 5.8
Mixed Platforms
Global
Information Disclosure Responsible Disclosure Medium 2026-04
No Server-Side JWT Invalidation on Logout

Logout only clears the client-side cookie while tokens remain valid server-side.

CVSS 5.5
Indian Crypto Exchange
SEA
Broken Authentication Responsible Disclosure Medium 2026-04
Source Map Exposure With KYC Service Architecture

cryptoforce.in JS bundles leak KYC microservice architecture and endpoints.

CVSS 5.5
Indian Crypto Exchange
SEA
Information Disclosure Responsible Disclosure Medium 2026-04
Full API Architecture Disclosed (250+ endpoints)

Bundle discloses 250+ internal endpoints with parameter signatures.

CVSS 5.5
African Fintech Expense Platform
Africa
Information Disclosure Responsible Disclosure Medium 2026-04
X-Session-Override Header Enables Session Fixation

Custom X-Session-Override header accepts attacker-supplied session IDs, enabling fixation attacks.

CVSS 5.4
European Payment Gateway
EU
Broken Authentication Responsible Disclosure Medium 2026-04
Sentry DSN Event Injection Across Three Projects

Three Sentry DSNs exposed in JS bundles accept arbitrary events, enabling log pollution and internal alert fatigue.

CVSS 5.3
European Payment Gateway
EU
Information Disclosure Responsible Disclosure Medium 2026-04
Public OpenAPI/Swagger Schemas Expose Full API Documentation

OpenAPI schemas of three platforms are served without auth, enumerating internal endpoints and parameters.

CVSS 5.3
European Payment Gateway
EU
Information Disclosure Responsible Disclosure Medium 2026-04
Internal Hostname and Port Leak via 404 Page

Default 404 response reveals internal Kubernetes hostnames and ports, aiding SSRF and lateral pivots.

CVSS 5.3
European Payment Gateway
EU
Information Disclosure Responsible Disclosure Medium 2026-04
2FA Optional by Default on Payment Gateway Admin Accounts

New admin accounts default to 2FA disabled across all instances, weakening account security posture.

CVSS 5.3
European Payment Gateway
EU
Broken Authentication Responsible Disclosure Medium 2026-04
Internal User IDs and Application Configuration Exposure

Assorted config endpoints reveal internal user IDs, feature flags and microservice addresses.

CVSS 5.3
SEA Investment Platform
SEA
Information Disclosure Responsible Disclosure Medium 2026-04
MongoDB ObjectID and Schema Leak in Error Responses

Stack traces expose Mongo ObjectIDs and schema fields aiding injection-based attacks.

CVSS 5.3
Indian Crypto Exchange
SEA
Information Disclosure Responsible Disclosure Medium 2026-04
Sentry DSN Exposed + Event Injection

Sentry DSN accepts arbitrary events usable for alert fatigue attacks.

CVSS 5.3
African Fintech Expense Platform
Africa
Information Disclosure Responsible Disclosure Medium 2026-04
RSA Public Key + Analytics Key Exposure

PocketBits bundle leaks RSA public key and analytics key usable for targeted attacks.

CVSS 5.3
Indian Crypto Exchange
SEA
Credential Exposure Responsible Disclosure Medium 2026-04
Infura + WalletConnect Project IDs Exposed

Infura project ID and WalletConnect credentials in bundle.

CVSS 5.3
African Crypto Infrastructure
Africa
API Key Exposure Responsible Disclosure Medium 2026-04
Source Map Exposure on App Bundle

flipexapp.com exposes production source map revealing app structure.

CVSS 5.3
African Crypto Trading Mobile App
Africa
Information Disclosure Responsible Disclosure Medium 2026-04
Firebase Storage Public File Listing (31 items)

dtunes-app bucket rules allow anonymous listing of user-uploaded images.

CVSS 5.3
African Digital Platform
Africa
Firebase Misconfig Responsible Disclosure Medium 2026-04
save-live - Open Firestore with 6 Users PII

Algerian blood donation app Firestore open exposing 6 users with phone/email/FCM tokens.

CVSS 5.3
African Fintech Firebase Cohort
Africa
Firebase Misconfig Responsible Disclosure Medium 2026-04
Apache Airflow Unauthenticated Info Disclosure

pricepally Airflow exposes DAG metadata without auth.

CVSS 5.3
African Fintech Metabase Cohort
Africa
Information Disclosure Responsible Disclosure Medium 2026-04
Metabase Login No Rate Limiting

Metabase login and reset endpoints allow unlimited attempts enabling brute-force.

CVSS 5.3
African Investment Fintech
Africa
Rate Limit Bypass Responsible Disclosure Medium 2026-04
Cloudinary Cloud Name + Upload Preset Discoverable

Cloudinary cloud_name 'drugstoc' allows unsigned uploads if preset leaked.

CVSS 5.3
African Pharma B2B Platform
Africa
Cloud Misconfig Responsible Disclosure Medium 2026-04
Development Configuration Deployed to Production

VITE_APP_ENV=development and devnet RPC URLs deployed to production dashboard.

CVSS 5.3
Crypto Payment Infrastructure
Global
Cloud Misconfig Responsible Disclosure Medium 2026-04
Strapi v4 CMS Publicly Reachable

content subdomain serves Strapi admin without auth redirect.

CVSS 5.3
European Crypto Exchange
EU
Admin Panel Exposure Responsible Disclosure Medium 2026-04
Birdeye DeFi API Key Hardcoded

Birdeye paid API key embedded in SPA; enables quota exhaustion.

CVSS 5.3
L1 Smart Contract
Global
API Key Exposure Responsible Disclosure Medium 2026-04
HitBTC/AlphaPoint Swagger UI Exposed

api.exchange.cryptomkt.com Swagger exposes full REST schema.

CVSS 5.3
LATAM Crypto Platform
LATAM
Information Disclosure Responsible Disclosure Medium 2026-04
.env File Path Exists Behind WAF

/.env returns 200 indicating file exists; only WAF blocks content. Bypass = full DB/APP_KEY.

CVSS 5.3
MENA Payment Giant
MENA
Information Disclosure Responsible Disclosure Medium 2026-04
Production Source Map Exposure on Affiliate Admin Panel

Affiliate admin Vue source code and internal API routes exposed via publicly-served source map.

CVSS 5.3
SEA Crypto Derivatives Exchange
SEA
Information Disclosure Responsible Disclosure Medium 2026-04
Unlimited Wallet Creation Resource Exhaustion

No limit on wallet creation per user; 20+ wallets per session feasible.

CVSS 5.3
West African Crypto Exchange
Africa
Rate Limit Bypass Responsible Disclosure Medium 2026-04
eKYC Application Publicly Accessible on Subdomain

External KYC verification app reachable without auth enabling reconnaissance of onboarding flow and potential data submission abuse.

CVSS 5.3
MENA Super-App Fintech
MENA
KYC Bypass Responsible Disclosure Medium 2026-04
Unauthenticated Products/System-Settings Data Exposure

Product details including AUM data, fee structures, wallet configurations, and system maintenance flags are exposed without any authentication

CVSS 5.3
SEA Crypto Exchange
SEA
Business Logic Responsible Disclosure Medium 2026-04
PHP Error Disclosure

GET /api/auth/menu-visibility {"success":false,"message":"Error","data":"Undefined variable $isMenu"}

CVSS 5.3
Crypto Payment Processor
Global
Business Logic Responsible Disclosure Medium 2026-04
Server Error Information Disclosure on Multiple Endpoints [MEDIUM]

Vulnerable Endpoints: Multiple

CVSS 5.3
Crypto Exchange Platform
Global
Information Disclosure HackerOne Medium 2026-04
Staging Environments Publicly Accessible

> NEW FINDING

CVSS 5.3
African SME Lender
Africa
Firebase Misconfig Responsible Disclosure Medium 2026-04
Cloud Run Microservices — 16 Services Exposed

> NEW FINDING

CVSS 5.3
African SME Lender
Africa
File Upload Responsible Disclosure Medium 2026-04
Django REST Framework OpenAPI Schema Endpoint Server Error

Vulnerable Endpoint: https://api.[vendor]/api/schema/

CVSS 5.3
African Identity Verification
Africa
Business Logic Responsible Disclosure Medium 2026-04
Complete IdentityPass API Endpoint Enumeration - 15+ Active Verification Endpoints

