Disclosures
Public disclosures. Redacted where we have to.
Vulnerabilities we have disclosed through bug bounty platforms, audit contests, and direct vendor coordination. Vendor names are redacted where disclosure is still embargoed or where public attribution was not granted.
Showing 1–25 of 958
| Finding | Target | Category | Channel | Severity | Date |
|---|---|---|---|---|---|
| Fund Theft Chain via total_override + mark_as_paid on Payment Gateway Purchase price can be overridden arbitrarily and marked paid without funds, enabling full fund theft across merchant plugin ecosystem. CVSS 10.0 | European Payment Gateway EU | Business Logic | Responsible Disclosure | Critical | 2026-04 |
| Unlimited Live Payout Creation Without Verification on Payment Gateway Live payout creation endpoint accepts unauthenticated requests producing unlimited real-money payouts to attacker-controlled accounts. CVSS 10.0 | European Payment Gateway EU | Business Logic | Responsible Disclosure | Critical | 2026-04 |
| NoSQL Injection on userDetails Leading to Admin Account Compromise Mongo operator injection on userDetails dumps admin profile including plaintext withdrawal OTP and 2FA token. CVSS 10.0 | SEA P2P Crypto Exchange SEA | NoSQL Injection | Responsible Disclosure | Critical | 2026-04 |
| OAuth2 Token Forge Grants 30-Day Access Token for Any User Token endpoint issues valid 30-day bearer tokens for arbitrary user IDs without credentials, impacting 1.73M investors. CVSS 10.0 | SEA Investment Platform SEA | Broken Authentication | Responsible Disclosure | Critical | 2026-04 |
| Unauthenticated IDOR Dumps 1.73M Investor PII and KYC Photos Profile API returns KTP, bank accounts and KYC identity_file URLs without auth for any user ID. CVSS 10.0 | SEA Investment Platform SEA | IDOR | Responsible Disclosure | Critical | 2026-04 |
| Flamberge Auth-less GCS Bucket Read/Write Across 11 Buckets Signer service issues signed GCS URLs without auth, allowing arbitrary upload/download to KYC and SBN buckets. CVSS 10.0 | SEA Investment Platform SEA | S3 Misconfig | Responsible Disclosure | Critical | 2026-04 |
| JWT HS256 Weak Secret Exposed in APK Cracks to Plaintext Legacy JWT secret `shhhhh` used for session signing; attackers forge tokens for any user or admin. CVSS 10.0 | Indian Crypto Exchange SEA | JWT Issues | Responsible Disclosure | Critical | 2026-04 |
| S3 Bucket KYC Data Mass Exposure with Versioning Recovery Public bucket lists 1352 KYC documents and versioning allows recovery of supposedly deleted files. CVSS 10.0 | Indian Crypto Exchange SEA | S3 Misconfig | Responsible Disclosure | Critical | 2026-04 |
| S3 Bucket KYC Data Mass Exposure 1352 Documents Public ThroughBit bucket lists 1352 KYC docs spanning two pagination batches. CVSS 10.0 | Indian Crypto Exchange SEA | S3 Misconfig | Responsible Disclosure | Critical | 2026-04 |
| Pre-Auth RCE via Fastjson $ref Chain Fastjson $ref gadget chain on CardGoal API yields unauthenticated remote code execution. CVSS 10.0 | Gaming Marketplace SEA | Deserialization | Responsible Disclosure | Critical | 2026-04 |
| Redis Full Control via SSRF + CRLF Injection SSRF chain sends arbitrary Redis commands enabling DB control. CVSS 10.0 | Gaming Marketplace SEA | SSRF | Responsible Disclosure | Critical | 2026-04 |
| Blind SSRF: Internal Network Discovery via Timing Oracle Response timing differentiates reachable vs unreachable internal hosts, enabling network mapping. CVSS 10.0 | Gaming Marketplace SEA | SSRF | Responsible Disclosure | Critical | 2026-04 |
| Fastjson Deserialization: 60+ Dangerous Classes Reachable 60+ gadget classes instantiated via Fastjson body parsing enabling RCE and file write chains. CVSS 10.0 | Gaming Marketplace SEA | Deserialization | Responsible Disclosure | Critical | 2026-04 |
| GraphQL customerSearch Returns PII + Wallet Balances Unauth Cashia customerSearch query returns full PII and wallet balances for 60 customers without auth. CVSS 10.0 | African Neobank Africa | GraphQL Issues | Responsible Disclosure | Critical | 2026-04 |
| back-office OAuth Registration Bypass -> 2.33M Transaction Data Breach OAuth back-office allows registration with arbitrary domain leading to read access on 2.33M transactions. CVSS 10.0 | African Neobank Africa | Auth Bypass | Responsible Disclosure | Critical | 2026-04 |
| payplus-1dfdf - Firestore FULL CRUD Plaintext Passwords + 13,554 KYC Crypto platform Firestore has read/write/update/delete; plaintext passwords, PINs, 13,554 KYC images. CVSS 10.0 | African Fintech Firebase Cohort Africa | Firebase Misconfig | Responsible Disclosure | Critical | 2026-04 |
| Unauthenticated KYC Verification Forgery via SmileID Callback /smile-id/callback accepts forged POSTs without signature/IP check; attacker can KYC-verify ANY user. CVSS 10.0 | West African Crypto Exchange Africa | KYC Bypass | Responsible Disclosure | Critical | 2026-04 |
| Unauthenticated API Keys Endpoint Exposes 288 Business Keys Public endpoint returns 288 merchant API keys enabling attacker to act as any merchant on the platform. CVSS 10.0 | African Crypto Payment Processor Africa | Credential Exposure | Responsible Disclosure | Critical | 2026-04 |
| Internal Backend Exposed on Eight Ports With No Firewall Backend host reachable on eight internal ports directly from the internet, exposing databases and admin services without firewall. CVSS 10.0 | African Crypto Payment Processor Africa | Cloud Misconfig | Responsible Disclosure | Critical | 2026-04 |
| Redis Commander Unauth Full Read/Write Access Redis Commander UI exposed without auth allowing arbitrary read/write against production Redis. CVSS 10.0 | African Crypto Payment Processor Africa | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-04 |
| Kafdrop Unauth Full Kafka Access Kafdrop UI accessible without credentials disclosing 29 topics with live payment messages and offsets. CVSS 10.0 | African Crypto Payment Processor Africa | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-04 |
| EVM Webhook Deposit Injection (Production) Production EVM deposit webhook lacks signature validation enabling injection of forged confirmed deposits. CVSS 10.0 | African Crypto Payment Processor Africa | Webhook Forgery | Responsible Disclosure | Critical | 2026-04 |
| Eight+ Payment Gateway Webhooks Forgeable All eight inbound payment gateway webhooks accept forged payloads permitting arbitrary balance manipulation. CVSS 10.0 | African Crypto Payment Processor Africa | Webhook Forgery | Responsible Disclosure | Critical | 2026-04 |
| Complete Attack Chain: Create->Forge->Validate = Free Money Chain of unauthenticated transaction creation plus webhook forgery and broken validation yields free settled funds. CVSS 10.0 | African Crypto Payment Processor Africa | Business Logic | Responsible Disclosure | Critical | 2026-04 |
| Internal Webhooks Accept Negative Amounts and Race Conditions All eight internal webhooks accept negative amounts and exhibit race conditions enabling arbitrary balance inflation. CVSS 10.0 | African Crypto Payment Processor Africa | Business Logic | Responsible Disclosure | Critical | 2026-04 |
| RabbitMQ Default Credentials (guest/guest) RabbitMQ broker retains guest/guest default allowing full AMQP access including administrative actions. CVSS 10.0 | EU iGaming Operator EU | Default Creds | Responsible Disclosure | Critical | 2026-04 |
| SumSub Webhook Forgery -- KYC Bypass POST https://[vendor]/kyc/sumsub_webhook/ Content-Type: application/json CVSS 10.0 | EU Crypto Exchange EU | KYC Bypass | Responsible Disclosure | Critical | 2026-04 |
| [vendor] S3 Bucket Full Compromise - Deep Exfiltration Proof Target: [vendor] Asset: AWS S3 Bucket [vendor] (us-west-2) Status: VERIFIED - Full R/W/D Access Proven CVSS 10.0 | EU Crypto Exchange EU | S3 Misconfig | Responsible Disclosure | Critical | 2026-04 |
| S3 Full Read/Write/Delete via Unauthenticated Cognito Role AWS Cognito Identity Pool us-east-1:b1cc32f2-117f-41c3-b797-e19d0e41b75e unauthenticated erisime acik. Elde edilen IAM role amplify-korapaykyc-dev-41238-unauthRole, [vendor] S3 bucket'ina s3:PutObject, s3:GetObject, s3:DeleteObject, s3:ListBucket dahil tam erisim sagliyor. Bucket versioning KAPALI. Bu, saldirganin KYC dokumentlarini okuyabil CVSS 10.0 | EU Crypto Exchange EU | S3 Misconfig | Responsible Disclosure | Critical | 2026-04 |
| Firebase Storage Full R/W/D — 247,303+ Customer Documents > UPGRADED from original report: File count increased from 20,000 to 247,303+. WRITE and DELETE access confirmed CVSS 10.0 | African SME Lender Africa | Firebase Misconfig | Responsible Disclosure | Critical | 2026-04 |
| [vendor] - Full Account Takeover Chain (End-to-End Proof) Target: [vendor] / [vendor] Classification: CRITICAL (CVSS 10.0) Attack Type: Full Account Takeover Chain (Password Reset OTP Brute-Force + No Email Change OTP + JWT Over-Expiry) CVSS 10.0 | Crypto Payment Processor Global | Broken Authentication | Responsible Disclosure | Critical | 2026-04 |
| (UPDATED): Source Map -> Full Exploitation Achieved New evidence: - Source map-den elde edilen melumatla 3 hesab yaradildi - Butun endpoint-ler test edildi ve 8 yeni vulnerability tapildi CVSS 10.0 | Crypto Payment Processor Global | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| ATO via OTP Brute Force (No Rate Limit) Total: 12 Critical + 6 High + 3 Medium = 21 unique findings CVSS 10.0 | Crypto Payment Processor Global | Broken Authentication | Responsible Disclosure | Critical | 2026-04 |
| JWT Forgery + IDOR: Full Account Takeover & Wallet Access POC Researcher: Atilla Memmedli CVSS 10.0 | Crypto Exchange Platform Global | IDOR | Responsible Disclosure | Critical | 2026-04 |
| OTP Token Injection Leads to Mass Account Takeover Accounts list endpoint returns server-generated OTP tokens allowing attacker to set password and take over any account zero-click. CVSS 9.9 | African Neobank Africa | Broken Authentication | Responsible Disclosure | Critical | 2026-04 |
| Open Merchant Registration with Automatic Admin Privileges Anyone can signup and is auto-granted admin role with no email or KYC verification on production merchant panel. CVSS 9.8 | European Payment Gateway EU | Privilege Escalation | Responsible Disclosure | Critical | 2026-04 |
| Price Manipulation via Negative Debt Parameter Negative debt values accepted during purchase create, reducing total due to near-zero for paid transactions. CVSS 9.8 | European Payment Gateway EU | Business Logic | Responsible Disclosure | Critical | 2026-04 |
| Unauthenticated OTP Disclosure via trade/userDetails Enables ATO trade/userDetails endpoint returns withdrawal OTP without authentication, making full account takeover one-step. CVSS 9.8 | SEA P2P Crypto Exchange SEA | Broken Authentication | Responsible Disclosure | Critical | 2026-04 |
| Predictable apiKey via Exposed encryptAlgo (Forge Any User Token) Source map exposes encryptAlgo allowing client-side generation of any user's apiKey including admin. CVSS 9.8 | SEA P2P Crypto Exchange SEA | JWT Issues | Responsible Disclosure | Critical | 2026-04 |
| Auth Middleware Bypass on Crypto Withdrawal Endpoint withdraw_amount endpoint passes decryptAlgo but skips identity check allowing unauthorized withdrawals with forged apiKey. CVSS 9.8 | SEA P2P Crypto Exchange SEA | Auth Bypass | Responsible Disclosure | Critical | 2026-04 |
| Zero OTP Rate Limiting Enables 5-Minute Account Brute Force 50 sequential OTP attempts all return 404 with zero throttling allowing exhaustive OTP brute force. CVSS 9.8 | SEA P2P Crypto Exchange SEA | Rate Limit Bypass | Responsible Disclosure | Critical | 2026-04 |
| Production PG2 JWT Issuer Validation Bypass for Fund Transfer Production payment gateway accepts JWTs from enumerable issuers without signature verification on 17 fund-transfer routes. CVSS 9.8 | Indian Investment Broker SEA | JWT Issues | Responsible Disclosure | Critical | 2026-04 |
| GCS Bucket Public Listing Exposes Admin Panel Backup + Source Maps Public bucket lists 52 source maps and admin panel tarball with 407 source files including investor service code. CVSS 9.8 | SEA Investment Platform SEA | Cloud Misconfig | Responsible Disclosure | Critical | 2026-04 |
| Cashfree Payment Gateway Secret Key Exposed in APK Live Cashfree secret key embedded in APK enables server-side payment creation on attacker's behalf. CVSS 9.8 | Indian Crypto Exchange SEA | API Key Exposure | Responsible Disclosure | Critical | 2026-04 |
| Unauthenticated Cryptocurrency Withdrawal Endpoints Withdrawal endpoints skip JWT validation, allowing attacker-triggered BTC/ETH outflows. CVSS 9.8 | Indian Crypto Exchange SEA | Auth Bypass | Responsible Disclosure | Critical | 2026-04 |
| Rancher Kubernetes Management API Publicly Accessible Two Rancher K8s management APIs reachable from the internet, one at v2.11.1, allowing cluster-wide control. CVSS 9.8 | MENA Crypto Exchange MENA | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-04 |
| HMAC API Signing Secret Exposed in Client-Side JS Young Platform exchange JS bundle embeds HMAC secret used to sign all BFF and Identity API requests. CVSS 9.8 | European Crypto Exchange EU | Credential Exposure | Responsible Disclosure | Critical | 2026-04 |
| Unauthenticated User Deletion Endpoint Cardify /api/user/tests/delete_user.php deletes arbitrary user accounts without auth. CVSS 9.8 | African Crypto Gift Card Platform Africa | BFLA | Responsible Disclosure | Critical | 2026-04 |
| Admin Authentication Bypass via Telegram Parameter (13 Endpoints) Setting ?telegram=1 on 13 admin endpoints bypasses session check and triggers real bank payouts/KYC approval. CVSS 9.8 | African Crypto Gift Card Platform Africa | Auth Bypass | Responsible Disclosure | Critical | 2026-04 |
| Unauthenticated Gift Card Callback Forgery Gift card OCR callback accepts forged results crediting attacker cards. CVSS 9.8 | Gaming Marketplace SEA | Webhook Forgery | Responsible Disclosure | Critical | 2026-04 |
| CORS Origin Reflection + Credentials (Admin Takeover) Admin API reflects arbitrary origin with credentials enabling cross-origin admin ATO. CVSS 9.8 | Gaming Marketplace SEA | CORS | Responsible Disclosure | Critical | 2026-04 |
| Temporal UI Unauthenticated Production Payment Data Exposure Temporal UI publicly reachable enabling workflow history viewing and namespace creation. CVSS 9.8 | African Neobank Africa | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-04 |
| apexmetanew - Firestore + Storage Open Same operator as payplus; Firestore and Storage both open with financial data. CVSS 9.8 | African Fintech Firebase Cohort Africa | Firebase Misconfig | Responsible Disclosure | Critical | 2026-04 |