API Base: https://api.[vendor]/identitypass/

CVSS 5.3
African Identity Verification
Africa
API Key Exposure Responsible Disclosure Medium 2026-04
Direct IP erisimini kapat

CVSS 5.3
African E-Commerce Platform
Africa
Admin Panel Exposure Responsible Disclosure Medium 2026-04
WordPress User Enumeration and XML-RPC Enabled (MEDIUM)

Finding 6: WordPress User Enumeration and XML-RPC Enabled (MEDIUM) Severity: Medium (CVSS 5.3 - AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) Summary: The WordPress blog at blog.[redacted].com exposes 4 user accounts via the REST API and has XML-RPC fully enabled with 80+ methods including c

CVSS 5.3
MENA Fintech
MENA
Rate Limit Bypass Responsible Disclosure Medium 2026-04
[redacted] DSN Exposure with Verified Event Injection (MEDIUM)

Finding 3: [redacted] DSN Exposure with Verified Event Injection (MEDIUM) - [redacted] App: `https://9c7d5cbc05d7ab151c379cf9bb2248e9@o4506558158471168.ingest.[redacted].io/4506558160437248` - Manteca Ramp: `https://ba91a78331d307cffbf7e77574d78ae9@o4506558158471168.ingest.[redacted].io/45

CVSS 5.3
LATAM Crypto Platform
LATAM
XSS Responsible Disclosure Medium 2026-04
Username and Email Enumeration via Registration

Finding 3: Username and Email Enumeration via Registration Vulnerable Endpoint: `POST https://thor.[redacted].com/api/register` Type: Information Exposure (CWE-204) The registration endpoint returns different error messages depending on whether a username, email, or phone number is

CVSS 5.3
African Crypto Exchange
Africa
Information Disclosure Responsible Disclosure Medium 2026-04
Email Verification Not Required for Full Platform Access

Unverified email accounts gain full platform access, making phishing/impersonation trivial.

CVSS 5.0
European Payment Gateway
EU
Broken Authentication Responsible Disclosure Medium 2026-04
.git Directory Detected on Production Server

/ .git returns 403 not 404 confirming repo presence on production webroot.

CVSS 5.0
EU Crypto ATM Operator
EU
Information Disclosure Responsible Disclosure Medium 2026-04
Dev API Stack Trace Information Disclosure

Dev API error handler returns stack traces exposing internal paths.

CVSS 5.0
African Fintech Expense Platform
Africa
Information Disclosure Responsible Disclosure Medium 2026-04
Third-Party Service Credentials Exposed in Bundle

Multiple third-party SaaS API keys present in production build.

CVSS 5.0
African Fintech Expense Platform
Africa
API Key Exposure Responsible Disclosure Medium 2026-04
Unauthenticated Platform Configuration Disclosure Across Instances

Spell instance configs downloadable without auth, leaking feature flags and integration IDs.

CVSS 4.3
European Payment Gateway
EU
Information Disclosure Responsible Disclosure Medium 2026-04
Email Flood via Unlimited Password Reset and Verification

Unlimited transactional email triggers enable victim mailbox flooding and cost attacks against the provider.

CVSS 4.3
European Payment Gateway
EU
Rate Limit Bypass Responsible Disclosure Medium 2026-04
PHP Stack Trace Leak via API Error

Malformed request returns PHP stack trace exposing Nette framework paths.

CVSS 4.3
EU Crypto ATM Operator
EU
Information Disclosure Responsible Disclosure Medium 2026-04
PHP Version Disclosure via X-Powered-By

PHP 8.4.3 version advertised in every API response aiding CVE targeting.

CVSS 4.3
SEA Crypto Exchange
SEA
Information Disclosure Responsible Disclosure Medium 2026-04
Hardcoded Internal API URLs in Production JS

Internal API endpoints and infra hostnames visible in compiled frontend.

CVSS 4.3
MENA Regulated Crypto Exchange
MENA
Information Disclosure Responsible Disclosure Medium 2026-04
Hardcoded Cryptocurrency Wallet Addresses and reCAPTCHA Key (MEDIUM)

Finding 5: Hardcoded Cryptocurrency Wallet Addresses and reCAPTCHA Key (MEDIUM) Affected Component: Source maps (environment.prod.ts, balance.service.ts, qr-payment.service.ts) Summary: Production cryptocurrency wallet addresses, reCAPTCHA site key, and contract addresses are har

CVSS 4.3
LATAM Crypto Platform
LATAM
Information Disclosure Responsible Disclosure Medium 2026-04
Internal Infrastructure Details Leaked

Dev ortami HTML sayfasi ve HTTP response header'lari, dahili altyapi detaylarini ifsa etmektedir

CVSS 6.8
African Crypto Exchange
Africa
Business Logic Responsible Disclosure Medium 2026-03
Ops Partner Portal - Unauthenticated Dashboard Redirect + CSRF Token Leak

Ops Partner Portal'a kimlik dogrulamasi olmadan erisim saglanabiliyor. Ana sayfa dogrudan /dashboard'a redirect ediyor (auth check yok). CSRF token ve session cookie unauthenticated olarak veriliyor

CVSS 6.8
African Crypto Exchange
Africa
Business Logic HackerOne Medium 2026-03
Unliquidatable Dust Position Creates Permanent Protocol Bad Debt

floor() rounding in seize_ctokens combined with missing min_borrow enforcement leaves tiny positions that cannot be liquidated, accumulating bad debt.

CVSS 6.5
Sui L1 Lending Protocol
Global
Rounding Sherlock Medium 2026-03
Flash Loan Fee Arbitrage via Caller-Controlled emode_group Parameter

Unvalidated emode_group parameter lets flash loan borrower pick the group with the lowest fee_rate for any asset, draining protocol fee revenue.

CVSS 6.5
Sui L1 Lending Protocol
Global
Business Logic Sherlock Medium 2026-03
EMode Borrow Limit Bypass via Stale Interest Tracking

assets_borrows tracking never reflects interest accruing on idle obligations so the per-emode max_borrow_amount cap is progressively exceeded.

CVSS 6.5
Sui L1 Lending Protocol
Global
Business Logic Sherlock Medium 2026-03
Chatwoot Super Admin Panel Exposed

Chatwoot super admin login page publicly reachable on subdomain.

CVSS 6.5
SEA Banking API Platform
SEA
Admin Panel Exposure Responsible Disclosure Medium 2026-03
Staging/Dev Admin Panels Publicly Accessible

Dev/staging admin portals reachable publicly mirroring production codebase.

CVSS 6.5
African Fintech Neobank
Africa
Admin Panel Exposure Responsible Disclosure Medium 2026-03
Client-Side Encryption Broken (secretPhrase + encryptionSecret Exposed)

Bundle embeds secretPhrase and encryptionSecret used for client-side payload protection.

CVSS 6.5
African Crypto Exchange
Africa
Credential Exposure Responsible Disclosure Medium 2026-03
Ory Kratos Admin API Publicly Accessible

Kratos admin endpoints reachable without network control, exposing identity schemas.

CVSS 6.5
African Bitcoin Lightning Provider
Africa
Admin Panel Exposure Responsible Disclosure Medium 2026-03
6 Socket.IO Endpoints Accept Unauthenticated Connections

Six Socket.IO endpoints accept unauth connections exposing real-time trade feeds.

CVSS 6.5
Indian Crypto Exchange
SEA
WebSocket Issues Responsible Disclosure Medium 2026-03
Cross-Site WebSocket Hijacking (CSWSH) on Exchange WebSocket

WebSocket handshake skips Origin validation allowing attacker pages to open authenticated channels.

CVSS 6.5
Global P2P Crypto Marketplace
Global
WebSocket Issues Responsible Disclosure Medium 2026-03
Kubernetes Internal Service URL Leak

topuplive.com leaks internal K8s svc URLs usable as SSRF target.

CVSS 6.5
Gaming Top-Up Platform
Global
Information Disclosure Responsible Disclosure Medium 2026-03
FlowM /events Auth Guard Bypass (Event Injection)

/events and /events/simulate processed without auth enabling arbitrary event injection.

CVSS 6.5
Central African Crypto Fintech
Africa
Access Control Responsible Disclosure Medium 2026-03
CORS Origin Reflection with Credentials on forms subdomain

forms.* subdomain reflects arbitrary Origin with Access-Control-Allow-Credentials true enabling cross-origin credentialed requests.

CVSS 6.5
Nigerian Gift Card Platform
Africa
CORS Responsible Disclosure Medium 2026-03
Login Page reCAPTCHA Sitekey and Architecture Disclosure (redeem-cards.com)

The login page at redeem-cards.com exposes the reCAPTCHA v3 sitekey, form structure, and when a non-empty CaptchaToken is provided, triggers DeveloperExceptionPage with full stack traces

CVSS 6.5
EU Gaming Key Marketplace
EU
Information Disclosure Responsible Disclosure Medium 2026-03
Xbox Bot Store Schedule Manipulation (20 Stores)

The collectglobalstore endpoint is accessible without authentication and triggers schedule rescheduling across ALL 20 Xbox stores. A single unauthenticated request modifies the update schedule for the entire Xbox game tracking system

CVSS 6.5
EU Gaming Key Marketplace
EU
Rate Limit Bypass Responsible Disclosure Medium 2026-03
Sentry Open Registration Form (Registration Tab Active)

The Sentry login page includes an active "Register" tab with a functional registration form (op=register). While the form fields appear to be empty (possibly a rendering issue), the form endpoint accepts POST requests with the register operation. Combined with invitesEnabled: true, this indicates the Sentry instance may accept new user registrat

CVSS 6.5
NA Gift Card Supplier
NA
Information Disclosure Responsible Disclosure Medium 2026-03
HIGH - Keycloak SSO & Internal Service Architecture Exposed

Vulnerable Endpoints: - https://keycloak.[vendor]/auth/realms/[vendor]- https://keycloak.[vendor]/auth/realms/[vendor]/.well-known/openid-configuration - https://[vendor] / (CORS wildcard)

CVSS 6.5
African Payment Processor
Africa
CORS Responsible Disclosure Medium 2026-03
HIGH - EMQX MQTT Broker Dashboard Publicly Accessible (emqx.[vendor])

Vulnerable Endpoint: https://emqx.[vendor]

CVSS 6.5
African Payment Processor
Africa
Credential Exposure Responsible Disclosure Medium 2026-03
Metabase v0.53.6 Setup-Token Persistent Exposure

metabase.[vendor] uzerindeki Metabase v0.53.6, setup tamamlanmis olmasina ragmen setup-token'i /api/session/properties endpointi uzerinden herkese acik birakiyor

CVSS 6.5
African Remittance Platform
Africa
Admin Panel Exposure Responsible Disclosure Medium 2026-03
FortiGate SSL VPN Login Exposed + Internal IP Leak

Endpoint: https://ofw.[vendor]

CVSS 6.5
EU Digital Goods Marketplace
EU
Business Logic Responsible Disclosure Medium 2026-03
KChat Vue.js SPA Complete Source Code and API Architecture Exposure

kchat.[vendor]'da host edilen Vue.js SPA, tum source chunk'lari ile birlikte public olarak erisilebilir durumdadir. Bu kaynak koddan tum API endpoint'leri, WebSocket komutlari, authentication flow'u, ve internal routing yapisi cikarilmistir. Ayni SPA, hem [vendor] ([vendor]) hem de SEAGM (seagm.com) icin kullanilmakta olup "SEAGM LiveChat" ola

CVSS 6.5
Gaming Marketplace
Global
WebSocket Issues HackerOne Medium 2026-03
MEDIUM -- Login Form Missing CSRF Token -- Login CSRF Attack

member.[vendor]/login sayfasindaki login formu, herhangi bir CSRF korumasina sahip degildir -- ne hidden CSRF token field'i, ne de SameSite cookie korumasina sahiptir (member.[vendor]'da cookie SameSite attribute'u YOK). Bu, saldirganin kurbanin tarayicisinda saldirganin kendi hesabiyla login yapmasina olanak tanir (Login CSRF). Kurbanin son

CVSS 6.5
Gaming Marketplace
Global
Business Logic HackerOne Medium 2026-03
Navigation JSON Leaks Admin User IDs, Internal Category Structure, and DynamoDB Schema

The publicly accessible navigation.json file at assets.[vendor] exposes the complete internal category tree including admin user IDs who made updates, DynamoDB partition/sort key schema (pk, sk fields), internal category UUIDs, INACTIVE/hidden categories, product counts, and timestamps. This data enables reconnaissance for privilege escalat

CVSS 6.5
SEA Gaming Marketplace
SEA
Privilege Escalation HackerOne Medium 2026-03
Full Source Code Exposure via Source Maps (623 Files, 9.4 MB)

The production JavaScript bundles at app.[vendor] have corresponding .map (source map) files publicly accessible. These files contain the complete original source code of the frontend application — 623 files totaling 9.4 MB. This includes all API endpoint paths, all business logic, admin routes, permission systems, internal comments, and e

CVSS 6.5
Crypto Gaming Platform
Global
Information Disclosure Responsible Disclosure Medium 2026-03
Staging Application Accessible Without CF Access

[vendor] and [vendor] Staging Applications Publicly Accessible Without Cloudflare Access Authentication

CVSS 6.5
LATAM Crypto Platform
LATAM
Access Control HackerOne Medium 2026-03
Router Pentest [ip]

Router Penetration Test Report - [ip] Hedef: [ip] (Yerel ag gateway/router) Yetkilendirme: Yetkili pentest, yerel ag | Uretici | Huawei Technologies Co., Ltd. |

CVSS 6.5
Router Infrastructure
Global
Rate Limit Bypass Responsible Disclosure Medium 2026-03
SSTI Payload Stored via Contact Form (CVE-2024-31447)

Shopware CVE-2024-31447 SSTI triggerable via contact form storage.

CVSS 6.1
EU Gaming Marketplace
EU
SSTI Responsible Disclosure Medium 2026-03
Heroku Subdomain Takeover Possibility

Referenced Heroku subdomain is unclaimed allowing attacker to register and serve content under the target domain.

CVSS 6.1
African Crypto Infrastructure
Africa
Subdomain Takeover Responsible Disclosure Medium 2026-03
Sentry Internal Configuration Data Leak

The Sentry login page leaks extensive internal configuration data in the __initialData JavaScript object, accessible without authentication

CVSS 6.1
NA Gift Card Supplier
NA
Privilege Escalation Responsible Disclosure Medium 2026-03
AWS API Gateway with CORS Wildcard () on sls.[vendor]

The serverless API at sls.[vendor] (AWS API Gateway + CloudFront) returns Access-Control-Allow-Origin: with full method and header permissions, allowing any website to make cross-origin requests to the API

CVSS 6.1
SEA Gaming Marketplace
SEA
CORS HackerOne Medium 2026-03
CORS Wildcard on Production API

The production API at api.[vendor] returns Access-Control-Allow-Origin: on all API endpoints, including the admin dashboard API. This allows any website to make cross-origin requests to the API

CVSS 6.1
SEA E-Commerce Platform
SEA
CORS Responsible Disclosure Medium 2026-03
Digest Auth MD5-only with Nonce Timestamp Leakage

Digest authentication uses MD5 only and nonce encodes server timestamp enabling replay windows.