| BTC Wallet Abuse (payplus/apexmetanew) Virtual Card Theft 446 virtual cards accessible via open Firestore enabling direct card abuse. CVSS 9.8 | African Fintech Firebase Cohort Africa | Business Logic | Responsible Disclosure | Critical | 2026-04 |
| Firebase Realtime Database Open Read/Write RTDB default rules allow anonymous writes; already exploited by external party. CVSS 9.8 | African Investment Fintech Africa | Firebase Misconfig | Responsible Disclosure | Critical | 2026-04 |
| Monnify Webhook Forgery No Signature Validation production.embed accepts Monnify webhooks without verifying monnify-signature HMAC; fake payment injection. CVSS 9.8 | African Investment Fintech Africa | Webhook Forgery | Responsible Disclosure | Critical | 2026-04 |
| Metabase Setup Token Exposed Config Dump metabase.dexpay.io leaks setup-token + 118 config keys unauth. CVSS 9.8 | African P2P Crypto Settlement Africa | Credential Exposure | Responsible Disclosure | Critical | 2026-04 |
| AirSign Microservice Unauth Registration + Ed25519 Key AirSign registers any caller producing Ed25519 key unlocking full platform access. CVSS 9.8 | African Payment Platform Africa | Auth Bypass | Responsible Disclosure | Critical | 2026-04 |
| BFLA on 180+ Admin Mutations via USER JWT Any USER JWT can call createAdmin, assignUserRole, updateKycStatus, automateWithdrawal admin mutations. CVSS 9.8 | Series B African Fintech Africa | BFLA | Responsible Disclosure | Critical | 2026-04 |
| Zero-Click ATO via Unthrottled Reset OTP + Oracle forgotPassword emits unlimited simultaneous OTPs with differential error oracle; ~3 min per victim. CVSS 9.8 | Series B African Fintech Africa | Broken Authentication | Responsible Disclosure | Critical | 2026-04 |
| adminSwapCurrencies BFLA Financial Theft USER JWT can swap any user's funds at manipulated rate; $22.5M platform-wide exposure. CVSS 9.8 | Series B African Fintech Africa | BFLA | Responsible Disclosure | Critical | 2026-04 |
| Unauthenticated User Profile Modification via SmileID Callback Same SmileID callback overwrites displayName, first/last name, and address for any user. CVSS 9.8 | West African Crypto Exchange Africa | Access Control | Responsible Disclosure | Critical | 2026-04 |
| Production OTP Bypass via Test Account Backdoor Phone 2250749994257 accepts any non-empty OTP; issues 90-day JWT with real production KYC data. CVSS 9.8 | West African Crypto Exchange Africa | Auth Bypass | Responsible Disclosure | Critical | 2026-04 |
| Monnify Webhook Signature Bypass Enables Unauthenticated Deposit Injection Monnify webhook endpoint accepts arbitrary payloads without HMAC signature or IP whitelist validation, allowing attacker to forge deposit/refund/disbursement events and credit arbitrary amounts. CVSS 9.8 | African Neobank Africa | Webhook Forgery | Responsible Disclosure | Critical | 2026-04 |
| Password Reset OTP Brute Force Leads to Full Account Takeover Password reset endpoint allows 84 consecutive OTP attempts per window with unlimited OTP requests. 4-6 digit OTP keyspace exhaustible within hours enabling account takeover of any user. CVSS 9.8 | African Neobank Africa | Broken Authentication | Responsible Disclosure | Critical | 2026-04 |
| Admin Backoffice Open Registration Admin backoffice exposes open registration, enabling any actor to self-provision an administrator account. CVSS 9.8 | African Neobank Africa | Access Control | Responsible Disclosure | Critical | 2026-04 |
| Unauthenticated Mass OTP and User Data Exposure Public accounts endpoint returns full user list with active OTP tokens permitting mass takeover pipeline. CVSS 9.8 | African Neobank Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| NextAuth Authentication Bypass via Social Login Flow NextAuth callback accepts attacker-controlled userId without proving social identity ownership, issuing session for arbitrary users. CVSS 9.8 | European iGaming Platform EU | Auth Bypass | Private Engagement | Critical | 2026-04 |
| Firebase Storage Public Read/Write/Delete - 3277 Files Exposed Firebase Storage bucket permits anonymous read, write and delete across 3277 user/course files enabling supply-chain upload and destructive actions. CVSS 9.8 | EU EdTech Platform EU | Firebase Misconfig | Responsible Disclosure | Critical | 2026-04 |
| Registration PIN Verification Bypass via activate-account Registration flow lets attacker skip PIN verification and directly invoke activate-account, creating activated accounts without email control. CVSS 9.8 | EU EdTech Platform EU | Auth Bypass | Responsible Disclosure | Critical | 2026-04 |
| Change-Password IDOR Without Authorization Check Authenticated user can change password of any other user via unprotected change-password endpoint. CVSS 9.8 | EU EdTech Platform EU | IDOR | Responsible Disclosure | Critical | 2026-04 |
| Metabase Setup Token Exposed (Unauth Admin Reprovisioning) Metabase session properties leak valid setup token usable to reconfigure admin when setup flow not finalized. CVSS 9.8 | West African B2B Fintech Africa | Cloud Misconfig | Responsible Disclosure | Critical | 2026-04 |
| Kafka UI Complete Unauthenticated Access Kafka UI reachable without auth exposing 55 topics including KYC and payment message streams. CVSS 9.8 | African Fintech Marketplace Africa | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-04 |
| Metabase Setup Token Exposed (bi.koywe) Metabase BI instance exposes unrotated setup token enabling admin provisioning. CVSS 9.8 | LATAM Crypto Platform LATAM | Cloud Misconfig | Responsible Disclosure | Critical | 2026-04 |
| Metabase Setup Token Exposed (bi.tiendacrypto) Second Metabase BI tenant exposes active setup token with unauthenticated admin bootstrap path. CVSS 9.8 | LATAM Crypto Platform LATAM | Cloud Misconfig | Responsible Disclosure | Critical | 2026-04 |
| Metabase Setup Token Exposure (bi.vpay.africa) BI instance exposes active Metabase setup token enabling admin provisioning bypass. CVSS 9.8 | African Payment Platform Africa | Cloud Misconfig | Responsible Disclosure | Critical | 2026-04 |
| Firestore Database — 74,676 Records with PII/BVN Exposure > NEW FINDING — Not in original report CVSS 9.8 | African SME Lender Africa | Firebase Misconfig | Responsible Disclosure | Critical | 2026-04 |
| Firebase Storage Production Bucket - Complete KYC Data Exposure https://firebasestorage.googleapis.com/v0/b/[vendor].appspot.com/o CVSS 9.8 | African SME Lender Africa | Firebase Misconfig | Responsible Disclosure | Critical | 2026-04 |
| Metabase Setup-Token Exposure Finding: Metabase instance exposes setup-token in session properties, enabling FULL admin takeover CVSS 9.8 | SEA Crypto Exchange SEA | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-04 |
| [vendor] Admin API — Spring Boot Actuator Deep-Dive + Origin Bypass Chain Target: admin-api.[vendor]:7443 ([vendor]-PRO-ADMIN-SERVICE) Base URL: https://admin-api.[vendor]:7443/AdminApi/actuator Stack: Spring Boot 3.x, Tomcat 10.1.4, Java 17.0.11+7-LTS-207, Oracle DB, Redis 7.0.15, SMTP2GO CVSS 9.8 | Global Crypto Exchange Global | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-04 |
| [vendor] (HashCash Consultants) - Infrastructure Vulnerability Assessment Target: [vendor], hashcashconsultants.com, hcx.com Scope: Infrastructure, exposed services, misconfigurations CVSS 9.8 | Global Crypto Exchange Global | KYC Bypass | Responsible Disclosure | Critical | 2026-04 |
| [vendor] API Authentication & Authorization Findings Target: [vendor] (White-Label Crypto Exchange Platform) Scope: API auth bypass, IDOR, BOLA/BFLA, privilege escalation CVSS 9.8 | Global Crypto Exchange Global | IDOR | Responsible Disclosure | Critical | 2026-04 |
| [vendor] - Firebase Veritabani Tam Erisim (Okuma + Yazma) Tarih: 2026-04-10 Hedef: [vendor] ([vendor] - Nijerya Toplu Gida Alisveris Platformu) Platform: Firebase (farmcrowdy-727ba) + Medusa.js (Next.js) Toplam Bulgu: 3 (1 Critical + 1 High + 1 Medium) CVSS 9.8 | African E-Commerce Platform Africa | Firebase Misconfig | Responsible Disclosure | Critical | 2026-04 |
| Security Finding [redacted].io / [redacted][target] - Critical Security Assessment Target: app.[redacted].io, secureapi.[redacted][target], admin.[redacted][target] Total Findings: 12 (7 Critical + 3 High + 2 Medium) FINDING 1: Arbitrary BTC Balance Manipulation via Unauthenticated-Like Endpoin CVSS 9.8 | MENA Crypto Exchange MENA | API Key Exposure | Responsible Disclosure | Critical | 2026-04 |
| Phase3 Critical Findings [redacted].io / [redacted][target] - Phase 3: CVSS 10 Findings Target: [redacted].io / [redacted][target] / [target] / [target] Tester: Atilla Memmedli (Authorized Bug Bounty) NEW CRITICAL FINDINGS: 8 Verified (5 Critical + 2 High + 1 Medium) CVSS 9.8 | MENA Crypto Exchange MENA | JWT Issues | Responsible Disclosure | Critical | 2026-04 |
| (NEW): Admin Account Takeover via Password Reset Chain + OTP Brute Force Finding 22 (NEW): Admin Account Takeover via Password Reset Chain + OTP Brute Force Severity: CRITICAL (CVSS 9.8 - AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The admin password reset endpoint (`/api/v1/admin/auths/reset-password`) is fully accessible with only a device token (no user a CVSS 9.8 | Nigerian Payment Provider Africa | Rate Limit Bypass | Responsible Disclosure | Critical | 2026-04 |
| API Signature Without Server Secret on 9 Brand APIs Signing algorithm runs client-side without server secret, enabling arbitrary request signing. CVSS 9.6 | Gaming Marketplace SEA | Broken Authentication | Responsible Disclosure | Critical | 2026-04 |
| Django DEBUG=True - Full Settings Dump with Admin Token Django debug reveals 240 settings including Redis/RabbitMQ/Admin bypass token. CVSS 9.6 | African Payment Platform Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| DEV Payment Gateway With Full Fund Transfer API Publicly Reachable Non-production PG2 endpoint exposed to internet with all 17 fund routes live, forming a safe-to-exploit staging replica. CVSS 9.5 | Indian Investment Broker SEA | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-04 |
| Arbitrary File Write via FileOutputStream Deserialization FileOutputStream reachable via deserialization lets attackers write arbitrary files to server. CVSS 9.5 | Gaming Marketplace SEA | Deserialization | Responsible Disclosure | Critical | 2026-04 |
| ServerSocket Port Binding via Deserialization ServerSocket instantiation allows listener binding as foothold for post-exploit. CVSS 9.5 | Gaming Marketplace SEA | Deserialization | Responsible Disclosure | Critical | 2026-04 |
| GCS Bucket cashiacdn Public Listing of 14,121 Objects Public bucket lists 14121 objects including KRA PIN certificates and KYC attachments. CVSS 9.5 | African Neobank Africa | Cloud Misconfig | Responsible Disclosure | Critical | 2026-04 |
| — CVSS 10.0 — JWT Forge → Tüm Merchant API Erişimi Finding 5 — CVSS 10.0 — JWT Forge → Tüm Merchant API Erişimi JWT Secret: `714a7ea9a0ef4d7886f41fd8b782fa7d` (HS256) Kaynak: GCE sunucu `/var/www/html/proxy/.env` + Cloud Run env var Etkilenen Merchant'lar (SUPER_ADMIN): CVSS 9.5 | African Remittance Provider Africa | JWT Issues | Responsible Disclosure | Critical | 2026-04 |
| Unauthenticated Laravel Log Viewer Exposes DB Backup Emails and Admin Logs Staging Laravel log-viewer is accessible without auth and leaks database backup delivery metadata, admin email, SQL traces, forge paths and webhook payloads. CVSS 9.4 | African Neobank Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| GKE Kubernetes API Server Publicly Exposed eramba subdomain exposes Kubernetes API server with version and verbose health responses. CVSS 9.3 | African Investment Fintech Africa | Cloud Misconfig | Responsible Disclosure | Critical | 2026-04 |
| Unrestricted STOMP Topic Wildcard Subscription STOMP broker accepts wildcard topic subscription exposing 2903 live messages including odds and user context. CVSS 9.3 | EU iGaming Operator EU | WebSocket Issues | Responsible Disclosure | Critical | 2026-04 |
| Unauthenticated File Write + Webhook Forgery Chain [CRITICAL] Vulnerable Components: - https://payout.[vendor]/file_creator.php → writes to HOOK_xLmu... directory - https://payout.[vendor]/file_reloadly_creator.php → writes to ACTIVE HOOK_JXO3... directory - https://payout.[vendor]/redbiller/ → directory listing confirms file creation CVSS 9.3 | Crypto Exchange Platform Global | Webhook Forgery | Responsible Disclosure | Critical | 2026-04 |
| Security Finding 1. API Token-Only Authentication (No IP Restriction) The API is protected only by an `X-Auth-Token` header. If the API token is leaked (via .env, git history, or brute force), ALL document templates, submissions, and submitter data become accessible. There is no IP allowlist or a CVSS 9.3 | Nigerian Payment Provider Africa | Rate Limit Bypass | Responsible Disclosure | Critical | 2026-04 |
| Odoo ERP Public Signup + Full Stack Trace Information Disclosure [CRITICAL] Finding 1: Odoo ERP Public Signup + Full Stack Trace Information Disclosure [CRITICAL] Summary: erp.[redacted].ng adresinde Odoo ERP sistemi public internet'e acik ve /web/signup sayfasi aktif. Herhangi biri hesap olusturabilir. Ayrica tum hata yanitlarinda full Python stack trace'l CVSS 9.3 | Nigerian Neobank Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| Security Finding 1. Attacker fetches `https://merchant.[redacted].ai/app-config.js` 2. Extracts [target] WRITE key -- can send emails/push notifications to all [redacted] merchants 3. Extracts Rutter production key -- can access merchant e-commerce integrations 4. Extracts GetStream key -- can access re CVSS 9.3 | MENA BNPL Provider MENA | Firebase Misconfig | Responsible Disclosure | Critical | 2026-04 |
| — CVSS 10.0 — PROD PostgreSQL Direkt Erişim (12 Veritabanı) Finding 1 — CVSS 10.0 — PROD PostgreSQL Direkt Erişim (12 Veritabanı) Endpoint: `[ip]:5432` (GCP Cloud SQL `[redacted]-prd`, europe-west2) — TCP AÇIK Credentials: `[redacted]-prd:idC4KeJkaaN!AoNp` Kaynak: `[redacted]-ccee8_cloudbuild/source/.tgz` → `prd.yml` CI/CD arşivi CVSS 9.3 | African Remittance Provider Africa | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-04 |
| Disclosure Report | 13 | Password Reset OTP Brute Force (0 rate limit, 500+ attempts) | 8.5 | | 14 | Biometric Authentication Endpoint Discovered (/api/biometric) | 8.5 | | 15 | Nova Files Preview - Potential Arbitrary File Read | 8.5 | | 16 | Bearer Tokens Survive Password Change (persistent ATO) CVSS 9.3 | African Crypto Exchange Africa | CORS | Responsible Disclosure | Critical | 2026-04 |