CVSS 5.9
CCTV Infrastructure
Global
Broken Authentication Responsible Disclosure Medium 2026-03
XMLRPC pingback.ping SSRF

pingback.ping XMLRPC method'u aktif. Sunucu, istenen herhangi bir URL'ye HTTP request gonderiyor. Bu, internal network scanning ve SSRF saldirisi icin kullanilabilir

CVSS 5.8
EU Digital Goods Marketplace
EU
SSRF Responsible Disclosure Medium 2026-03
admin.[redacted].com - Admin Panel Source Map Exposure [MEDIUM]

Finding 2: admin.[redacted].com - Admin Panel Source Map Exposure [MEDIUM] `admin.[redacted].com` is [redacted]'s internal admin panel for managing clients, KYC applications, merchants, and bank integrations. The webpack source map is publicly accessible, exposing 129 source files includi

CVSS 5.8
SEA Fintech
SEA
Information Disclosure Responsible Disclosure Medium 2026-03
MEDIUM - Order Generation DoS via paySmart2D Repeated Invalid Hash Requests

Finding 59: MEDIUM - Order Generation DoS via paySmart2D Repeated Invalid Hash Requests Summary: paySmart2D endpoint'i her basarisiz hash_key denemesinde veritabaninda yeni bir order kaydi (order_no) olusturuyor. Saldirgan rate limit olmadan binlerce istek gonderip veritabanini g

CVSS 5.8
Turkish Payment Gateway
MENA
Information Disclosure Responsible Disclosure Medium 2026-03
Security Finding

Platform WAF/CDN arkasında DEĞİL (doğrudan IP: [ip]), bu da saldırıyı kolaylaştırır. 1. Saldırgan `[target]` üzerinde exploit sayfası hazırlar 2. [redacted] admin'ine phishing email gönderir (örn: "Yeni sunucu sipariş durumu") 3. Admin linki tıkladığında, browser otomatik ol

CVSS 5.8
Web Hosting Provider
EU
Credential Exposure Responsible Disclosure Medium 2026-03
P-2: CORS Wildcard on API Subdomains (MEDIUM)

Finding P-2: CORS Wildcard on API Subdomains (MEDIUM) Endpoint: `api.[redacted].com`, `currency-api.[redacted].com`, `liquidity-api.[redacted].com` Note: `currency-api.[redacted].com` has the dangerous combination of `Access-Control-Allow-Origin: ` WITH `Access-Control-Allow-Credentials:

CVSS 5.8
African Neobank
Africa
CORS Responsible Disclosure Medium 2026-03
[MEDIUM] - Staging API CORS Wildcard Misconfiguration

Finding 2 [MEDIUM] - Staging API CORS Wildcard Misconfiguration Summary: The staging API at `apiprostaging.[redacted].africa` responds with `Access-Control-Allow-Origin: ` for all origins, combined with accepting all methods and headers including `Authorization`. Vulnerable Endpoint: `

CVSS 5.8
DeFi Lending/DEX Protocol
Global
CORS Responsible Disclosure Medium 2026-03
Unauthenticated ThirdParty Profile Creation on Production [MEDIUM]

Finding 6: Unauthenticated ThirdParty Profile Creation on Production [MEDIUM] - POST /api/ThirdParty/CreateThirdPartyProfileOnProd - POST /api/LiquidityProviderRegistration/Initiate ThirdParty profil olusturma endpoint'i authentication olmadan erisilebilir. Dogru parametreler sag

CVSS 5.8
African DeFi Protocol
Africa
Business Logic Responsible Disclosure Medium 2026-03
Security Finding

1. Production service running in "development" mode — `env: "development"` on `.svc.[redacted].co` 2. PEP screening methodology exposed — strict/fuzzy matching logic, country filtering, keyword search 3. Conviction check API — Criminal record screening endpoint structure revealed

CVSS 5.8
African KYC Provider
Africa
Information Disclosure Responsible Disclosure Medium 2026-03
Sandbox API 500 Error (Unhandled Exception) [MEDIUM]

Finding 5: Sandbox API 500 Error (Unhandled Exception) [MEDIUM] - URL: `https://[target]/` - Response: `{"code":"500","description":"An unexpected system error occurred","status":false}` - Impact: Sandbox environment exposed with unhandled errors

CVSS 5.8
Crypto Fintech Mass Scan
Global
Information Disclosure Responsible Disclosure Medium 2026-03
Bounty Platformlari

- [[redacted] DAO - HackerOne](https://[target]/[redacted]_dao) - [JustLend DAO - Immunefi](https://[target]/bounty/justlenddao/) - [ChainSecurity Java-[redacted] Audit](https://[target]/security-audit/java-[redacted]) - [dWallet Labs Multisig PoC](https://[target]/dwallet-labs/t

CVSS 5.8
L1 Smart Contract
Global
Information Disclosure HackerOne Medium 2026-03
MEDIUM - Invoice Share Link Endpoint Processes Without Auth (Unauthenticated Error Oracle)

Finding 38: MEDIUM - Invoice Share Link Endpoint Processes Without Auth (Unauthenticated Error Oracle) Severity: Medium (CVSS 5.3 - AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) Summary: `/invoices-share-with-link/{link}` endpoint'i JWT gerektirmeden istekleri isler (diger 239 endpoint'in

CVSS 5.8
Turkish Payment Gateway
MENA
S3 Misconfig Responsible Disclosure Medium 2026-03
[redacted] Staging Infrastructure Exploitation

Security finding identified during authorized security assessment.

CVSS 5.8
African Payment Gateway
Africa
Information Disclosure Responsible Disclosure Medium 2026-03
Wildcard CORS on Main Domain (Informational)

Finding 6: Wildcard CORS on Main Domain (Informational) `www.[redacted].am`, `sport.[redacted].am`, and `go-cms.[redacted].am` all return `Access-Control-Allow-Origin: ` without `Access-Control-Allow-Credentials: true`. While this is not exploitable for authenticated requests (browsers won't send

CVSS 5.8
EU iGaming Operator
EU
Credential Exposure Responsible Disclosure Medium 2026-03
[MEDIUM] - Staging API Accessible (apiprostaging.[redacted].africa)

Finding 3 [MEDIUM] - Staging API Accessible (apiprostaging.[redacted].africa) Summary: The staging API at `apiprostaging.[redacted].africa/api/` is publicly accessible and returns structured JSON responses for all admin endpoints (HTTP 400 with auth error, not 404). This confirms the API is

CVSS 5.8
DeFi Lending/DEX Protocol
Global
RCE Responsible Disclosure Medium 2026-03
Admin 2FA Configuration Exposure [MEDIUM]

Finding 5: Admin 2FA Configuration Exposure [MEDIUM] Endpoint: GET /api/Admin/TwoFA/Configurations Admin panelinin 2FA konfigurasyonu authentication olmadan erisilebilir durumdadir. Sistem tarafindan kullanilan 2FA provider'lari, ID'leri ve aktiflik durumlari ifsa olmaktadir. - 2

CVSS 5.8
African DeFi Protocol
Africa
Admin Panel Exposure Responsible Disclosure Medium 2026-03
Drone CI v2.25.0 Publicly Accessible

CI server UI reachable without auth, exposing repo and build metadata.

CVSS 5.5
SEA Banking API Platform
SEA
Admin Panel Exposure Responsible Disclosure Medium 2026-03
Webhook Degisikligi OTP Gerektirmiyor

Webhook Degisikligi OTP Gerektirmiyor

CVSS 5.4
Crypto Gaming Platform
Global
JWT Issues Responsible Disclosure Medium 2026-03
Deposit Limit Double-Subtraction Bypass in Reserve Accounting

cash_reserve is subtracted twice in the deposit_limit_breached check, effectively raising the admin-configured deposit cap.

CVSS 5.3
Sui L1 Lending Protocol
Global
Rounding Sherlock Medium 2026-03
Zero-Amount Claims Bypass Per-Epoch Reward Claim Flag

Claimed status inferred from reward amount > 0, so users with zero-reward epochs can re-claim later when inputs change.

CVSS 5.3
Ethereum Attestation Protocol
Global
Business Logic Code4rena Medium 2026-03
PHPSESSID Cookie Without HttpOnly + SameSite=None

Session cookie missing HttpOnly flag and SameSite=None enabling XSS theft and CSRF.

CVSS 5.3
Global P2P Crypto Marketplace
Global
Broken Authentication Responsible Disclosure Medium 2026-03
Email Enumeration via user-mgm API

user-mgm endpoint returns differential errors confirming registered emails.

CVSS 5.3
SEA Banking API Platform
SEA
Information Disclosure Responsible Disclosure Medium 2026-03
Unauthenticated User Registration (Progressive Field Disclosure)

Registration service reveals required fields through error messages allowing structured enumeration.

CVSS 5.3
SEA Banking API Platform
SEA
Business Logic Responsible Disclosure Medium 2026-03
Singular Attribution SDK Credentials Exposed

Singular SDK key in bundle allows impersonating attribution events.

CVSS 5.3
African Fintech Neobank
Africa
API Key Exposure Responsible Disclosure Medium 2026-03
Ory Kratos Self-Service API Unrestricted Registration

Self-service registration accepts unlimited requests without captcha or throttling.

CVSS 5.3
African Bitcoin Lightning Provider
Africa
Rate Limit Bypass Responsible Disclosure Medium 2026-03
SensorsData Event Injection Verified

Three SensorsData endpoints accept unauthenticated analytics events enabling log poisoning.

CVSS 5.3
Global P2P Crypto Marketplace
Global
Information Disclosure Responsible Disclosure Medium 2026-03
New Relic License Key + App ID Exposed

zeusx.com bundle exposes New Relic license key and app ID.

CVSS 5.3
Game Top-Up Platform
Global
API Key Exposure Responsible Disclosure Medium 2026-03
S3 Bucket Name + Password Salt Exposed in JS

coincola.com bundle reveals S3 bucket names and password-hashing salt.

CVSS 5.3
Global P2P Crypto Marketplace
Global
Information Disclosure Responsible Disclosure Medium 2026-03
Source Map Exposure on Frontend + Admin

CRA source maps served publicly leaking admin routes and secrets.

CVSS 5.3
African Crypto Trading Platform
Africa
Information Disclosure Responsible Disclosure Medium 2026-03
Internal Error Codes & Redis Reset

Public endpoints expose internal error codes and Redis tracking reset.

CVSS 5.3
African KYC/Identity Provider
Africa
Information Disclosure Responsible Disclosure Medium 2026-03
Microservice Naming Disclosure via Source

hms/hpms/homs/hums microservice hostnames visible in frontend.

CVSS 5.3
Asian Gift-Card Marketplace
SEA
Information Disclosure Responsible Disclosure Medium 2026-03
Email Enumeration via Register Endpoint

EMAIL_ALREADY_TAKEN error discloses account existence.

CVSS 5.3
EU iGaming Operator
EU
Information Disclosure Responsible Disclosure Medium 2026-03
WordPress Internal API Unauthenticated Exchange Rate Refresh

Unauthenticated endpoint can refresh cached exchange rates, enabling cache pollution.

CVSS 5.3
European Crypto Payment Gateway
EU
Access Control Responsible Disclosure Medium 2026-03
OpenCart Callback Token in URL Query String

Token transmitted in URL query string, appearing in web server access logs and referrer headers.

CVSS 5.3
European Crypto Payment Processor
EU
Credential Exposure Responsible Disclosure Medium 2026-03
Mass Source Map Exposure Across Payment Providers

Paybis, Kuda and others serve production source maps with full frontend source.

CVSS 5.3
Global Crypto Broker Cluster
Global
Information Disclosure Responsible Disclosure Medium 2026-03
CORS Misconfiguration on Blog API

Blog API allows arbitrary origin with credentials.

CVSS 5.3
Indian Crypto Exchange
SEA
CORS Responsible Disclosure Medium 2026-03
Unauthenticated Source Code / JavaScript Disclosure

Firmware UI exposes JavaScript and 439 ISAPI endpoint URLs without authentication.

CVSS 5.3
CCTV Infrastructure
Global
Information Disclosure Responsible Disclosure Medium 2026-03
Pusher Real-time Credentials Exposed

Pusher app key/cluster exposed allowing event injection into real-time dashboards.

CVSS 5.3
African Payment Gateway
Africa
API Key Exposure Responsible Disclosure Medium 2026-03
Unauthenticated API Data Access (User Profiles)

Offers and profile endpoints reveal counterparty identities without authentication.

CVSS 5.3
African P2P Crypto Platform
Africa
IDOR Responsible Disclosure Medium 2026-03
Semicolon Path Traversal Bypasses API Gateway Filtering

Semicolon segment normalization differs between gateway and Spring Boot enabling bypass to backend actuator paths.

CVSS 5.3
EU Student Banking Fintech
EU
Path Traversal Responsible Disclosure Medium 2026-03
Hardcoded Content API Key in Client JavaScript

Content API key hard-coded in frontend enables replay against backend though lacks additional privileges.

CVSS 5.3
CIS Streaming Platform
MENA
API Key Exposure Responsible Disclosure Medium 2026-03
Third-Party Payment/KYC Integration Architecture Full Leak

Registration ve profile API'leri [vendor]'in kullandigi tum ucuncu parti servis entegrasyonlarini ortaya koyuyor. Bu bilgi rakip analizi, hedefli saldirilar ve social engineering icin kullanilaabilir

CVSS 5.3
African Remittance Platform
Africa
KYC Bypass Responsible Disclosure Medium 2026-03
Ramp API Authentication Bypass — JWT Token Without User Auth

ramp.[vendor] ramp/auth Endpoint Issues JWT Session Tokens Without Any User Authentication

CVSS 5.3
LATAM Crypto Platform
LATAM
JWT Issues HackerOne Medium 2026-03
Firebase Configuration & Google Analytics Tracking ID Exposed

All admin panel JavaScript bundles contain the complete Firebase project configuration including API key, project ID, storage bucket, messaging sender ID, app ID, and measurement ID. This is shared across admin.[vendor] and subadmin.[vendor]

CVSS 5.3
SEA E-Commerce Platform
SEA
Firebase Misconfig Responsible Disclosure Medium 2026-03
Guvenlik Bulgulari

Detay: Port 554 (RTSP) TCP baglantisi kabul ediyor ancak hemen Connection Reset by Peer donuyor. Bu davranis birden fazla sebepten kaynaklanabilir

CVSS 5.3
CCTV Infrastructure
Global
Auth Bypass HackerOne Medium 2026-03
Unauthenticated Payment Infrastructure & Business Logic Disclosure

Vulnerable Endpoint: https://[vendor]/api/deposit

CVSS 5.3
EU Gaming Marketplace
EU
Business Logic Responsible Disclosure Medium 2026-03
Comprehensive API Endpoint Exposure via JavaScript Bundle Analysis

Vulnerable Endpoint: https://[vendor]static.com/_nuxt/ad02966.js (467KB main bundle)

CVSS 5.3
EU Gaming Marketplace
EU
WebSocket Issues Responsible Disclosure Medium 2026-03
GraphQL Full Schema Introspection Enabled Without Authentication

Finding 1: GraphQL Full Schema Introspection Enabled Without Authentication Summary: The production GraphQL API at `api.[redacted].money/graphql` allows FULL schema introspection without any authentication. This exposes the complete API architecture including 817 types (310 objects,

CVSS 5.3
African Payment Gateway
Africa
Credential Exposure Responsible Disclosure Medium 2026-03
Binance OAuth Client ID + Permission Scopes Exposed via Unauthenticated API

Finding 44: Binance OAuth Client ID + Permission Scopes Exposed via Unauthenticated API Endpoint: `GET https://www.[redacted].com/v1/binance/oauth` The Binance OAuth integration configuration is exposed via an unauthenticated GET request, revealing the OAuth client_id (`80EvkbrBg

CVSS 5.3
SEA Crypto Exchange
SEA
Subdomain Takeover Responsible Disclosure Medium 2026-03
Customer Email Enumeration via Login (MEDIUM, CVSS 5.3)

Finding 11: Customer Email Enumeration via Login (MEDIUM, CVSS 5.3) - "No matching customer" vs "Invalid username" error differential - 6 confirmed accounts: support@, marketing@, office@, szymon.osadowski@, test@, test1@[redacted].com

CVSS 5.3
Gaming Marketplace
EU
Information Disclosure Responsible Disclosure Medium 2026-03
Admin API Endpoint Structure Fully Enumerated with Method D[redacted]s

Finding 10: Admin API Endpoint Structure Fully Enumerated with Method D[redacted]s Severity: Medium (CVSS 5.3 - AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) Through OPTIONS requests to each admin endpoint, the complete method structure of the admin API has been mapped. While endpoints require

CVSS 5.3
NA Online Casino
NA
Rate Limit Bypass Responsible Disclosure Medium 2026-03
MinIO Console Publicly Accessible (MEDIUM)

Finding 1: MinIO Console Publicly Accessible (MEDIUM) URL: https://minio-console.blix.gg/ MinIO Console (AGPL lisansli) internet uzerinden erisime acik. Login formu gorunuyor: - Login strategy: "form" (username/password)

CVSS 5.3
KYC Mass Scan
Global
Rate Limit Bypass Responsible Disclosure Medium 2026-03
Blog Internal API URL Disclosure (API_INNER_URL) (MEDIUM)