| Public Postman API Documentation with Production Data [CRITICAL] Finding 3: Public Postman API Documentation with Production Data [CRITICAL] Vulnerable Endpoint: https://docs.[redacted].com/ [redacted]'nin Merchant API'si Postman Documenter ile herkese acik dokumante edilmistir. Dokumantasyon 21 endpoint, request body ornekleri, response ornekleri, me CVSS 9.3 | African Fintech Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| Mid Size Platform Targets Mid-Size Platform Targets - 10 Verified Targets with Initial Findings Tarama Tipi: Reconnaissance + Initial Vulnerability Discovery TARGET 1: [redacted] ([redacted].co) - Saudi BNPL Unicorn Company: [redacted], Saudi Arabia BNPL (Buy Now Pay Later) CVSS 9.3 | Mid-size Platforms Global | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| CRITICAL - Admin Panel Source Map Exposure (6.1 MB) Finding 1: CRITICAL - Admin Panel Source Map Exposure (6.1 MB) URL: `https://adminer.[redacted].site` Source Maps: ALL `.js.map` files accessible (200 OK) - `app.b9a4e86d.js.map` - 111 KB CVSS 9.3 | Mixed Platforms Global | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| Firebase Mass Scan Firebase Misconfiguration Mass Scan -- 2026-04-10 Scanned 100+ crypto/fintech platforms for Firebase security misconfigurations. Found 3 platforms with open Firebase Storage, 2 platforms with open Realtime Database, and 1 platform with open Firestore. The most critical finding is CVSS 9.3 | Firebase Mass Scan Global | Firebase Misconfig | Responsible Disclosure | Critical | 2026-04 |
| Source Map Exposure - API Endpoints and Bank Account Validation Logic [CRITICAL] Finding 2: Source Map Exposure - API Endpoints and Bank Account Validation Logic [CRITICAL] Summary: win.[redacted].ng ("[redacted] Accounts Validation") uygulamasinda source map dosyalari public erisime acik. Source map'ler, uygulamanin tam kaynak kodunu icerir ve icinden unauthentica CVSS 9.3 | Nigerian Neobank Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| PIN Overwrite Without Old PIN Verification (CRITICAL - CVSS 8.8) Finding 13: PIN Overwrite Without Old PIN Verification (CRITICAL - CVSS 8.8) Vulnerable Endpoint: `POST https://thor.[redacted].com/api/user/pin` Type: Broken Authentication (CWE-620) The `POST /api/user/pin` endpoint allows overwriting an existing transaction PIN without verifying CVSS 9.3 | African Crypto Exchange Africa | XSS | Responsible Disclosure | Critical | 2026-04 |
| CRITICAL - 60+ Admin API Endpoints Exposed Finding 2: CRITICAL - 60+ Admin API Endpoints Exposed Via source map analysis, all admin API endpoints discovered: CVSS 9.3 | Mixed Platforms Global | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| CRITICAL - Internal Support App Full Source Code Exposure (12.8MB, 500 Files, 199 GraphQL Operations) Finding 1: CRITICAL - Internal Support App Full Source Code Exposure (12.8MB, 500 Files, 199 GraphQL Operations) The [redacted] internal support application at `supportapp-new.[redacted].com` exposes a 12.8MB source map containing 500 application source files and 199 GraphQL mutation/query d CVSS 9.3 | African Neobank Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| D[redacted]s - Extracted API Endpoints Vulnerability D[redacted]s - Extracted API Endpoints Transaction Service (12+ endpoints): Extracted User Model / Permission System Extracted Third-Party Integrations CVSS 9.3 | African Fintech Africa | Access Control | Responsible Disclosure | Critical | 2026-04 |
| New Platforms Critical Findings Yeni Platform Taramalari - Kritik Bulgular Toplam Hedef: 5 platform (3 CRITICAL + 2 HIGH attack surface) 1. [target] - CRITICAL (Stablecoin Payment Infrastructure) Sektor: Afrika stablecoin odeme altyapisi (Nigeria, Ghana, Kenya, South Africa) CVSS 9.3 | Mixed Platforms Global | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| Unauthenticated Admin Configuration Data Exposure Admin config endpoint accessible without auth exposes admin user IDs and platform secrets. CVSS 9.1 | SEA P2P Crypto Exchange SEA | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| Mass Wallet Address IDOR Exposing 600+ Users' Crypto Addresses Wallet address endpoint dumps 600+ user addresses without auth, enabling targeted deanonymisation. CVSS 9.1 | SEA P2P Crypto Exchange SEA | IDOR | Responsible Disclosure | Critical | 2026-04 |
| getAllTradeList Unauthenticated: 3647 Trades + 120 Plaintext Emails Public trade list dumps 3647 trades, counterparty emails, and amounts, exposing KYC-adjacent data. CVSS 9.1 | SEA P2P Crypto Exchange SEA | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| Signup Response Leaks 2FA Secret, Bcrypt Hash and OTP Registration response returns the full Mongo user document including TOTP secret, bcrypt hash and email OTP. CVSS 9.1 | SEA P2P Crypto Exchange SEA | Credential Exposure | Responsible Disclosure | Critical | 2026-04 |
| Unauthenticated TOTP OTP Generation Enables Mass User Enumeration Public TOTP OTP endpoint differentiates valid vs invalid clientIDs, enabling enumeration and SMS bomb across 44M accounts. CVSS 9.1 | Indian Investment Broker SEA | Broken Authentication | Responsible Disclosure | Critical | 2026-04 |
| AWS S3 Configuration Files Publicly Accessible S3 config files readable without auth leak internal user IDs and service-to-service endpoints. CVSS 9.1 | SEA Investment Platform SEA | S3 Misconfig | Responsible Disclosure | Critical | 2026-04 |
| Hardcoded OAuth Client Credentials in Production JavaScript OAuth client id and secret embedded in JS allow forging tokens against backend API used by Bitcoin ATM network. CVSS 9.1 | EU Crypto ATM Operator EU | Credential Exposure | Responsible Disclosure | Critical | 2026-04 |
| CORS Origin Reflection + Credentials on Admin Dashboard API Admin dashboard API reflects any Origin with Allow-Credentials, enabling zero-click admin takeover via phishing. CVSS 9.1 | African Crypto Aggregator Africa | CORS | Responsible Disclosure | Critical | 2026-04 |
| Password Reset Token Leakage + Rate Limit Bypass Enables ATO Password reset token returned in response body and OTP verification endpoint permits brute force leading to full takeover. CVSS 9.1 | African Fintech Neobank Africa | Broken Authentication | Responsible Disclosure | Critical | 2026-04 |
| Bani Payment Webhook Inverted Signature Verification Signature check compares hashes inversely so any mismatched signature passes validation. CVSS 9.1 | African Crypto Gift Card Platform Africa | Webhook Forgery | Responsible Disclosure | Critical | 2026-04 |
| SafeHaven Payment Webhook No Signature Verification SafeHaven callback endpoint accepts forged payloads without HMAC verification. CVSS 9.1 | African Crypto Gift Card Platform Africa | Webhook Forgery | Responsible Disclosure | Critical | 2026-04 |
| Crypto Deposit Webhook Inverted Checksum Verification Deposit webhook checksum comparison inverted so forged payloads credit attacker wallets. CVSS 9.1 | African Crypto Gift Card Platform Africa | Webhook Forgery | Responsible Disclosure | Critical | 2026-04 |
| Payment Callback Without Webhook Signature Verification Shared payment callback endpoint accepts unsigned payloads enabling arbitrary deposit crediting. CVSS 9.1 | African Crypto Gift Card Platform Africa | Webhook Forgery | Responsible Disclosure | Critical | 2026-04 |
| AES Decryption Key Hardcoded in Admin Source Map Admin source map leaks AES-CBC key used to encrypt server responses; enables full decryption. CVSS 9.1 | African Digital Platform Africa | Credential Exposure | Responsible Disclosure | Critical | 2026-04 |
| Zendesk Admin API Token Active - Full User Data Access Admin Zendesk API token hardcoded in bundle, validated as active with billing_admin+moderator role. CVSS 9.1 | African P2P Crypto Settlement Africa | Credential Exposure | Responsible Disclosure | Critical | 2026-04 |
| Client-Auth OTP Bypass - Any Code Returns Verified Client auth service returns verified:true regardless of OTP value. CVSS 9.1 | African Payment Platform Africa | Auth Bypass | Responsible Disclosure | Critical | 2026-04 |
| Django DEBUG=True on Production shop.drugstoc.com and staging Django apps expose full stack traces and URL route listings. CVSS 9.1 | African Pharma B2B Platform Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| Full React Source Code Exposure via Source Maps (32.1MB 2675 files) Admin panel, payment logic, auth flow, hardcoded credentials, merchant IDs exposed via production source maps. CVSS 9.1 | LATAM Crypto Platform LATAM | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| CORS Wildcard on All API Endpoints Enables Cross-Origin Account Takeover All production and staging API endpoints return Access-Control-Allow-Origin wildcard with Authorization header permitted; malicious site can perform authenticated cross-origin requests. CVSS 9.1 | African Neobank Africa | CORS | Responsible Disclosure | Critical | 2026-04 |
| Admin Console DELETE /users/{id} Missing Admin Role Check (User Deletion) DELETE endpoint on admin console reaches controller logic with a regular user token; any authenticated user can delete arbitrary accounts, including admins. CVSS 9.1 | African Neobank Africa | Access Control | Responsible Disclosure | Critical | 2026-04 |
| reCAPTCHA v3 SECRET KEY Exposed in Client JavaScript reCAPTCHA v3 secret key hardcoded in frontend allowing attacker to forge bot scores and bypass bot protection globally. CVSS 9.1 | Gaming Marketplace Global | Credential Exposure | Responsible Disclosure | Critical | 2026-04 |
| JWT Stored in localStorage Exposed to XSS (Token Theft) JWT access tokens persisted in localStorage are recoverable via any XSS enabling account takeover. CVSS 9.1 | European iGaming Platform EU | JWT Issues | Private Engagement | Critical | 2026-04 |
| CryptoWallets IDOR Exposes 100K+ Wallet Addresses Wallet resource enumerable by incrementing numeric ID leaks 100K+ user wallet addresses and balances. CVSS 9.1 | European iGaming Platform EU | IDOR | Private Engagement | Critical | 2026-04 |
| Password Reset PIN Verify Returns 200 for Any PIN Password reset PIN verification endpoint returns success for arbitrary input enabling password change on any email. CVSS 9.1 | EU EdTech Platform EU | Auth Bypass | Responsible Disclosure | Critical | 2026-04 |
| Metabase Google OAuth without Domain Restriction Metabase Google SSO accepts any Google identity creating self-service admin accounts wired to production database. CVSS 9.1 | West African B2B Fintech Africa | Cloud Misconfig | Responsible Disclosure | Critical | 2026-04 |
| Unauthenticated OTP Send + Verify Chain (Phone Takeover) OTP send and verify endpoints accept unlimited calls without rate limit enabling 6-digit OTP brute force phone takeover. CVSS 9.1 | West African B2B Fintech Africa | Broken Authentication | Responsible Disclosure | Critical | 2026-04 |
| Infisical Secret Manager Open Registration Infisical instance exposes open signup without email verification or captcha enabling tenant creation and lateral movement to secrets. CVSS 9.1 | African Fintech Marketplace Africa | Cloud Misconfig | Responsible Disclosure | Critical | 2026-04 |
| BVN Agents Backoffice & Frontoffice Swagger UI Publicly Accessible BVN agents admin Swagger UI reachable without auth exposing KYC agent workflows. CVSS 9.1 | African Digital Bank Africa | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-04 |
| Genesys Chat Full Exploitation Chain (User Impersonation) Unauthenticated Genesys chat token generation plus WACE bot API permits impersonating arbitrary customers in live chat. CVSS 9.1 | EU iGaming Operator EU | Business Logic | Responsible Disclosure | Critical | 2026-04 |
| CRM SDK CLIENT_ID + CLIENT_SECRET Hardcoded in APK Android APK embeds CRM client credentials enabling full read/write on marketing event system across members. CVSS 9.1 | EU iGaming Operator EU | Credential Exposure | Responsible Disclosure | Critical | 2026-04 |
| CRM Auth Token Generation Formula Exposed Token generation formula decompiled from APK allows reproducing valid auth tokens offline. CVSS 9.1 | EU iGaming Operator EU | Credential Exposure | Responsible Disclosure | Critical | 2026-04 |
| STOMP Broker Authentication Bypass STOMP broker accepts CONNECT without credentials permitting unauthenticated subscription. CVSS 9.1 | EU iGaming Operator EU | WebSocket Issues | Responsible Disclosure | Critical | 2026-04 |
| STOMP Odds Injection +10% Manipulation Injected STOMP frames propagate to all subscribers allowing attacker to alter live odds received by clients. CVSS 9.1 | EU iGaming Operator EU | WebSocket Issues | Responsible Disclosure | Critical | 2026-04 |
| Payout Service Directory Listing + Redbiller Webhook Data Exposure [CRITICAL] Vulnerable Endpoint: https://payout.[vendor]/ CVSS 9.1 | Crypto Exchange Platform Global | Business Logic | Responsible Disclosure | Critical | 2026-04 |
| IDOR - Unauthenticated Bank Account Data Access via X-User-ID Header Any unauthenticated attacker can read ANY user's bank account information (full legal name, bank name, masked account number, internal IDs) by simply changing the X-User-ID header. No authentication token, session cookie, or API key is required CVSS 9.1 | SEA Crypto Exchange SEA | IDOR | Responsible Disclosure | Critical | 2026-04 |
| [vendor] - KYC Document Access Testing Evidence CVSS 9.1 | SEA Crypto Exchange SEA | KYC Bypass | Responsible Disclosure | Critical | 2026-04 |
| CRITICAL - Supabase OKR Database Unauthenticated Full Read Access (413 Employee Records) The OKR platform at okrs.[vendor] exposes a Supabase backend with anon key that grants unauthenticated read access to the entire profiles table containing 413 employee records with full names, job titles, teams, managers, HiBob IDs, and corporate email addresses, including C-level executives (CEO, CTO, CFO) CVSS 9.1 | European B2B Spend Management EU | Cloud Misconfig | Responsible Disclosure | Critical | 2026-04 |
| CORS Wildcard with Credentials on Admin Panel and API (CRITICAL) Finding 1: CORS Wildcard with Credentials on Admin Panel and API (CRITICAL) Severity: Critical (CVSS 9.1 - AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N) Summary: Both admin panels (hiftigh.[redacted].com and [target]) return `Access-Control-Allow-Origin: ` combined with `Access- CVSS 9.1 | MENA Fintech MENA | CORS | Responsible Disclosure | Critical | 2026-04 |
| Whitelabel Partner Data and MongoDB ObjectIDs Exposed (CRITICAL) Finding 6: Whitelabel Partner Data and MongoDB ObjectIDs Exposed (CRITICAL) Affected Component: [target] source map Summary: MongoDB ObjectIDs for all whitelabel integration partners (including Worldcoin across 8+ countries) are exposed in client-side source code, along w CVSS 9.1 | LATAM Crypto Platform LATAM | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| Production API Authentication Bypass via Encryption Key Exposure Finding 2: Production API Authentication Bypass via Encryption Key Exposure The API gateway validation uses an AES-256-CBC encrypted `X-Request-ID` header. The encryption key, IV, API key, and subscription key are all exposed in client-side JavaScript, allowing anyone to forge va CVSS 9.1 | African Remittance Provider Africa | API Key Exposure | Responsible Disclosure | Critical | 2026-04 |
| Shopify Payment Test Environment API Key Exposure (CRITICAL) Finding 3: Shopify Payment Test Environment API Key Exposure (CRITICAL) The `sfy-payment-test.[redacted].ai` subdomain exposes a [redacted] API key in its Next.js `__NEXT_DATA__` runtime configuration, accessible without authentication. This is a Shopify payment integration test environmen CVSS 9.1 | MENA BNPL Provider MENA | API Key Exposure | Responsible Disclosure | Critical | 2026-04 |
| Hardcoded AES-GCM Production Encryption Key in Web Bundle Client-side AES-GCM key for production payload encryption exposed in JS, reducing encryption to obfuscation. CVSS 9.0 | Indian Investment Broker SEA | Credential Exposure | Responsible Disclosure | Critical | 2026-04 |
| Hardcoded AES-CBC Key + IV in Mobile App APK ships with static AES-CBC key and IV used for request protection enabling MITM decryption on all installs. CVSS 9.0 | Indian Investment Broker SEA | Credential Exposure | Responsible Disclosure | Critical | 2026-04 |
| Virtual Card Callback Without Webhook Signature Verification Virtual card issuance callbacks skip HMAC validation enabling forged card event injection. CVSS 9.0 | African Crypto Gift Card Platform Africa | Webhook Forgery | Responsible Disclosure | Critical | 2026-04 |
| Blind SSRF Into Internal Kubernetes Services Server-side fetch endpoint permits requests to internal Kubernetes cluster services facilitating metadata exfiltration. CVSS 9.0 | European iGaming Platform EU | SSRF | Private Engagement | Critical | 2026-04 |
| [redacted] Staging Deep Security Assessment [redacted].com - Staging Environment Deep Security Assessment Target: stage.[redacted].com (staging) vs [redacted].com (production) Discovered: dev.[redacted].com (development), casino.[redacted].com, admin.[redacted].com, sportsbook.[redacted].com, crypto.[redacted].com, api.[redacted].com, sb CVSS 9.0 | EU iGaming Operator EU | API Key Exposure | Responsible Disclosure | Critical | 2026-04 |
| Unauthenticated Private Trade Chat Access Trade chat endpoint serves private buyer/seller messages and shared KYC attachments without auth. CVSS 8.8 | SEA P2P Crypto Exchange SEA | IDOR | Responsible Disclosure | Critical | 2026-04 |
| Coolify PaaS Deployment Platform Publicly Accessible Coolify deployment platform accessible over internet without hardening enabling deployment and container control plane attacks. CVSS 8.8 | African Fintech Marketplace Africa | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-04 |
| CORS Origin Reflection with Credentials on Backend Services Multiple backend services reflect arbitrary Origin with credentials enabling cross-origin authenticated operations. CVSS 8.8 | African Digital Bank Africa | CORS | Responsible Disclosure | Critical | 2026-04 |
| STOMP Message Injection into Topics STOMP broker accepts SEND to arbitrary topics enabling attacker to inject odds and score events. CVSS 8.8 | EU iGaming Operator EU | WebSocket Issues | Responsible Disclosure | Critical | 2026-04 |
| Source Map Exposure: 243 Source Files, 10.9MB Full Frontend Production source maps reveal 243 files including API encryption helpers, internal endpoints and admin routes. CVSS 8.6 | SEA P2P Crypto Exchange SEA | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| Vercel Deployment Credentials + Internal Infra Leak DevDashboard JS leaks NUXT_ENV_VERCEL_ARTIFACTS_TOKEN, ORG_ID, PROJECT_ID enabling Vercel supply-chain. CVSS 8.6 | African Crypto Infrastructure Africa | Credential Exposure | Responsible Disclosure | Critical | 2026-04 |
| Kubernetes Cluster Disclosure via Unauth /health WalletPro API gateway /health reveals node IPs, pod names, service account, microservice names, Datadog labels. CVSS 8.6 | European Crypto Exchange EU | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| Payment Gateway Credentials Hardcoded in Production JS NGenius and Checkout.com API keys embedded in SPA bundle; NGenius keys only base64-encoded. CVSS 8.6 | MENA Regulated Crypto Exchange MENA | Credential Exposure | Responsible Disclosure | Critical | 2026-04 |
| Production Secret Token Hardcoded in Client-Side JavaScript x-secret-token used by all authenticated endpoints is hard-coded in browser bundle. CVSS 8.6 | West African B2B Fintech Africa | Credential Exposure | Responsible Disclosure | Critical | 2026-04 |
| Develop Environment REACT_APP_SECRET Encryption Key Disclosed Develop bundle exposes REACT_APP_SECRET used as encryption key for client-side session storage. CVSS 8.6 | West African B2B Fintech Africa | Credential Exposure | Responsible Disclosure | Critical | 2026-04 |
| Unrestricted Firebase Authentication Registration Firebase Auth allows open email/password registration without email verification enabling unbounded account creation. CVSS 8.6 | African Fintech Africa | Firebase Misconfig | Responsible Disclosure | Critical | 2026-04 |
| User App Full Source Code Exposure via Source Map (502 files) User app exposes 9.6MB source map with 502 TypeScript files including exchange logic. CVSS 8.6 | LATAM Crypto Platform LATAM | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| KYC API Key Hardcoded in Android APK Static KYC API key enables direct invocation of KYC provider endpoints and enumeration of document flows. CVSS 8.5 | Indian Investment Broker SEA | API Key Exposure | Responsible Disclosure | Critical | 2026-04 |
| Self-Hosted Sentry Event Injection Verified Internal Sentry DSN accepts unauth events enabling log pollution and developer alert fatigue. CVSS 8.5 | MENA Crypto Exchange MENA | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| Exchange Application Full Source Code via Source Maps Production source maps expose complete exchange logic including private modules. CVSS 8.5 | European Crypto Exchange EU | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| Full Source Code Exposure via Source Maps (Admin Panel) AstroAfrica admin ships Vue source maps disclosing 96 API endpoints and internal flows. CVSS 8.5 | African Astrology Platform Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| Vite Dev Server Production - Full Source Code Exposure Production dexpay.io runs vite dev exposing 19+ source files directly. CVSS 8.5 | African P2P Crypto Settlement Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-04 |
| CORS Misconfiguration on Login API Enables Credential Theft Login API reflects Origin with credentials allowing a hostile page to capture 44M-user broker login session. CVSS 8.1 | Indian Investment Broker SEA | CORS | Responsible Disclosure | Critical | 2026-04 |
| Complete API Authentication Bypass (ALL 66 Endpoints) ASP.NET Core API accepts all requests without validating Authorization header; every endpoint accessible unauth. CVSS 10.0 | African Crypto Trading Platform Africa | Auth Bypass | Responsible Disclosure | Critical | 2026-03 |
| SQL Injection Full Database Compromise (14.8M records) Fraud Decision API concatenates verification_id into SQL enabling full extraction of 11 databases. CVSS 10.0 | African KYC/Identity Provider Africa | SQLi | Responsible Disclosure | Critical | 2026-03 |
| Production MySQL User Created via Stacked Query Attacker-created MySQL user with full privileges across all databases via stacked-query SQLi. CVSS 10.0 | African KYC/Identity Provider Africa | RCE | Responsible Disclosure | Critical | 2026-03 |
| Wazuh SIEM API Default Credentials — Full Infrastructure Compromise Endpoint: https://46.101.230.90:55000 CVSS 10.0 | African Crypto Exchange Africa | Credential Exposure | HackerOne | Critical | 2026-03 |
| [vendor] -- 30K+ Kullaniciya TOPLU ERISIM: DOGRULANMIS VEKTOR ANALIZI Tarih: 2026-03-20 (Guncellenmis -- Aktif Test Sonuclari) Aciliyet: KRITIK -- Aktif tehdit, 200K+ kullanici risk altinda Durum: 30K hesaba zaten erisilmis. BIRISI AKTIF OLARAK BRUTE FORCE YAPIYOR CVSS 10.0 | Crypto Gaming Platform Global | CORS | Responsible Disclosure | Critical | 2026-03 |
| CORS HTTP Downgrade Enables 0-Click Crypto Theft via MITM BitValve accepts http:// origin with credentials on all 40+ endpoints letting in-path attacker drain wallets on HTTP downgrade. CVSS 9.8 | Global P2P Crypto Marketplace Global | CORS | Responsible Disclosure | Critical | 2026-03 |
| HashiCorp Vault v1.12.1 Production Secrets Manager Public Production Vault instance reachable publicly, exposing sys/metrics and AppRole endpoints. CVSS 9.8 | SEA Banking API Platform SEA | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-03 |
| Internal Admin API Publicly Accessible with 44 gRPC Methods Admin gRPC service reachable without auth exposing 44 methods including user management. CVSS 9.8 | SEA Banking API Platform SEA | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-03 |
| Eight Dangling CNAME Subdomains Target Backend APIs Eight CNAMEs point to deleted DigitalOcean apps, takeable to intercept dashboard/admin/staging traffic. CVSS 9.8 | African Crypto Exchange Africa | Subdomain Takeover | Responsible Disclosure | Critical | 2026-03 |
| Production Widget Uses Dev-Login Backdoor + Commented Access Key Widget bundle ships '/auth/dev-login' call and commented access-key reveals production backdoor pattern. CVSS 9.8 | African Crypto Exchange Africa | Auth Bypass | Responsible Disclosure | Critical | 2026-03 |
| SQL Injection via Table Name + 3x Cloudflare WAF Bypass Bitbns table-name parameter is SQL-injectable and three WAF bypass payloads succeed on production. CVSS 9.8 | Indian Crypto Exchange SEA | SQLi | Responsible Disclosure | Critical | 2026-03 |
| NoSQL Injection on Login, Admin Login and Signup Mongo operator injection succeeds on three auth endpoints enabling admin enumeration and auth bypass. CVSS 9.8 | African Fintech Remittance Africa | NoSQL Injection | Responsible Disclosure | Critical | 2026-03 |
| MinIO S3 CORS Wildcard + Credentials with KYC Buckets Present obiex minio-api reflects arbitrary origin with credentials and KYC/KYB buckets confirmed via 403 responses. CVSS 9.8 | African Fintech Crypto Exchange Africa | Cloud Misconfig | Responsible Disclosure | Critical | 2026-03 |
| Production KYB Compliance API Internet Reachable kyb-api.sigma.obiex.finance publicly reachable without WAF, 42-day uptime. CVSS 9.8 | African Fintech Crypto Exchange Africa | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-03 |
| Coolify PaaS Deployment Panel Publicly Accessible sigma.obiex.finance hosts Coolify deployment console with wildcard CORS controlling all services. CVSS 9.8 | African Fintech Crypto Exchange Africa | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-03 |
| Jenkins Admin Credentials (Base64) + Build Trigger Token la3eb Jenkins exposes Base64-encoded admin credential and build trigger token publicly. CVSS 9.8 | Saudi Gaming Marketplace MENA | Credential Exposure | Responsible Disclosure | Critical | 2026-03 |
| Admin Panel + 30 Admin API Endpoints Fully Open enjoygm admin panel reachable publicly with 30 privileged API routes and wildcard CORS. CVSS 9.8 | Gaming Recharge Platform SEA | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-03 |
| Admin User Hashes Exposed via GetAdmins GET /User/GetAdmins returns 4 admin accounts with ASP.NET Identity password hashes. CVSS 9.8 | African Crypto Trading Platform Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| Deposit Address Hijack via AddCryptoWallet Unauth POST /CryptoWallet/AddCryptoWallet redirects all customer BTC/USDT deposits to attacker address. CVSS 9.8 | African Crypto Trading Platform Africa | Business Logic | Responsible Disclosure | Critical | 2026-03 |
| Unauthenticated KYC Data Access (Mass PII) /verification-details and /data endpoints expose complete KYC records unauth (5.8M BVN + 2.75M verifications). CVSS 9.8 | African KYC/Identity Provider Africa | Access Control | Responsible Disclosure | Critical | 2026-03 |
| SSRF Full Data Exfiltration via 303 Redirect Chain Checkout.com Apple Pay integration allows 303 redirect chain for OOB SSRF exfiltrating origin IP + metadata. CVSS 9.8 | EU Gaming Marketplace EU | SSRF | Responsible Disclosure | Critical | 2026-03 |
| Blind XXE via Altenar XML - K8s Token + File Exfiltration Altenar game integration accepts XML with external entities; K8s service account JWT + pod hostname exfiltrated. CVSS 9.8 | EU iGaming Operator EU | SSRF | Responsible Disclosure | Critical | 2026-03 |
| Pusher E2E Encryption Key Hardcoded Full Trade Surveillance 256-bit HMAC key in JS enables subscribing private-global_private channel monitoring all trades. CVSS 9.8 | Indian Crypto Exchange SEA | Credential Exposure | Responsible Disclosure | Critical | 2026-03 |
| Password Reset Token Leaked in Response Body (Full ATO) Password reset API returns the reset code and token in response body enabling mass account takeover via email enumeration. CVSS 9.8 | Gaming Marketplace SEA | Broken Authentication | Responsible Disclosure | Critical | 2026-03 |
| Outdated Camera Firmware with Multiple Known CVEs (V3.4.87-modify) Device runs 2018 firmware vulnerable to known authentication bypass and RCE CVEs without vendor patch path. CVSS 9.8 | CCTV Infrastructure Global | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| Unauthenticated Admin Wallet Transaction History Admin wallet transaction endpoint returns platform-wide financial history without authentication. CVSS 9.8 | African Crypto Exchange Africa | Access Control | Responsible Disclosure | Critical | 2026-03 |
| Unauthenticated Admin Wallet Balance Per-Customer IDOR Admin wallet balance endpoint accepts arbitrary customer IDs without auth revealing holdings. CVSS 9.8 | African Crypto Exchange Africa | IDOR | Responsible Disclosure | Critical | 2026-03 |
| OTP Brute Force Account Takeover (No Rate Limit) OTP verification endpoint accepts unlimited attempts with no lockout enabling account takeover. CVSS 9.8 | African Crypto Exchange Africa | Broken Authentication | Responsible Disclosure | Critical | 2026-03 |
| Unauthenticated Webhook Callback - Deposit Forgery Primary payment callback endpoint accepts arbitrary payloads without signature validation enabling deposit forgery. CVSS 9.8 | African Fintech Africa | Webhook Forgery | Responsible Disclosure | Critical | 2026-03 |