Finding 5: Blog Internal API URL Disclosure (API_INNER_URL) (MEDIUM) Summary: Blog'un Nuxt.js SSR publicRuntimeConfig'i, dahili API URL'sini (`http://[ip]:7008`) ifsa etmektedir. Bu bilgi SSRF saldirilarinda kullanilabilir. Vulnerable Endpoint: `https://blog.[redacted].store/` (SS

CVSS 5.3
SEA Crypto Exchange
SEA
SSRF Responsible Disclosure Medium 2026-03
Yii2 Framework Debug Information Disclosure on dev-account-api.[redacted].com (MEDIUM)

Finding 3: Yii2 Framework Debug Information Disclosure on dev-account-api.[redacted].com (MEDIUM) Summary: The development account API at dev-account-api.[redacted].com leaks full Yii2 framework exception d[redacted]s including PHP class names, exception types, and error messages. This

CVSS 5.3
Gaming Marketplace
SEA
Information Disclosure Responsible Disclosure Medium 2026-03
[redacted]_CODE_BLOCKING_LIMIT_OVERRIDE - Context Window Limit Bypass

Finding 1: [redacted]_CODE_BLOCKING_LIMIT_OVERRIDE - Context Window Limit Bypass Summary: The `[redacted]_CODE_BLOCKING_LIMIT_OVERRIDE` environment variable allows overriding the blocking limit for context window size, potentially allowing users to send larger context windows than their

CVSS 5.3
AI SaaS Provider
NA
RCE Responsible Disclosure Medium 2026-03
Staging Environment Shares Production Database and Backend

Finding 6: Staging Environment Shares Production Database and Backend Severity: MEDIUM (CVSS 5.3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) Summary: `staging.[redacted].cc` ayni production backend ve veritabanina baglidir. Staging uzerinde bulunan tum vulnerability'ler dogrud

CVSS 5.3
NA Online Casino
NA
Rate Limit Bypass Responsible Disclosure Medium 2026-03
WordPress Directory Listing Active 2021-2026

Apache directory listing exposes WP upload tree including pum-debug log.

CVSS 5.0
Global P2P Crypto Marketplace
Global
Information Disclosure Responsible Disclosure Medium 2026-03
Unauthenticated User Report Submission Enables Abuse

User report endpoint accepts anonymous submissions allowing mass false-reports against traders.

CVSS 5.0
Global P2P Crypto Marketplace
Global
Business Logic Responsible Disclosure Medium 2026-03
WordPress Blog User Enumeration + XML-RPC Enabled

WP blog permits author enumeration and XML-RPC amplification.

CVSS 5.0
African Fintech Neobank
Africa
Information Disclosure Responsible Disclosure Medium 2026-03
Cached Feature Flags (GrowthBook + Statsig) - Local Tampering

Finding 2: Cached Feature Flags (GrowthBook + Statsig) - Local Tampering Summary: Billing-relevant feature flags are cached in plaintext JSON in `~/.[redacted].json` (GrowthBook) and `~/.[redacted]/statsig/statsig.cached.evaluations.` (Statsig). These can be modified locally. - `~/.claud

CVSS 5.0
AI SaaS Provider
NA
RCE Responsible Disclosure Medium 2026-03
Password Reset Endpoint Without Rate Limit

Unlimited password reset triggers enable inbox flooding at scale.

CVSS 4.3
SEA Banking API Platform
SEA
Rate Limit Bypass Responsible Disclosure Medium 2026-03
Open Redirect on Email Verify Endpoint

Verify endpoint honors unvalidated `returnUrl`, usable for phishing via branded domain.

CVSS 4.3
Indian Crypto Exchange
SEA
Open Redirect Responsible Disclosure Low 2026-04
Email Verification Token Returned in Response Body

Registration response contains verification token removing need for email access.

CVSS 4.3
African Fintech Neobank
Africa
Broken Authentication Responsible Disclosure Low 2026-04
Differential Error Messages Reveal Account Existence

Login/signup endpoints use distinct error strings aiding enumeration.

CVSS 4.3
African Fintech Neobank
Africa
Information Disclosure Responsible Disclosure Low 2026-04
LOW - Storage Subdomain Active

Finding 6: LOW - Storage Subdomain Active URL: `https://storage.[redacted].site` - Returns 403 (storage server exists) - `[redacted].site` - Main landing (Netlify) - `app.[redacted].site` - User app (Netlify)

CVSS 3.8
Mixed Platforms
Global
Information Disclosure Responsible Disclosure Low 2026-04
gtws.bareksa Legacy Subdomain With Old PHP Login/Register

Legacy trading gateway still serves login/register on EOL PHP version without modern hardening.

CVSS 3.7
SEA Investment Platform
SEA
Information Disclosure Responsible Disclosure Low 2026-04
No Rate Limiting on OAuth Token Endpoint

Token endpoint accepts unlimited failed attempts enabling credential stuffing.

CVSS 3.7
EU Crypto ATM Operator
EU
Rate Limit Bypass Responsible Disclosure Low 2026-04
Spark Plan Transition Vulnerability Window

Files cannot download on Spark but upgrade to Blaze would expose all content.

CVSS 3.7
African Crypto Trading Mobile App
Africa
Cloud Misconfig Responsible Disclosure Low 2026-04
Subdomain Infrastructure Disclosure (11 subs)

11 subdomains including accounting, crm, payment visible via DNS.

CVSS 3.7
African Digital Platform
Africa
Information Disclosure Responsible Disclosure Low 2026-04
Source Map Exposure on Shipping Dashboard (CRA + maps)

topship dashboard exposes CRA source maps; 24 JS files with original sources.

CVSS 3.7
African Fintech Cohort
Africa
Information Disclosure Responsible Disclosure Low 2026-04
Tushop Current - Storage Open (non-PII)

Current Tushop project Storage bucket readable but without PII.

CVSS 3.7
African Fintech Firebase Cohort
Africa
Firebase Misconfig Responsible Disclosure Low 2026-04
Grafana v11.6.0 /metrics Endpoint Public

stashfin Grafana exposes Prometheus metrics without authentication.

CVSS 3.7
African Fintech Metabase Cohort
SEA
Information Disclosure Responsible Disclosure Low 2026-04
JWT Error Message Enumeration on Staging Auth

JWT validation errors differentiate signature vs expiry enabling token probing.

CVSS 3.7
African Investment Fintech
Africa
Information Disclosure Responsible Disclosure Low 2026-04
MongoDB Error Stack Trace Leakage

Backend errors expose MongoDB collection and path information.

CVSS 3.7
African P2P Crypto Settlement
Africa
Information Disclosure Responsible Disclosure Low 2026-04
Odoo ERP Integration Hostnames Exposed

Odoo integration endpoints visible in settings.

CVSS 3.7
African Pharma B2B Platform
Africa
Information Disclosure Responsible Disclosure Low 2026-04
Sentry DSN Exposed on Dashboard

Sentry DSN exposed in production bundle enabling event injection.

CVSS 3.7
Crypto Payment Infrastructure
Global
Credential Exposure Responsible Disclosure Low 2026-04
CORS Wildcard on Production + Dev API

Both prod and dev APIs return ACAO:*.

CVSS 3.7
L1 Smart Contract
Global
CORS Responsible Disclosure Low 2026-04
Broffice Redirect to Main App (Exposure)

Back-office subdomain 302 reveals internal naming convention.

CVSS 3.7
LATAM Crypto Platform
LATAM
Information Disclosure Responsible Disclosure Low 2026-04
Laravel Framework Information Disclosure

Error pages reveal Laravel framework usage and _debugbar path.

CVSS 3.7
MENA Payment Giant
MENA
Information Disclosure Responsible Disclosure Low 2026-04
Hardcoded PostHog/3rd-Party Analytics Keys

Frontend exposes analytics project tokens usable for event injection.

CVSS 3.7
MENA Regulated Crypto Exchange
MENA
Credential Exposure Responsible Disclosure Low 2026-04
Extensive Infrastructure Subdomain Exposure

Large set of internal-looking subdomains resolve publicly disclosing infrastructure architecture.