| Eleven Unauthenticated Payment Callbacks (PawaPay/Peach/Encryptus/ChoiceBank/SasaPay/Fonbnk/Tanda) Eleven different provider callback endpoints accept forged payloads across all zones enabling payment manipulation. CVSS 9.8 | African Fintech Africa | Webhook Forgery | Responsible Disclosure | Critical | 2026-03 |
| Facebook/Apple Social Login Full Account Takeover (No Token Validation) Social login endpoint accepts any provided token without validating with Facebook/Apple enabling full account takeover by email. CVSS 9.8 | MENA Travel Fintech MENA | Auth Bypass | Responsible Disclosure | Critical | 2026-03 |
| HashiCorp Vault Staging Unsealed and Publicly Accessible Staging Vault instance is unsealed, public, with UI enabled exposing secret management plane. CVSS 9.8 | LATAM Crypto Exchange LATAM | Cloud Misconfig | Responsible Disclosure | Critical | 2026-03 |
| OpenSearch Security Alerts — 10,000+ Events Readable Endpoint: https://guards.[vendor] (via kibanaserver:kibanaserver) CVSS 9.8 | African Crypto Exchange Africa | Credential Exposure | HackerOne | Critical | 2026-03 |
| Production RCE Chain via Wazuh Agent Group Configuration Injection Through the Wazuh API, an attacker can achieve Remote Code Execution on production by: 1. Creating a new agent group 2. Uploading a configuration with localfile commands 3. Assigning the production agent to that group 4. Restarting the agent to apply the configuration CVSS 9.8 | African Crypto Exchange Africa | RCE | HackerOne | Critical | 2026-03 |
| Metabase Analytics Setup Token Exposed - Full Internal Config Leak Vulnerable Endpoint: https://analytics.[vendor]/api/session/properties CVSS 9.8 | Crypto Gaming Platform Global | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-03 |
| Email OTP Bypass via API Token — Enables Unauthorized Withdrawals This is the core vulnerability that makes fund theft possible. When a user withdraws crypto through the website, they must enter a 6-digit code sent to their email (email OTP). However, when using an API token (generated via /auth-http/auth/business/generate-token), this email OTP check is completely skipped. The server accepts an empty security CVSS 9.8 | Crypto Gaming Platform Global | Auth Bypass | Responsible Disclosure | Critical | 2026-03 |
| Unauthenticated Xbox Order Creation on Internal API (redeem-cards.com) The internal Xbox order fulfillment API at redeem-cards.com is accessible from the public internet without any authentication. The UserType: [vendor]Bot HTTP header bypasses all authentication, granting direct access to order creation logic that reaches the DecideXboxPreOrder() function -- one step from triggering real monetary transactions on Mi CVSS 9.8 | EU Gaming Key Marketplace EU | Business Logic | Responsible Disclosure | Critical | 2026-03 |
| Full Account Takeover via Password Reset Brute Force + XFF Bypass Any user's password can be reset without authentication, CAPTCHA, or rate limiting. The password reset code brute force endpoint has zero rate limiting -- 300+ consecutive requests were tested with 0 blocked. Combined with X-Forwarded-For bypass, the attack is completely unlimited CVSS 9.8 | EU Gaming Key Marketplace EU | Broken Authentication | Responsible Disclosure | Critical | 2026-03 |
| Eski PIN sorulmadi (dogrudan yeni PIN set ediliyor) curl -s -X POST "https://grpc-global-service-web-envoy.use[vendor]/business_banking.backend.protos.global.proto.KycManagementService/FetchAllKycLevels" \ -H "Content-Type: application/grpc-web-text" \ -H "Accept: application/grpc-web-text" \ -H "X-Grpc-Web: 1" \ -d 'AAAAAAA=' CVSS 9.8 | African Payment Processor Africa | Broken Authentication | Responsible Disclosure | Critical | 2026-03 |
| Bcrypt Password Hash Leaked in Registration Response AND JWT Token POST /api/auth/register endpointi basarili kayit sonrasinda kullanicinin bcrypt password hash'ini hem JWT token payload'inda hem de response body'sinde dondurur. Ayrica GET /api/auth/me endpointi de authenticated kullanicinin password hash'ini response'da dondurur. Bu bir fintech platformunda felaket seviyesinde bir guvenlik acigi CVSS 9.8 | African Remittance Platform Africa | JWT Issues | Responsible Disclosure | Critical | 2026-03 |
| [redacted] Full Report [redacted] Infrastructure Security Assessment — Full Report Researcher: Atilla Mammadli (atillamemmedli@[target]) Target: [redacted].io and associated infrastructure Critical: 10 | High: 6 | Medium: 16 | Low/Info: 28+ CVSS 9.8 | DeFi Lending/DEX Protocol Global | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| VPN Superuser Account Compromise via Weak Credentials (CRITICAL) Finding 27: VPN Superuser Account Compromise via Weak Credentials (CRITICAL) Status: PROVEN - TOKEN OBTAINED The VPN admin account `candra@[redacted].com` uses a [redacted]ially guessable password `[redacted]123!` which grants `superuser` role access to the VPN management API. Combined CVSS 9.8 | SEA Crypto Exchange SEA | Credential Exposure | Responsible Disclosure | Critical | 2026-03 |
| [redacted] 2012.55 CVE Research [redacted] SSH 2012.55 - CVE ve Exploit Arastirmasi Hedef Versiyon: [redacted] sshd 2012.55 Amac: Authorized internal network security audit Kaynak: NVD (NIST), [redacted] CHANGES log, ExploitDB, GitHub CVSS 9.8 | SSH Infrastructure Global | RCE | Responsible Disclosure | Critical | 2026-03 |
| [redacted] My Default Creds Report [redacted] (my.[redacted].com) — Default Admin Credentials on Magento REST API Target: my.[redacted].com ([redacted] / Azerconnect) Report To: informationsecurity@[target] Severity: CRITICAL (CVSS 9.8 — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) CVSS 9.8 | Telecom Operator MENA | Default Creds | Responsible Disclosure | Critical | 2026-03 |
| K-3: Transaction Automation API with Broken Authentication (CRITICAL) Finding K-3: Transaction Automation API with Broken Authentication (CRITICAL) Endpoint: `http://[ip]/` (port 80, same server as [redacted]) Summary: A Transaction Automation API running on the same server as [redacted] accepts ANY Bearer token value for authentication. The CVSS 9.8 | African Neobank Africa | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-03 |
| Zero Click Exploit [redacted] Finance - Zero-Click Wallet Drain Exploit Analysis Target: [redacted].finance (mobilelab.[redacted].africa + [redacted]bridge.[redacted].finance) Type: Authorized Bug Bounty - Maximum Impact Chain Analysis Status: CHAIN PROVEN - Multiple 0-click and 1-click wallet drain vectors identified CVSS 9.8 | African DeFi Protocol Africa | Rate Limit Bypass | Responsible Disclosure | Critical | 2026-03 |
| [redacted] SSH 2012.55 - Multiple Critical CVEs (14+ Years Old) Finding 3: [redacted] SSH 2012.55 - Multiple Critical CVEs (14+ Years Old) CVSS Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H SSH daemon'u [redacted] 2012.55, 14+ yillik ve en az 8 bilinen CVE'ye karsi savunmasiz. Bunlar arasinda remote code execution (CVE-2016-7406) ve authenticated R CVSS 9.8 | CCTV Infrastructure Global | RCE | Responsible Disclosure | Critical | 2026-03 |
| Translation Write + CDN Publish (Supply Chain Attack) Finding 2: Translation Write + CDN Publish (Supply Chain Attack) Type: CWE-94 (Supply Chain Compromise) Step 4 — Confirmed on live site: GCS file modification timestamp updated to `2026-03-23T10:14:49.721Z` during our test. All values were restored immediately after verification. CVSS 9.8 | Global Crypto Exchange Global | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| Critical Oss Sts Finding CRITICAL: Unauthenticated STS Token Generation → Full OSS Bucket Read/Write Access Target: [redacted].store (Nigerian gift card P2P trading platform, ~1.3M users) Status: Authorized Penetration Test Unauthenticated Alibaba Cloud STS Token Generation via getOssToken API Leads to Full Re CVSS 9.8 | SEA Crypto Exchange SEA | API Key Exposure | Responsible Disclosure | Critical | 2026-03 |
| Ato Chain Verified [redacted] ([redacted].az) - Full Account Takeover Chain Verification Target: https://api.[redacted].az (Production API) Classification: CRITICAL - Full Account Takeover (CVSS 9.8) Status: FULLY VERIFIED on production CVSS 9.8 | EU iGaming Operator EU | Rate Limit Bypass | Responsible Disclosure | Critical | 2026-03 |
| Google OAuth CSRF via Empty State Parameter BitValve OAuth flow omits state parameter enabling CSRF-based account takeover via attacker-supplied code. CVSS 9.6 | Global P2P Crypto Marketplace Global | Broken Authentication | Responsible Disclosure | Critical | 2026-03 |
| Apple OAuth CSRF via Static 'apple' State Parameter Apple OAuth always sets state=apple allowing reliable CSRF account linkage on victim sessions. CVSS 9.6 | Global P2P Crypto Marketplace Global | Broken Authentication | Responsible Disclosure | Critical | 2026-03 |
| Google OAuth Client SECRET Exposed la3eb OAuth client secret leak allows forging Sign-in-with-Google assertions. CVSS 9.6 | Saudi Gaming Marketplace MENA | Credential Exposure | Responsible Disclosure | Critical | 2026-03 |
| Unauthenticated Invoice API Endpoints (request-void/cancel/mark-as-paid) 7 invoice manipulation endpoints accept requests without any auth token; any UUID enables cancel/refund/mark-paid actions. CVSS 9.6 | European Crypto Payment Gateway EU | Access Control | Responsible Disclosure | Critical | 2026-03 |
| Zero-Price Primer Production Payment Tokens Guest endpoint issues 0 EUR Primer production tokens with full card tokenization. CVSS 9.6 | Gaming Marketplace EU | Business Logic | Responsible Disclosure | Critical | 2026-03 |
| Guest Order IDOR + Credential Theft Chain byGuestAccessId endpoint skips auth returning 10 credential field types. CVSS 9.6 | Gaming Marketplace EU | IDOR | Responsible Disclosure | Critical | 2026-03 |
| Private Channel Auth Bypass via OTP + HMAC globalPrivateChannelKey returns rotating OTP; HMAC computed locally to sign channel auth. CVSS 9.6 | Indian Crypto Exchange SEA | Auth Bypass | Responsible Disclosure | Critical | 2026-03 |
| CORS Wildcard + localStorage Bearer Token = Full Cross-Origin Account Takeover Chain The [vendor] Vue.js SPA stores the user's authentication Bearer token in localStorage under the key accessToken. Combined with the CORS wildcard () on sls.[vendor] that allows Authorization header in cross-origin requests, and the DELETE method enabled on /user/account, this creates a full account takeover and destruction chain exploitable CVSS 9.6 | SEA Gaming Marketplace SEA | CORS | HackerOne | Critical | 2026-03 |
| MinIO Images Bucket Anonymous WRITE (Supply Chain) blix.gg MinIO images bucket allows anonymous object upload to 38,219 public assets (1.3GB). CVSS 9.5 | Gaming Marketplace EU | Cloud Misconfig | Responsible Disclosure | Critical | 2026-03 |
| Twitter/X Brand Account Takeover (119K Followers) la3eb.com OAuth 1.0a flow allows X account session takeover with 119K-follower brand handle. CVSS 9.5 | Saudi Gaming Marketplace MENA | Access Control | Responsible Disclosure | Critical | 2026-03 |
| Complete Environment Config Dump (20+ API Keys) Single JS bundle leaks 20+ service API keys including Checkout.com sandbox, Lokalise, Firebase anonymous. CVSS 9.5 | Saudi Gaming Marketplace MENA | Credential Exposure | Responsible Disclosure | Critical | 2026-03 |
| Fonbnk Third-Party Callback Forgery (ATEN System) Fonbnk callback accepts empty or arbitrary payloads with unvalidated signature enabling ATEN system abuse. CVSS 9.4 | African Fintech Africa | Webhook Forgery | Responsible Disclosure | Critical | 2026-03 |
| Unauthenticated Transaction CSV Download via DownloadTransactions DownloadTransactions gRPC method returns CSV transaction data without a token after progressive field disclosure. CVSS 9.3 | SEA Banking API Platform SEA | BFLA | Responsible Disclosure | Critical | 2026-03 |
| Cloudflare WAF Complete Bypass via Wageon Origin IP wageon.io white-label brand resolves to AWS origin bypassing CF. CVSS 9.3 | EU iGaming Operator EU | Cloud Misconfig | Responsible Disclosure | Critical | 2026-03 |
| CORS Origin Reflection with Credentials on All 928 REST API Routes Every REST route reflects arbitrary Origin with credentials enabling cross-origin session hijack across the storefront. CVSS 9.3 | Gaming Marketplace NA | CORS | Responsible Disclosure | Critical | 2026-03 |
| Vite Dev Server Source Code Exposure on Integrator Dashboard Integrator dashboard runs Vite dev server in production exposing full React source, routes and env config. CVSS 9.3 | African Fintech Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| Unregistered Staging Domain Takeover (traderjoexyz.dev) Staging API base URL points to an unregistered .dev domain; claiming it hijacks staging frontend traffic. CVSS 9.3 | DeFi DEX Protocol Global | Subdomain Takeover | Responsible Disclosure | Critical | 2026-03 |
| Payment OTP Brute Force -- Zain/Simpaisa Zero Rate Limit Payment OTP verification endpoints have no effective rate limiting. Zain allows 185 requests per IP without any block, Simpaisa allows 50+ requests. Combined with XFF bypass, the entire OTP keyspace can be brute-forced CVSS 9.3 | EU Gaming Key Marketplace EU | Broken Authentication | Responsible Disclosure | Critical | 2026-03 |
| Security Finding 1. Hardcoded API Signature (auth.crud.js) - Internal IP: `[ip]` (Alibaba Cloud, staging/dev backend) - Hardcoded Signature: `X-TCDX-SIGNATURE: salamtothemoon` - used for admin authentication - Endpoint: `POST /admin/auth` with email/password CVSS 9.3 | SEA Fintech SEA | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| Round6 Deep Exploitation 1. Refund Chain: Public API creds ([redacted]) -> Token -> invoice_id enum -> Unauthorized refund execution 2. Account Takeover Chain: Email enum (login differential) -> Reset flood (no rate limit) -> Token brute-force -> IMT operator account takeover -> Cross-border payment data 3. CVSS 9.3 | Turkish Payment Gateway MENA | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| [redacted] SSRF Azure Infrastructure SSRF Azure Infrastructure Deep Exploitation - [redacted].money Hedef: [redacted].money ([redacted] Money (Pty) Ltd) Zafiyet: SSRF via `validateApplePayMerchant` GraphQL Mutation Severity: CRITICAL (Infrastructure Mapping + Database Discovery + Key Vault Discovery) CVSS 9.3 | African Payment Gateway Africa | SSRF | Responsible Disclosure | Critical | 2026-03 |
| Reverse Authentication Logic on Notification/EscrowPayout [CRITICAL] Finding 1: Reverse Authentication Logic on Notification/EscrowPayout [CRITICAL] Endpoint: POST /api/Notification/EscrowPayout Notification/EscrowPayout endpoint'inde authentication logic'i TERS calisiyor. `ApiKey` header gonderilMEdiginde endpoint "Success!" donuyor. ApiKey heade CVSS 9.3 | African DeFi Protocol Africa | Auth Bypass | Responsible Disclosure | Critical | 2026-03 |
| [redacted] Deep Dive V2 - Existing email: "Password reset link has been sent to your e-mail address." - Non-existing email: "Active user could not be found." No authentication is required. No rate limiting observed (beyond the global IP-based rate limit). reCAPTCHA is not enforced. | support@[redacted].com CVSS 9.3 | Gaming Marketplace MENA | Broken Authentication | Responsible Disclosure | Critical | 2026-03 |
| African Fintech Mass Scan African Crypto/Fintech Platform Mass Scan Results Scope: 20 African crypto/fintech platforms Method: Passive reconnaissance, subdomain enumeration, configuration exposure, API discovery 1. [target] / [target] -- MULTI-VECTOR COMPROMISE CVSS 9.3 | African Fintech Mass Scan Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| Crypto Exchange Mass Scan Crypto Exchange Mass Scan - 2026-03-22 20+ Platform Vulnerability Assessment VERIFIED FINDINGS (3 Platforms) 1. [redacted] -- VERIFIED CRITICAL (Vietnamese Crypto Exchange, ~1.39M users) CVSS 9.3 | Crypto Exchange Mass Scan Global | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| Firebase Realtime Database PUBLIC READ Access [CRITICAL] Finding 1: Firebase Realtime Database PUBLIC READ Access [CRITICAL] - URL: `https://[target]/.json` - Impact: Full database readable without authentication (562KB) - 80 production bank configurations (codes, logos, names) CVSS 9.3 | Crypto Fintech Mass Scan Global | Firebase Misconfig | Responsible Disclosure | Critical | 2026-03 |
| Local Network Mdns Upnp Discovery mDNS/Bonjour ve UPnP Servis Kesfi Raporu Test Makinasi: [ip] (MacBook Pro, Mac16,8, macOS Darwin 25.2.0) Yetkilendirme: Authorized pentest [ip]/24 yerel aginda mDNS/Bonjour ve UPnP/SSDP protokolleri kullanilarak servis ve cihaz kesfesi yapildi. Toplamda 8 benz CVSS 9.3 | Local Network Scan Global | Auth Bypass | Responsible Disclosure | Critical | 2026-03 |
| Subdomain Information Disclosure (LOW) Finding 5: Subdomain Information Disclosure (LOW) Kesfedilen subdomain'ler ve durumlar: - `api.blix.gg` - 502 (backend down) - `api-dev.blix.gg` - timeout (DNS var, service yok) CVSS 9.3 | KYC Mass Scan Global | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| [redacted] Billing Findings Proven [redacted] Code Billing/Auth Security Assessment — PROVEN FINDINGS [redacted] VDP — Authorized Security Research Hedef: [redacted] Code CLI v2.1.74, [redacted] API Kapsam: Billing bypass, auth bypass, client-side manipulation CVSS 9.3 | AI SaaS Provider NA | Auth Bypass | Responsible Disclosure | Critical | 2026-03 |
| Disclosure'lar - [UpdateAccountPermission Exploit](https://[target]/blog/[redacted]-wallet-exploit-updateaccountpermission) - [14,500 Wallets at Risk](https://[target]/news/[redacted]-addresses-risk-silent-hijacking) - [$500M Multisig Vulnerability](https://[target]/news/[redacted]-multis CVSS 9.3 | L1 Smart Contract Global | RCE | HackerOne | Critical | 2026-03 |
| Mass Scanner Prompt V2 Mass Scanner Prompt v2 — COPY BELOW INTO NEW SESSION You are conducting authorized bug bounty security research on digital game/gift card marketplace platforms. You have ONE job: find LETHAL vulnerabilities and PROVE they exist with real HTTP responses. WHAT I CARE ABOUT (NOTHING CVSS 9.3 | Mass Scan Global | Subdomain Takeover | Responsible Disclosure | Critical | 2026-03 |
| CRITICAL - Full Stack Trace Disclosure with GoCD CI/CD Path Exposure Finding 2: CRITICAL - Full Stack Trace Disclosure with GoCD CI/CD Path Exposure Summary: IMT backend API'leri, kimlik dogrulama hatalarinda tam .NET stack trace ifsa etmektedir. Stack trace'ler GoCD CI/CD pipeline yollarini, kaynak kod dosya adlarini ve satir numaralarini icerir. CVSS 9.3 | Turkish Payment Gateway MENA | Access Control | Responsible Disclosure | Critical | 2026-03 |
| [CRITICAL]: OIDC Discovery Exposes Internal Architecture + Admin Impersonation Grant Type Finding 3 [CRITICAL]: OIDC Discovery Exposes Internal Architecture + Admin Impersonation Grant Type `secure.[redacted].money` ve `secure-staging.[redacted].money` OIDC discovery endpoint'leri production'da 26, staging'de 85 OAuth scope ifsa ediyor. Staging'de `admin-oidc-impersonation` g CVSS 9.3 | African Payment Gateway Africa | Broken Authentication | Responsible Disclosure | Critical | 2026-03 |
| [redacted] Final Exploit [redacted].com - FINAL Penetration Test Report Authorized Bug Bounty Security Assessment - 2026-03-16 Target: [redacted].com ([redacted] - Gift Card E-Commerce) Stack: WordPress 6.x + WooCommerce + PHP 7.4.33 (EOL) + Apache + cPanel (CloudLinux/StableServer) CVSS 9.3 | Gaming Marketplace EU | Rate Limit Bypass | Responsible Disclosure | Critical | 2026-03 |
| [redacted] Security Assessment Report 2026 The following critical credentials are hardcoded in the JS bundle: Security Config File (Publicly Accessible) These values are used as custom headers in login requests: | JWT Secret | `YOUR_VERY_CONFIDENTIAL_SECRET_FOR_SIGNING_JWT_TOKENS!!!` | Mock auth (Fuse framework) | CVSS 9.3 | African Fintech Africa | JWT Issues | Responsible Disclosure | Critical | 2026-03 |
| 5x [redacted] Database Instances FULLY ACCESSIBLE [CRITICAL - MEGA] Finding 0: 5x [redacted] Database Instances FULLY ACCESSIBLE [CRITICAL - MEGA] - Severity: CRITICAL (CVSS 9.8) - Impact: 5 separate [redacted] PostgreSQL databases for internal operations dashboards are publicly accessible with anon JWT keys hardcoded in publicly-hosted JS files. Com CVSS 9.3 | Crypto Fintech Mass Scan Global | JWT Issues | Responsible Disclosure | Critical | 2026-03 |
| KYC Db Scan KYC & Database Exposure Scan — 2026-03-17 Objective: Find HTTP 200 with ACTUAL real data (user records, KYC documents, DB contents) Result: NO verified data access found across 100+ platforms scanned Regions: Nigeria, Turkey, Southeast Asia, Latin America, Eastern Europe, Global CVSS 9.3 | KYC Mass Scan Global | S3 Misconfig | Responsible Disclosure | Critical | 2026-03 |
| [redacted] Billing Research [redacted] Billing/Usage Bypass Research Responsible Disclosure — [redacted] VDP Araştırmacı: Atilla (atilla0283@hackerone) Amaç: Billing/usage enforcement bypass zafiyetleri tespit etmek CVSS 9.3 | AI SaaS Provider NA | Race Condition | HackerOne | Critical | 2026-03 |
| CRITICAL - 367-Endpoint API Specification Exposure (4x [redacted] UI Public) Finding 1: CRITICAL - 367-Endpoint API Specification Exposure (4x [redacted] UI Public) Summary: [redacted]'in cross-border para transferi (IMT) altyapisi 4 adet [redacted] UI/JSON spec dosyasini kimlik dogrulama olmadan internete acik birakmistir. Toplam 367 API endpoint'i (240 Accounting CVSS 9.3 | Turkish Payment Gateway MENA | Auth Bypass | Responsible Disclosure | Critical | 2026-03 |
| [CRITICAL]: CORS Origin Reflection + Credentials on GraphQL API Finding 1 [CRITICAL]: CORS Origin Reflection + Credentials on GraphQL API Production (`api.[redacted].money`) ve staging (`api-staging.[redacted].money`) GraphQL API endpoint'leri, `Access-Control-Allow-Origin` header'ında gönderilen herhangi bir `Origin` değerini yansıtıyor ve `Access-C CVSS 9.3 | African Payment Gateway Africa | Credential Exposure | Responsible Disclosure | Critical | 2026-03 |
| ThirdParty App Key Renewal Without Authentication [CRITICAL] Finding 5: ThirdParty App Key Renewal Without Authentication [CRITICAL] Endpoint: POST /api/ThirdParty/App/RenewKeys ThirdParty App key renewal endpoint'i JWT auth gerektirmiyor. "User Not Found" hatasi donuyor (401 degil) - bu, auth katmaninin bypass edildigini ve business logic CVSS 9.3 | African DeFi Protocol Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| [redacted] Rtsp Audit [redacted] Kamera RTSP Guvenlik Denetimi Raporu Hedef: [ip] ([redacted] NVR/IP Kamera) Kapsam: Yetkili lokal ag pentest | Cihaz Turu | [redacted] NVR veya IP Kamera | CVSS 9.3 | CCTV Infrastructure Global | Auth Bypass | HackerOne | Critical | 2026-03 |
| The Tolgee XLIFF import endpoint does not disable external entity processing: The Tolgee XLIFF import endpoint does not disable external entity processing: After import + apply, the file content is stored as a translation value and readable via API. | File | Content | Criticality | |------|---------|-------------| CVSS 9.3 | Global Crypto Exchange Global | RCE | Responsible Disclosure | Critical | 2026-03 |
| Unsigned validity Window Metadata in ERC-4337 Wallet Signature validUntil/validAfter are appended to userOp.signature but never hashed, so any relayer can alter the validity window without invalidating the signer's ECDSA signature. CVSS 9.1 | Ethereum Attestation Protocol Global | Broken Authentication | Code4rena | Critical | 2026-03 |
| Ownership Slot Mismatch Bricks Smart Wallet After Claim Transition Wallet stores owner in both custom and OZ Ownable slots, and owner() switches source based on isClaimed, leaving the wallet ownerless after the two-step claim. CVSS 9.1 | Ethereum Attestation Protocol Global | Access Control | Code4rena | Critical | 2026-03 |
| KYC Document Bucket Public Access Leaks User Identity Documents Bucket lists and serves KYC front_image, liveness video and selfie images for registered users. CVSS 9.1 | African Crypto Exchange Africa | S3 Misconfig | Responsible Disclosure | Critical | 2026-03 |
| 8 Internal Services Publicly Accessible including Grafana and Admin Eight internal services reachable publicly including analytics, admin portal and staging env. CVSS 9.1 | African Fintech Neobank Africa | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-03 |
| CORS Origin Reflection + credentials:true on 7 APIs (ATO Chain) Busha 7 hosts reflect arbitrary origin with credentials, enabling cross-origin authenticated reads of 41 endpoints including PII. CVSS 9.1 | African Crypto Exchange Africa | CORS | Responsible Disclosure | Critical | 2026-03 |
| DigitalOcean Spaces Production Credentials Hardcoded Bitmama production JS bundle exposes DigitalOcean Spaces key and secret valid for account-level actions. CVSS 9.1 | African Crypto Exchange Africa | Credential Exposure | Responsible Disclosure | Critical | 2026-03 |
| Staging DO Spaces Credentials + Admin Panel Source Code Exposed Staging admin panel ships 26MB source map and embedded DO Spaces key. CVSS 9.1 | African Crypto Exchange Africa | Credential Exposure | Responsible Disclosure | Critical | 2026-03 |
| Enterprise API Tokens Exposed in Public Postman Documentation Public Postman collection hosts enterprise bearer tokens tied to live Heroku backends. CVSS 9.1 | African Crypto Exchange Africa | Credential Exposure | Responsible Disclosure | Critical | 2026-03 |
| n8n Workflow Automation Platform Exposed Self-hosted n8n v2.7.2 reachable publicly with API endpoints exposed. CVSS 9.1 | African Crypto Exchange Africa | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-03 |
| Unauthenticated Database Dump via Public test.php globaladmin.bitbns.com/test.php returns raw DB dump without auth. CVSS 9.1 | Indian Crypto Exchange SEA | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-03 |
| Unauthenticated Database Dump via admin CRM test.php admin.bitbns.com/bitbns/crm/test.php exposes DB dump unauthenticated. CVSS 9.1 | Indian Crypto Exchange SEA | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-03 |
| Two Freshdesk Subdomain Takeover Targets Two Freshdesk-pointing subdomains show dangling CNAMEs allowing takeover. CVSS 9.1 | Indian Crypto Exchange SEA | Subdomain Takeover | Responsible Disclosure | Critical | 2026-03 |
| Flutterwave SECRET Key + Encryption Key Exposed in Production JS Changera/Payborda JS exposes Flutterwave secret and AES encryption key used for payments. CVSS 9.1 | African Fintech Remittance Africa | API Key Exposure | Responsible Disclosure | Critical | 2026-03 |
| Roqqu Unsigned Cloudinary Upload to KYC Document Folder Cloudinary preset allows unsigned uploads to KYC folder enabling attacker-uploaded proofs. CVSS 9.1 | African Crypto Exchange Africa | Cloud Misconfig | Responsible Disclosure | Critical | 2026-03 |
| CORS Origin Reflection + Credentials Enables Full ATO Cardtonic API reflects origin including null with credentials across all endpoints. CVSS 9.1 | African Fintech Remittance Africa | CORS | Responsible Disclosure | Critical | 2026-03 |
| SignalR ChatHub Unauthenticated JWT Token Issuance ChatHub issues 1-hour JWTs unauthenticated enabling session identity forging. CVSS 9.1 | Gaming Top-Up Platform Global | JWT Issues | Responsible Disclosure | Critical | 2026-03 |
| CORS Origin Reflection + Credentials = Full ATO (Null Origin) usenosh.com reflects origin including null enabling iframe-sandbox ATO chain. CVSS 9.1 | Nigerian Gift Card Marketplace Africa | CORS | Responsible Disclosure | Critical | 2026-03 |
| Two AWS S3 Buckets Unauthenticated Object Access gcbuying buckets deny listing but permit direct-object read enabling object enumeration via key guessing. CVSS 9.1 | Nigerian Gift Card Marketplace Africa | S3 Misconfig | Responsible Disclosure | Critical | 2026-03 |
| CORS Wildcard on buffbuff Gaming Gateway api.buffbuff.top ACAO * + credentials enables zero-click ATO. CVSS 9.1 | Gaming Marketplace Global | CORS | Responsible Disclosure | Critical | 2026-03 |
| Spring Boot Admin Panel Publicly Reachable kefu89757 admin panel accepts brute-force logins over Akamai without WAF rules. CVSS 9.1 | Asian Gift-Card Marketplace SEA | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-03 |
| Multiple Payment Processors Hardcoded PayPal, Airwallex, Antom, PayerMax, Asiabill credentials in JS bundles. CVSS 9.1 | Asian Gift-Card Marketplace SEA | Credential Exposure | Responsible Disclosure | Critical | 2026-03 |
| Production API Key + Client ID Leaked in Merchant Panel JS REACT_APP_API_KEY + CLIENT_ID bundled in merchant panel allowing unauth access to production services. CVSS 9.1 | Central African Crypto Fintech Africa | Credential Exposure | Responsible Disclosure | Critical | 2026-03 |
| Cloudflare WAF Complete Bypass via Origin IP Origin IP 188.245.49.12 reachable bypassing CF WAF allowing unrestricted backend access. CVSS 9.1 | EU Gaming Marketplace EU | Cloud Misconfig | Responsible Disclosure | Critical | 2026-03 |
| Passbolt Full Config + GPG Key Exfiltration via SSRF Passbolt CE 5.9.0 self-registration + admin GPG key + email exfiltrated via SSRF. CVSS 9.1 | EU Gaming Marketplace EU | Credential Exposure | Responsible Disclosure | Critical | 2026-03 |
| SumSub KYC Webhook Forgery - No HMAC Validation KYC webhook accepts forged POSTs without X-Payload-Digest enabling AML bypass for any account. CVSS 9.1 | EU iGaming Operator EU | KYC Bypass | Responsible Disclosure | Critical | 2026-03 |
| Unauthenticated Refund Claim via UUID Full PII exposure + wallet hijack via refund-claim endpoint; 3.6M UUID/hr brute force with no rate limit. CVSS 9.1 | European Crypto Payment Gateway EU | Business Logic | Responsible Disclosure | Critical | 2026-03 |