CVSS 3.7
MENA Super-App Fintech
MENA
Information Disclosure Responsible Disclosure Low 2026-04
Deep Link Scheme Hijacking

Custom URL schemes [vendor]:// and bitstore:// registered without proper validation. A malicious app can register the same scheme for intent hijacking

CVSS 3.7
EU Crypto Exchange
EU
Business Logic Responsible Disclosure Low 2026-04
Production Environment Variables Hardcoded in JavaScript

Source: radar.[vendor]/static/js/main.ce51035c.js

CVSS 3.7
African Identity Verification
Africa
Credential Exposure Responsible Disclosure Low 2026-04
AWS Account ID Disclosure via S3 Error [LOW]

[vendor]-documents S3 bucket'ina yapilan isteklerde AWS Account ID (935364935069) hata mesajinda ifsa edilmektedir. Bu bilgi, IAM role enumeration ve cross-account saldirlar icin kullanilabilir

CVSS 3.7
Crypto Payment Processor
Global
S3 Misconfig Responsible Disclosure Low 2026-04
CSRF Token Static/Long-lived Within Session [LOW]

Vulnerable Component: All authenticated forms

CVSS 3.7
Crypto Exchange Platform
Global
Business Logic HackerOne Low 2026-04
MapTiler API Key Without Domain Restriction

Hardcoded MapTiler key lacks referer restrictions enabling quota abuse.

CVSS 3.1
European Payment Gateway
EU
API Key Exposure Responsible Disclosure Low 2026-04
Yonetici Ozeti

192.168.100.0/24 aginda ARP spoofing MITM saldirisi audit'i yapildi. Ag uzerinde 31 aktif cihaz tespit edildi. IP forwarding'in zaten aktif oldugu (net.inet.ip.forwarding=1) ve agin ARP spoofing'e karsi hicbir koruma mekanizmasinin bulunmadigi belirlendi. Script hazirlandi ve 10 hedef cihazin tamami aktif olarak dogrulandi. Root yetkisi ile cali

CVSS 3.1
CCTV Infrastructure
Global
Business Logic Responsible Disclosure Low 2026-04
Breach Notification Urgency

Critical factors: 1. Breach is ACTIVE -- data is being uploaded to public buckets right now 2. userkycdoc allows DELETE -- attacker could destroy KYC records 3. userkycdoc allows WRITE -- attacker could inject fraudulent KYC documents 4. Government IDs exposed -- identity theft risk is immediate and irreversible 5. Biometric data cannot be "chan

CVSS 3.1
Global Crypto Exchange
Global
KYC Bypass Responsible Disclosure Low 2026-04
Google OAuth Misconfiguration (Strapi)

Google OAuth configured with localhost redirect URI: - Client ID: 610914703543-ifqukul5a6o7870l8s3nn77okq16qacl.apps.googleusercontent.com - Redirect URI: http://localhost:1337/api/connect/google/callback

CVSS 3.1
African SME Lender
Africa
Firebase Misconfig Responsible Disclosure Low 2026-04
Intercom HMAC User Hash Exposed in API Response

Identity hash returned in API response can be misused to impersonate authenticated users in Intercom.

CVSS 2.1
European Payment Gateway
EU
Credential Exposure Responsible Disclosure Low 2026-04
[target] - SonarQube v10.0.0 Exposed [LOW]

Finding 4: [target] - SonarQube v10.0.0 Exposed [LOW] `[target]` runs SonarQube v10.0.0 and is accessible from the internet. While authentication is required and no public projects were found, the exposed version information aids reconnaissance. Additional [target]

CVSS 3.8
SEA Fintech
SEA
Information Disclosure Responsible Disclosure Low 2026-03
LOW - POS Configuration and Dynamic Hash Key Generation Exposure via getpos

Finding 42: LOW - POS Configuration and Dynamic Hash Key Generation Exposure via getpos Severity: Low (CVSS 4.3 - AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) Summary: `/ccpayment/api/getpos` endpoint'i, her istek icin farkli kart BIN'leri ve miktarlar bazinda unik POS konfigurasyonu ve

CVSS 3.8
Turkish Payment Gateway
MENA
Information Disclosure Responsible Disclosure Low 2026-03
[LOW] - Missing Security Headers on Admin Panel

Finding 4 [LOW] - Missing Security Headers on Admin Panel Summary: The admin panel at admin.[redacted].finance lacks critical security headers. - `X-Frame-Options` - Allows clickjacking attacks - `Content-Security-Policy` - No CSP protection

CVSS 3.8
DeFi Lending/DEX Protocol
Global
Admin Panel Exposure Responsible Disclosure Low 2026-03
[redacted] Phase2 Findings

1. Saldirgan [redacted].com'da bir hesap olusturur (normal kullanici) 2. Authenticated session ile /[redacted]'a erisir 3. [redacted] UI tum API endpoint'lerini, parametrelerini ve data model'lerini gosterir 4. /graphql ile tum GraphQL schema'si kesfedilebilir (introspection)

CVSS 3.8
Gaming Marketplace
SEA
Information Disclosure Responsible Disclosure Low 2026-03
Missing Security Headers (Low)

Finding 3: Missing Security Headers (Low) Multiple security-critical HTTP headers are missing across all `.[redacted].am` domains: | Header | www.[redacted].am | cms.[redacted].am | go-cms.[redacted].am | |--------|------------|-------------|----------------|

CVSS 3.8
EU iGaming Operator
EU
XSS Responsible Disclosure Low 2026-03
LOW - Merchant Panel Login Form Action URL Leaks Backend Architecture (app.[redacted].[target]/merchant)

Finding 42: LOW - Merchant Panel Login Form Action URL Leaks Backend Architecture (app.[redacted].[target]/merchant) Summary: merchant.[redacted].[target] login sayfasi, form action URL'si ve asset yollari araciligiyla backend mimarisini (Laravel CSRF token, adminca theme, app.[redacted].[target]/mer

CVSS 3.8
Turkish Payment Gateway
MENA
CORS Responsible Disclosure Low 2026-03
[LOW] - Third-Party API Keys Exposed

Finding 5 [LOW] - Third-Party API Keys Exposed Summary: Multiple third-party API keys are embedded in the admin JavaScript: | TinyMCE | `8pcipe5hjq4vkklqt7jhaiphdwc00w1qa893u7mqwmd12g1r` | Active | | Blocknative | `a7f90c48-943a-4d3a-a8df-6ca5d0f7522a` | Active |

CVSS 3.8
DeFi Lending/DEX Protocol
Global
API Key Exposure Responsible Disclosure Low 2026-03
ASP.NET Stack Trace Disclosure

Server returns full .NET stack traces on error including file paths.

CVSS 3.7
African Crypto Trading Platform
Africa
Information Disclosure Responsible Disclosure Low 2026-03
Mixdesk Chat Integration Session Leak

Mixdesk chat bundles session IDs in URL.

CVSS 3.7
Asian Gift-Card Marketplace
SEA
Information Disclosure Responsible Disclosure Low 2026-03
Customer ID/Hash Disclosure on Registration

Registration response leaks customer ID and hash.

CVSS 3.7
EU Gaming Marketplace
EU
Information Disclosure Responsible Disclosure Low 2026-03
WordPress User Enumeration + SAML SSO Workspace ID

6 users enumerable via WP REST; Google Workspace domain customer ID leaked.

CVSS 3.7
European Crypto Payment Gateway
EU
Information Disclosure Responsible Disclosure Low 2026-03
PrestaShop Error Message Token Leak

Error messages echo callback tokens back, aiding token recovery via forced errors.

CVSS 3.7
European Crypto Payment Processor
EU
Information Disclosure Responsible Disclosure Low 2026-03
Hardcoded Hangfire Dashboard Path

Hangfire dashboard path discoverable via source map.