| Shopware6 Plugin Webhook No Token Validation Callback handler has no token/HMAC validation; CSRF explicitly disabled. Attacker can forge order status updates without any auth. CVSS 9.1 | European Crypto Payment Processor EU | Webhook Forgery | Responsible Disclosure | Critical | 2026-03 |
| CSRF Protection Bypass via Hardcoded Fallback Token Angular fallback XSRF token hardcoded; full CSRF bypass enabling guest-token chain. CVSS 9.1 | Gaming Marketplace EU | Access Control | Responsible Disclosure | Critical | 2026-03 |
| Django DEBUG=True on stream subdomain stream.flitpay.com exposes 175 production settings including DB hostname/username. CVSS 9.1 | Indian Crypto Exchange SEA | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| 21.6 GB Public debug.log Exposes Payment Credentials and Server Paths Publicly accessible debug.log of 21.6 GB leaks payment gateway credentials, server file paths and broken S2S webhook details. CVSS 9.1 | Gaming Marketplace NA | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| RSA Private Key Exposed in HTML Source Production HTML embeds an RSA private key usable to decrypt or forge server-side operations. CVSS 9.1 | Gaming Marketplace SEA | Credential Exposure | Responsible Disclosure | Critical | 2026-03 |
| Google OAuth Client Secret Exposed in HTML Google OAuth client secret hard-coded in HTML permits SSO flow takeover or spoofed server exchange. CVSS 9.1 | Gaming Marketplace SEA | Credential Exposure | Responsible Disclosure | Critical | 2026-03 |
| Seven Unauthenticated Payment Webhook Endpoints (PayPal/Stripe/Coinbase/Skrill/Payssion) Multiple payment webhooks lack signature validation enabling forged deposit notifications for seven different payment rails. CVSS 9.1 | Gaming Marketplace SEA | Webhook Forgery | Responsible Disclosure | Critical | 2026-03 |
| Laravel Horizon Dashboard Unauthenticated Read + Write Laravel Horizon reachable without auth permitting queue inspection and job manipulation. CVSS 9.1 | Gaming Marketplace EU | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-03 |
| Mass Customer IDOR Exposes 60,623+ Users PII Customer endpoint enumerable by sequential ID discloses 60K+ user PII including KYC and wallet data. CVSS 9.1 | African Crypto Exchange Africa | IDOR | Responsible Disclosure | Critical | 2026-03 |
| CORS Origin Reflection on Production API Enables ATO Production API reflects any Origin header with credentials allowing cross-origin account takeover chain. CVSS 9.1 | African Fintech Africa | CORS | Responsible Disclosure | Critical | 2026-03 |
| Payment Provider Toggle Enables Remote DoS Provider enable/disable admin endpoint reachable without admin check allowing attacker to disable all 11 payment providers causing platform-wide DoS. CVSS 9.1 | African Fintech Africa | Business Logic | Responsible Disclosure | Critical | 2026-03 |
| Tanda Webhook BullMQ/Redis Infrastructure Leak via Content-Type Manipulating Content-Type on Tanda webhook leaks internal BullMQ/Redis error details exposing infrastructure. CVSS 9.1 | African Fintech Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| 17.1MB Source Map Exposes Complete Admin Dashboard Source Admin dashboard ships a 17MB source map revealing 180 internal admin endpoints and business flows. CVSS 9.1 | African Payment Gateway Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| CORS Origin Reflection with Credentials (Account Takeover) P2P trading API reflects arbitrary Origin with credentials enabling ATO of users visiting attacker site. CVSS 9.1 | African P2P Crypto Platform Africa | CORS | Responsible Disclosure | Critical | 2026-03 |
| Unauthenticated Mass Customer PII Exposure via GraphQL GraphQL endpoint returns enumerable customer PII including addresses and loyalty data without authentication. CVSS 9.1 | MENA Travel Fintech MENA | GraphQL Issues | Responsible Disclosure | Critical | 2026-03 |
| Direct HLS Stream Access Without Authentication Premium content HLS master and segment URLs directly accessible without auth bypassing paid subscription. CVSS 9.1 | CIS Streaming Platform MENA | Access Control | Responsible Disclosure | Critical | 2026-03 |
| Phone Verification Set to Mock Mode in Production Production phone verification service configured to mock mode allowing any code to pass during registration. CVSS 9.1 | LATAM Crypto Exchange LATAM | Broken Authentication | Responsible Disclosure | Critical | 2026-03 |
| Auth0 Open Registration Enables Unlimited Account Creation Auth0 tenant allows public signups with email enumeration and arbitrary password reset. CVSS 9.1 | LATAM Crypto Exchange LATAM | Broken Authentication | Responsible Disclosure | Critical | 2026-03 |
| Monad RPC Debug Namespace Enabled Without API Key Monad RPC exposes debug_traceCall/debug_traceBlockByNumber without authentication enabling MEV sandwich attacks and pre-image extraction on DEX swaps. CVSS 9.1 | DeFi DEX Protocol Global | Oracle Manipulation | Responsible Disclosure | Critical | 2026-03 |
| API Authorization Keys Hardcoded in JavaScript Frontend bundle embeds API authorization keys usable against admin endpoints. CVSS 9.1 | African DeFi Platform Africa | Credential Exposure | Responsible Disclosure | Critical | 2026-03 |
| CRITICAL - Supabase Admin Password Exposed via Unauthenticated Database Access (bybit.[vendor]) Vulnerable Endpoint: https://kntlvmafkdfzneiugdck.supabase.co/rest/v1/admin_settings CVSS 9.1 | African Payment Processor Africa | Cloud Misconfig | Responsible Disclosure | Critical | 2026-03 |
| CRITICAL - CORS Wildcard with Credentials on Production API Vulnerable Endpoints: - https://api.[vendor] (Production API) - https://business-banking.[vendor] (Business Banking API) CVSS 9.1 | African Payment Processor Africa | CORS | Responsible Disclosure | Critical | 2026-03 |
| Email Verification Token Brute Force - Account Takeover POST /api/auth/verify-email endpointi 6 karakterlik verification token kabul eder. Bu endpoint'te HICBIR rate limiting uygulanmamis. Saldirgan, herhangi bir kullanicinin email verification token'ini brute force ederek hesabini verify edebilir ve bu fintech platformunda islem yapabilir CVSS 9.1 | African Remittance Platform Africa | Broken Authentication | Responsible Disclosure | Critical | 2026-03 |
| CORS Wildcard + Credentials on currency-api.[vendor] currency-api.[vendor] endpointi Access-Control-Allow-Origin: ile birlikte Access-Control-Allow-Credentials: true set ediyor. Bu, tarayici tarafindan her zaman uygulanmasa da (spec'e gore bu kombinasyon engellenmelidir), bazi eski tarayicilar veya yanlis yapilandirilmis proxy'ler bunu izin verebilir. Daha onemlisi, bu yapilandirma guvenlik bi CVSS 9.1 | African Remittance Platform Africa | CORS | Responsible Disclosure | Critical | 2026-03 |
| CORS Wildcard on Financial/Checkout Endpoints Enables Cross-Origin Purchase and Balance Theft Beyond the user profile endpoints (Finding 13), the SLS API also exposes financial and checkout endpoints with CORS wildcard (), including checkout/buyNow/buy, store-credit/get-balance, userBar/getCustomerScWor (store credit/wallet), and site/getAIChatSessionToken. Combined with the localStorage token storage (Finding 17), an attacker with a sto CVSS 9.1 | SEA Gaming Marketplace SEA | CORS | HackerOne | Critical | 2026-03 |
| Sentry DSN Exposure + Event Injection (Stored XSS via Error Events) The self-hosted Sentry instance at apm.[vendor] leaks its DSN (Data Source Name) key in the login page's __initialData JavaScript object. This DSN allows any unauthenticated attacker to inject arbitrary error events, including crafted XSS payloads, into the Sentry dashboard. When an administrator views these injected events, the XSS CVSS 9.1 | NA Gift Card Supplier NA | XSS | Responsible Disclosure | Critical | 2026-03 |
| Laravel Horizon Dashboard -- Unauthenticated Full Access Endpoint: https://sandbox.[vendor]/horizon CVSS 9.1 | EU Digital Goods Marketplace EU | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-03 |
| Queue Manipulation via CSRF Token Extraction (Job Retry + Batch Retry) POST endpoints on Horizon require CSRF token, but the token is freely obtainable from the Horizon page itself (which is unauthenticated). By first fetching the page to get session cookies + XSRF-TOKEN, then including the decoded XSRF-TOKEN in the X-XSRF-TOKEN header, all POST operations succeed. This enables CVSS 9.1 | EU Digital Goods Marketplace EU | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-03 |
| Predictive Audience API Exposed - Unauthenticated IDOR + Swagger + Pipeline Execution [vendor]' Predictive Audience API is deployed on Azure App Service (pa-api-prod.azurewebsites.net) completely outside of Cloudflare WAF protection. The API has NO authentication whatsoever, exposes full Swagger/OpenAPI documentation, allows unauthenticated IDOR across all client IDs (user segmentation data, churn predictions, LTV data), an CVSS 9.1 | Gaming Marketplace NA | IDOR | Responsible Disclosure | Critical | 2026-03 |
| Strapi API Token Leaked in Client-Side JavaScript Vulnerable Endpoint: https://[vendor] (HTML source, __NUXT__ config) CVSS 9.1 | EU Gaming Marketplace EU | Credential Exposure | Responsible Disclosure | Critical | 2026-03 |
| K-1: [redacted] Setup-Token Exposed (CRITICAL) Finding K-1: [redacted] Setup-Token Exposed (CRITICAL) Endpoint: `https://[redacted] com/api/session/properties` Additionally accessible on direct IP (bypassing any WAF): CVSS 9.1 | African Neobank Africa | Admin Panel Exposure | Responsible Disclosure | Critical | 2026-03 |
| B — LSLB API Unauthenticated Business Data Exposure (78 Production Records) Finding 0B — LSLB API Unauthenticated Business Data Exposure (78 Production Records) CVSS: 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N) The LSLB (Lagos State Lotteries Board) permit management API at `api-prod.lslb.[redacted].co` returns 78 production business records (Niger CVSS 9.1 | African KYC Provider Africa | IDOR | Responsible Disclosure | Critical | 2026-03 |
| Sea Mena Turkey Scan SEA / MENA / Turkey Crypto-Fintech-Betting Platform Scan Scope: Southeast Asia, Middle East, Turkey — crypto exchanges, fintech, betting platforms Method: Automated reconnaissance (subdomain enum, .env, [redacted], Actuator, GraphQL, CORS, source maps, S3, [redacted], KYC dirs) | | Plat CVSS 9.1 | SEA/MENA Mass Scan MENA | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| 512-bit RSA Key for Login Encryption ([redacted]ially Factorable) Finding 2: 512-bit RSA Key for Login Encryption ([redacted]ially Factorable) CVSS Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Login islemi icin kullanilan RSA anahtari sadece 512-bit uzunlugunda. 512-bit RSA 1999 yilinda faktorize edildi (RSA-155). Modern donanim ile dakikalar icinde k CVSS 9.1 | CCTV Infrastructure Global | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| Unauthenticated Mass User Data Leak via Chat Messages Endpoint Finding 7: Unauthenticated Mass User Data Leak via Chat Messages Endpoint Severity: Critical (CVSS 9.1 - AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) The `/api/messages/` endpoint returns 1,000 chat messages from 492 unique users without ANY authentication. Each message includes the user CVSS 9.1 | NA Online Casino NA | Broken Authentication | Responsible Disclosure | Critical | 2026-03 |
| Crypto Exchange Scan Crypto Exchange Security Scan - 2026-03-23 Authorized Penetration Testing Report Targets: 10 cryptocurrency exchanges with public bug bounty/responsible disclosure programs Method: Subdomain enumeration (crt.sh), API/endpoint discovery, source map analysis, credential extraction, CVSS 9.1 | Crypto Exchange Scan Global | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| Final Deep Results [redacted].store Final Deep Dive -- All Findings Target: [redacted].store / [target] Bu final deep dive fazinda onceki tapdiqlar uzerine 7 yeni kritik ve yuksek severity bulgu ortaya cixarildi. Toplam etkile 1.44M istifadeci, 197K fatura kaydi, 69K email adresi, 851K degerlendirme ve CVSS 9.1 | SEA Crypto Exchange SEA | CORS | Responsible Disclosure | Critical | 2026-03 |
| Full [redacted] API Documentation Publicly Exposed (CRITICAL) Finding 3: Full [redacted] API Documentation Publicly Exposed (CRITICAL) Endpoint: `https://api.[redacted].az/[redacted]/index.html` The complete [redacted]/OpenAPI documentation for the OneXTwo CRM API is publicly accessible, exposing all 135 API endpoints with full request/response schema CVSS 9.1 | EU iGaming Operator EU | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| C — PEP/AML Service OpenAPI Spec & Endpoint Disclosure (Production) Finding 0C — PEP/AML Service OpenAPI Spec & Endpoint Disclosure (Production) CVSS: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) `pep-dom.svc.[redacted].co` (Domestic PEP Service) exposes its complete OpenAPI specification publicly, revealing 6+ PEP screening, conviction chec CVSS 9.1 | African KYC Provider Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| Login Rate Limit Bypass via X-Forwarded-For Header Spoofing Finding 1: Login Rate Limit Bypass via X-Forwarded-For Header Spoofing Severity: CRITICAL (CVSS 9.1 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) Summary: Django backend'i rate limiting icin client IP adresini `X-Forwarded-For` header'indan aliyor. Cloudflare arkasinda oldugu i CVSS 9.1 | NA Online Casino NA | Rate Limit Bypass | Responsible Disclosure | Critical | 2026-03 |
| Wildcard CORS Policy on Financial API Finding 5: Wildcard CORS Policy on Financial API The production API at `api.[redacted].ng` returns `Access-Control-Allow-Origin: ` on all endpoints, including admin and financial transaction APIs. The application uses Bearer token authentication stored in `localStorage`, which is CVSS 9.1 | Nigerian Payment Provider Africa | XSS | Responsible Disclosure | Critical | 2026-03 |
| — Unauthenticated ML Anomaly Detection Engine + [redacted] UI on Production Finding 0 — Unauthenticated ML Anomaly Detection Engine + [redacted] UI on Production CVSS: 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) The KYC/AML risk scoring service (FastAPI/Python) exposes [redacted] UI and full OpenAPI specification on BOTH development AND production. On t CVSS 9.1 | African KYC Provider Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| CORS Misconfiguration — Arbitrary Origin Reflection with Credentials (CRITICAL) Finding 1: CORS Misconfiguration — Arbitrary Origin Reflection with Credentials (CRITICAL) `api.[redacted].com` reflects ANY `Origin` header value in `Access-Control-Allow-Origin` with `Access-Control-Allow-Credentials: true`. This allows any malicious website to make authenticated CVSS 9.1 | Gaming Marketplace EU | CORS | Responsible Disclosure | Critical | 2026-03 |