CVSS 3.7
Gaming Marketplace
EU
Admin Panel Exposure Responsible Disclosure Low 2026-03
Client IP Disclosure via mtc-customerip Header

Five subdomains return the real client IP address in the mtc-customerip response header and country code in mtc-country

CVSS 3.7
EU Gaming Key Marketplace
EU
CORS Responsible Disclosure Low 2026-03
Chatwoot /auth/password/new - 500 Internal Server Error

The Chatwoot password reset page at /auth/password/new returns a 500 Internal Server Error, indicating a misconfiguration (likely SMTP/email not properly configured for password reset emails)

CVSS 3.7
NA Gift Card Supplier
NA
Admin Panel Exposure Responsible Disclosure Low 2026-03
LOW - Third-Party API Keys Exposed

CVSS 3.7
African Payment Processor
Africa
API Key Exposure Responsible Disclosure Low 2026-03
WooCommerce on Help Center - Unnecessary Attack Surface

help.[vendor] (yardim merkezi) uzerinde WooCommerce 9.1.0 yuklu. Bir yardim merkezi icin e-ticaret plugin'i gereksiz bir saldiri yuzeyi olusturur. WooCommerce REST API v1/v2/v3 endpointleri ve 200+ route acik

CVSS 3.7
African Remittance Platform
Africa
Rate Limit Bypass Responsible Disclosure Low 2026-03
Apache Server Version Disclosure

Apache versiyonu response header'larinda ve hata sayfalarinda aciga cikiyor: Apache/2.4.58 (Ubuntu)

CVSS 3.7
EU Digital Goods Marketplace
EU
Business Logic Responsible Disclosure Low 2026-03
API Documentation Publicly Accessible

documentation.[vendor] uzerinde barindirilan API dokumanasyonu (ReadMe.io), HMAC-SHA256 kimlik dogrulama akisi, API-Hash header olusturma yontemleri ve tum endpoint detaylarini acik olarak paylasmaktadir

CVSS 3.7
African Crypto Exchange
Africa
Business Logic Responsible Disclosure Low 2026-03
Alibaba Cloud ARMS RUM Monitoring PID Exposed -- Application Monitoring Data Leakage Risk

KChat Vue.js SPA'sinda Alibaba Cloud ARMS (Application Real-time Monitoring Service) yapilandirmasi, monitoring PID'si ve data endpoint'i acik olarak ifsa edilmektedir. Bu bilgi, monitoring verilerine erisim veya veri enjeksiyonu icin kullanilabilir

CVSS 3.7
Gaming Marketplace
Global
Business Logic HackerOne Low 2026-03
Akamai WAF Bypass via Differential Response

The Akamai WAF on account-api.[vendor] exhibits differential behavior based on headers. Without auth headers, the request reaches the Yii2 backend (404 JSON). With Authorization: Bearer or X-API-Key headers, Akamai intercepts and returns a 403 Access Denied page. This reveals WAF rule logic

CVSS 3.7
SEA Gaming Marketplace
SEA
Business Logic HackerOne Low 2026-03
Strapi CMS Instance Information Disclosure

Vulnerable Endpoint: https://strapi.[vendor]/

CVSS 3.7
EU Gaming Marketplace
EU
Information Disclosure Responsible Disclosure Low 2026-03
15+ Microservice Health Endpoints Publicly Accessible

Vulnerable Endpoints: Multiple /health endpoints on api.[vendor]

CVSS 3.7
Crypto Gaming Platform
Global
Business Logic Responsible Disclosure Low 2026-03
Unicorn API with Laravel Horizon Installed (Authenticated)

The unicorn.[vendor] subdomain hosts a Laravel API with Horizon queue monitoring installed. While Horizon returns 401 Unauthorized (properly authenticated), its presence reveals infrastructure details and the subdomain serves cookies with the session name ricki_session, indicating it's part of the core platform

CVSS 3.7
SEA E-Commerce Platform
SEA
Admin Panel Exposure Responsible Disclosure Low 2026-03
DRF Browsable API Enabled in Production

Finding 9: DRF Browsable API Enabled in Production Severity: Low (CVSS 3.7 - AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) The Django REST Framework Browsable API is enabled in production, providing an interactive HTML interface for API exploration at `/api/admin/?format=api`. This expose

CVSS 3.7
NA Online Casino
NA
Information Disclosure Responsible Disclosure Low 2026-03
api.blix.gg Backend Down - 502 Bad Gateway (LOW)

Finding 4: api.blix.gg Backend Down - 502 Bad Gateway (LOW) API backend tum endpoint'lerde 502 donduruyor. Bu backend crash'i veya misconfiguration gosteriyor. Impact: API hizmet disi, monitoring ve alerting eksikligi.

CVSS 3.7
KYC Mass Scan
Global
Information Disclosure Responsible Disclosure Low 2026-03
Retroactive Reward Manipulation via Mutable Epoch Parameters

Historical epoch rewards are recomputed using current globals (multiVault, utilization bound) so governance updates retroactively change payouts.

CVSS 3.5
Ethereum Attestation Protocol
Global
Business Logic Code4rena Low 2026-03
Utilization Ratio Division-by-Zero DoS Blocks Reward Claims

_getNormalizedUtilizationRatio divides by an unchecked target value; an attacker can force a zero denominator, DoSing reward claims.

CVSS 3.5
Ethereum Attestation Protocol
Global
Business Logic Code4rena Low 2026-03
Postman Collection Access Key in Public HTML

Documentation page exposes a Postman collection access key in HTML source.

CVSS 3.5
SEA Banking API Platform
SEA
API Key Exposure Responsible Disclosure Low 2026-03
GraphQL Field Enumeration via Error Messages

GraphQL server returns descriptive errors enabling schema field enumeration without authentication.

CVSS 3.1
African Crypto Infrastructure
Africa
GraphQL Issues Responsible Disclosure Low 2026-03
Decommissioned Staging Subdomains with Dangling CF DNS

Multiple Staging Subdomains Return HTTP 530 (Origin DNS Failure) — Decommissioned Services Not Cleaned Up

CVSS 3.1
LATAM Crypto Platform
LATAM
Subdomain Takeover HackerOne Low 2026-03
Webhook HMAC Signing Secret Exposure + Forgery (CRITICAL)

Finding 2: Webhook HMAC Signing Secret Exposure + Forgery (CRITICAL) CVSS 3.1: 8.7 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) Tum 13 webhook endpoint'in HMAC signing secret'lari Svix API uzerinden okunabiliyor. Bu secret'lar, sahte webhook event'leri imzalamak icin kullanilabilir. | E

CVSS 3.1
African Payment Gateway
Africa
Credential Exposure Responsible Disclosure Low 2026-03
Analytics & Tracking IDs Disclosure

Finding 4: Analytics & Tracking IDs Disclosure | Google Analytics 4 | `G-3PVFW01CEZ` | toko_index.html | | Google Tag Manager | `GTM-WWBN8CP` | toko_index.html | | Google Analytics (UA) | `UA-162512367-1` | 1b7de00.modern.js |

CVSS 3.1
SEA Crypto Exchange
SEA
Information Disclosure Responsible Disclosure Low 2026-03
Statsig Evaluation Cache Contains PII and Account Identifiers

Finding 3: Statsig Evaluation Cache Contains PII and Account Identifiers Severity: Low (CVSS 3.1) - Information Disclosure Summary: The Statsig cached evaluations file at `~/.[redacted]/statsig/statsig.cached.evaluations.3ab63d3fa2` contains sensitive identifiers in plaintext. Impact

CVSS 3.1
AI SaaS Provider
NA
Information Disclosure Responsible Disclosure Low 2026-03
Webhook Endpoint Injection (CRITICAL)

Finding 1: Webhook Endpoint Injection (CRITICAL) CVSS 3.1: 9.1 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N) Svix API token uzerinden yeni webhook endpoint olusturulabilir. Bu, saldirganin TUM gelecekteki payment, bank account, consent ve transaction event'lerini kendi sunucusuna yonlend

CVSS 3.1
African Payment Gateway
Africa
RCE Responsible Disclosure Low 2026-03
OSS Bucket Catch-All Misconfiguration

Finding 5: OSS Bucket Catch-All Misconfiguration The `[target]` Alibaba OSS bucket is configured with a catch-all redirect that returns the SPA HTML page (HTTP 200) for ANY path including non-existent resources: The inconsistency (some paths return 200

CVSS 3.1
SEA Crypto Exchange
SEA
Information Disclosure Responsible Disclosure Low 2026-03

Curated selection, anonymized by default. Named vendors, report IDs, and CVEs available to qualified prospects under NDA. New disclosures land here as embargoes lift.

Want the full list under NDA?

Named vendors, report IDs, CVEs, and PoCs available to qualified prospects after a signed NDA.