| Deep Exploitation [redacted].[target] - Deep Penetration Test Report Target: [redacted].[target] (International Money Transfer Platform) Type: Authorized Penetration Testing Engagement [redacted]'in International Money Transfer (IMT) altyapisinda 10 guvenlik bulgusu tespit edildi: 1 Critical, 3 High, 4 Medium, 2 Low CVSS 9.1 | Turkish Payment Gateway MENA | CORS | Responsible Disclosure | Critical | 2026-03 |
| [redacted] OAuth OIDC Exploitation `testClientCreateDirectDeposit` mutation'i, normalde test ortami icin tasarlanmis olmasina ragmen, PRODUCTION GraphQL API'sinde aktif ve herhangi bir ek yetki kontrolu olmadan calistirilabiyor. Mutation basarili response dondurdu (`TestClientCreateDirectDepositPayload`). Ek test CVSS 9.1 | African Payment Gateway Africa | Webhook Forgery | Responsible Disclosure | Critical | 2026-03 |
| Google OAuth hosted_domain Bypass Potential OAuth client lacks server-side hosted_domain check, attacker can craft token with arbitrary hd claim. CVSS 9.0 | SEA Banking API Platform SEA | Broken Authentication | Responsible Disclosure | Critical | 2026-03 |
| CRM 17+ Unauthenticated Financial Admin Actions CRM exposes 17+ admin actions (wallet credit, KYC approve) without authentication. CVSS 9.0 | Indian Crypto Exchange SEA | BFLA | Responsible Disclosure | Critical | 2026-03 |
| Roqqu AES-256-CTR Encryption Key Exposed Full API Traffic Decryption Static AES-256-CTR key found in JS bundle decrypts all encrypted API traffic. CVSS 9.0 | African Crypto Exchange Africa | Credential Exposure | Responsible Disclosure | Critical | 2026-03 |
| IDOR on User-Specific Endpoints (No Ownership Check) Several user endpoints accept arbitrary userId enabling cross-tenant reads. CVSS 9.0 | African Fintech Remittance Africa | IDOR | Responsible Disclosure | Critical | 2026-03 |
| Client-Side Password Hashing With Exposed Salt + PBKDF2 1000 CoinCola hashes passwords client-side with exposed salt and weak 1000-iteration PBKDF2 enabling rapid cracking. CVSS 9.0 | Global P2P Crypto Marketplace Global | Broken Authentication | Responsible Disclosure | Critical | 2026-03 |
| JWT Session Secret Leaked Enables Token Forge nosh.ng JWT secret discovered in public artifact allowing arbitrary user session forging. CVSS 9.0 | Nigerian Gift Card Marketplace Africa | JWT Issues | Responsible Disclosure | Critical | 2026-03 |
| SSRF to Internal GKE Services Finding 4: SSRF to Internal GKE Services HashiCorp Vault — Unsealed, Full Info Disclosure Vault `/v1/sys/internal/ui/mounts`: | Service | Port | Protocol | Status | CVSS 9.0 | Global Crypto Exchange Global | SSRF | Responsible Disclosure | Critical | 2026-03 |
| Password Hash Exposure on Registration Registration response echoes server bcrypt password hash which attacker can crack offline. CVSS 8.7 | African Crypto Exchange Africa | Credential Exposure | Responsible Disclosure | Critical | 2026-03 |
| 180 Admin API Endpoints Exposed via Source Map Reconstructed source reveals complete admin API surface including merchant, settlement and payout operations. CVSS 8.7 | African Payment Gateway Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| Akamai mPulse + Origin IP Bypass Origin IP 43.199.67.100 reachable bypassing Cloudflare/Akamai protection. CVSS 8.6 | Asian Gift-Card Marketplace SEA | Cloud Misconfig | Responsible Disclosure | Critical | 2026-03 |
| Admin GraphQL updateTransaction / createManualBatch Schema Exposure Admin GraphQL endpoint introspection reveals 18 admin types and financial mutation signatures. CVSS 8.6 | European Crypto Payment Gateway EU | GraphQL Issues | Responsible Disclosure | Critical | 2026-03 |
| RBAC Structure Full Exposure (11 Roles) RBAC role/permission endpoint unauthenticated reveals complete privilege taxonomy across 11 admin roles. CVSS 8.6 | African Crypto Exchange Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| Full Source Code Exposure via Source Maps (Admin + Customer) Customer and admin bundles expose .map files revealing complete TypeScript source of 126 files across services. CVSS 8.6 | African Crypto Exchange Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| Full Admin Source Code Exposure via Source Maps Production admin ships source maps revealing complete admin business logic. CVSS 8.6 | African DeFi Platform Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| Grafana /metrics Exposes Complete Infrastructure Telemetry 4735-line Prometheus dump reveals datasources, dashboards and admin identities. CVSS 8.5 | African Fintech Neobank Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| Payborda Dashboard Source Maps Expose 1492 Files 1492 source files (165 app files, 6.8MB) exposed via source maps including encryption logic. CVSS 8.5 | African Fintech Remittance Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| ASP.NET Dev API Stack Trace + Source Code Path Disclosure gamejus.com dev API leaks MSSQL column names and H:\Projects\ paths via stack trace. CVSS 8.5 | Gaming Top-Up Platform Global | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| Admin JS Leaks 120+ API Endpoints Including KYC and Bybit Auto-Sell gcbuying admin JS enumerates 120+ admin routes including KYC mgmt and Bybit integration. CVSS 8.5 | Nigerian Gift Card Marketplace Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| WebAuthn Passkey Credential ID Mass Leakage Passkey credential IDs returned enumerably enabling fingerprinting and replay scenarios across 2FA system. CVSS 8.1 | African Crypto Exchange Africa | Information Disclosure | Responsible Disclosure | Critical | 2026-03 |
| withdrawOtp Stored Plaintext Leaked via admin/viewDetail Withdrawal OTP stored unhashed and returned by admin/viewDetail enabling withdrawal replay. CVSS 9.8 | SEA P2P Crypto Exchange SEA | Credential Exposure | Responsible Disclosure | High | 2026-04 |
| admin/viewDetail Accepts Leaked twoFAToken as Auth admin/viewDetail authenticates on twoFAToken alone which is recoverable via NoSQL injection, exposing admin profile. CVSS 9.8 | SEA P2P Crypto Exchange SEA | Auth Bypass | Responsible Disclosure | High | 2026-04 |
| Full Stack Trace Disclosure in Production Crypto API Invalid apiKey triggers full stack trace leaking framework versions, internal file paths and DB model names. CVSS 9.8 | SEA P2P Crypto Exchange SEA | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| TOTP OTP Verify Endpoint Brute Force With Minimal Rate Limiting Verify endpoint permits ~5 tries before soft lockout; chained with OTP generate enables realistic OTP guessing. CVSS 9.3 | Indian Investment Broker SEA | Rate Limit Bypass | Responsible Disclosure | High | 2026-04 |
| TOTP 2FA Secret Exposed in Plaintext via Profile API Authenticated user can retrieve their TOTP secret seed in plaintext, allowing attackers with session hijack to clone 2FA indefinitely. CVSS 9.1 | European Payment Gateway EU | Credential Exposure | Responsible Disclosure | High | 2026-04 |
| Keycloak Admin Console Publicly Accessible Keycloak admin UI reachable without IP restriction and with insecure grant types enabled. CVSS 8.8 | SEA Investment Platform SEA | Admin Panel Exposure | Responsible Disclosure | High | 2026-04 |
| API CORS Wildcard + Mass Assignment on Registration [CRITICAL] Vulnerable Endpoint: POST https://app.[vendor]/api/register CVSS 8.8 | Crypto Exchange Platform Global | Mass Assignment | HackerOne | High | 2026-04 |
| Deep Scan Findings The endpoint accepts a JSON body with `email` and `phone` fields, and returns a signed JWT token containing those exact values. No validation is performed: - Any email/phone combination accepted - Token expiry is approximately 24 hours 3. Generate token for arbitrary user: CVSS 8.8 | MENA Crypto Exchange MENA | JWT Issues | Responsible Disclosure | High | 2026-04 |
| Client Bank Account Details Manipulation via Unprotected Update API Authenticated user can modify arbitrary client bank details through an unrestricted endpoint, redirecting payouts to attacker accounts. CVSS 8.6 | European Payment Gateway EU | BFLA | Responsible Disclosure | High | 2026-04 |
| Unauthenticated Payment Event Injection via Partner Callback Partner callback endpoint has no signature check so attackers can inject arbitrary payment events for any merchant. CVSS 8.6 | European Payment Gateway EU | Webhook Forgery | Responsible Disclosure | High | 2026-04 |
| Signed PPM Investor Contracts Public in startups-bucket S3 bucket exposes signed Private Placement Memorandum contracts with investor signatures. CVSS 8.6 | Series B African Fintech Africa | S3 Misconfig | Responsible Disclosure | High | 2026-04 |
| Vite Dev Server in Production Source Disclosure takephlight subdomain runs vite dev server exposing /@vite/client, /@fs/ paths. CVSS 8.6 | Series B African Fintech Africa | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Real-Time KYC Data Leakage via Kafka Kafka topics stream real-time KYC submissions unencrypted to anonymous Kafka UI readers. CVSS 8.6 | African Fintech Marketplace Africa | KYC Bypass | Responsible Disclosure | High | 2026-04 |
| Swagger UI / Full API Specification Public on 3 Subdomains [CRITICAL] Vulnerable Endpoints: - https://xchangeapi.[vendor]/api - https://instbtc.[vendor]/api - https://awstron.[vendor]/api CVSS 8.6 | Crypto Exchange Platform Global | Business Logic | Responsible Disclosure | High | 2026-04 |
| SumSub Webhook Without Signature Verification Vulnerable Endpoint: https://test.[vendor]/kyc/sumsub_webhook/ CVSS 8.6 | EU Crypto Exchange EU | KYC Bypass | HackerOne | High | 2026-04 |
| Expo OTA Staging Channel Publicly Accessible The Expo EAS Update staging channel is publicly accessible, exposing the development/test server configuration and allowing download of staging JavaScript bundles CVSS 8.6 | EU Crypto Exchange EU | Business Logic | Responsible Disclosure | High | 2026-04 |
| CRITICAL - Supabase HawkVibes HR Platform with 48 Tables (Employee Performance, Salary, Compensation) A second Supabase instance at hawkvibes.[vendor] exposes 48 database tables including compensations, salary_ranges, salary_ranges_private, employee_feedback, performance_commentaries, employee_scores, penalties, and audit_logs. While currently empty (possibly new deployment), the schema is fully accessible via anon key with CORS wildcard CVSS 8.6 | European B2B Spend Management EU | Cloud Misconfig | Responsible Disclosure | High | 2026-04 |
| VIP Wallet Access Control Bypass CVSS 8.6 | Crypto Payment Processor Global | Access Control | Responsible Disclosure | High | 2026-04 |
| VIP Wallet Access Control Bypass (Non-VIP->VIP) Total: 12 Critical + 6 High + 3 Medium = 21 unique findings CVSS 8.6 | Crypto Payment Processor Global | Access Control | Responsible Disclosure | High | 2026-04 |
| Live Payment Webhook Hijack to Attacker-Controlled URL Authenticated user can overwrite live webhook URL for all events, redirecting all merchant notifications to attacker-controlled endpoint. CVSS 8.5 | European Payment Gateway EU | Webhook Forgery | Responsible Disclosure | High | 2026-04 |
| Admin Panel Zero Server-Side Authentication Admin pages rely exclusively on client-side redirects allowing direct URL access. CVSS 8.5 | African Crypto Gift Card Platform Africa | Auth Bypass | Responsible Disclosure | High | 2026-04 |
| Druid SQL Monitor Public on 13 Endpoints Across 3 Domains Alibaba Druid SQL monitoring UI exposed publicly on 13 endpoints. CVSS 8.5 | Gaming Marketplace SEA | Admin Panel Exposure | Responsible Disclosure | High | 2026-04 |
| ArgoCD Production Unauthenticated Settings Exposure Production ArgoCD v3.0.11 exposes settings including execEnabled:true and Lua health checks. CVSS 8.5 | African Neobank Africa | Admin Panel Exposure | Responsible Disclosure | High | 2026-04 |
| CORS Wildcard With Credentials on Production Financial APIs All production financial APIs return ACAO: * enabling cross-origin credentialed requests and account takeover chains. CVSS 8.1 | European Payment Gateway EU | CORS | Responsible Disclosure | High | 2026-04 |
| CORS Origin Reflection With Credentials on Payment API API reflects arbitrary Origin with Allow-Credentials: true, allowing full cross-origin session theft. CVSS 8.1 | European Payment Gateway EU | CORS | Responsible Disclosure | High | 2026-04 |
| 2FA Bypass Grants Full Dashboard Without Verification Step After password login the user reaches the merchant dashboard without completing the 2FA challenge, bypassing the second factor. CVSS 8.1 | European Payment Gateway EU | Auth Bypass | Responsible Disclosure | High | 2026-04 |
| Business Logic Flaw: Cancelled Purchase Re-Marked as Paid Cancelled purchase can be re-transitioned to paid via mark_as_paid without validation, causing goods release without payment. CVSS 8.1 | European Payment Gateway EU | Business Logic | Responsible Disclosure | High | 2026-04 |
| CORS Wildcard With Permissive Headers on API All origins accepted with credentials and Authorization reflected, enabling credentialed cross-origin attacks. CVSS 8.1 | SEA P2P Crypto Exchange SEA | CORS | Responsible Disclosure | High | 2026-04 |
| Fixed Bcrypt Salt Makes Identical Passwords Hash Identically Static salt reuse across users allows rainbow-table style precomputation and common-password cracking. CVSS 8.1 | SEA P2P Crypto Exchange SEA | Broken Authentication | Responsible Disclosure | High | 2026-04 |
| Pre-Auth Bypass on Accounts and Order Submit APIs Order submit and accounts endpoints accept requests without valid JWT enabling trade parameter discovery. CVSS 8.1 | Indian Crypto Exchange SEA | Auth Bypass | Responsible Disclosure | High | 2026-04 |
| CORS Wildcard + Credentials True on Four API Services Four API subdomains return ACAO * and Allow-Credentials true, bypassing same-origin policy. CVSS 8.1 | MENA Crypto Exchange MENA | CORS | Responsible Disclosure | High | 2026-04 |
| lenda-app - Firestore Open with User Data lenda-app Firestore readable unauth exposing lending user records. CVSS 8.1 | African Fintech Firebase Cohort Africa | Firebase Misconfig | Responsible Disclosure | High | 2026-04 |
| Dispute Approval Admin API Without Auth POST /trade/disputes/approve/{id} on admin-api reachable with weak/bypassable auth. CVSS 8.1 | African P2P Crypto Settlement Africa | Access Control | Responsible Disclosure | High | 2026-04 |
| Rate Manipulation via PATCH /rate Admin PATCH /rate accessible via predictable token enabling rate manipulation. CVSS 8.1 | African P2P Crypto Settlement Africa | Business Logic | Responsible Disclosure | High | 2026-04 |
| 2FA Token Brute Force No Rate Limiting 2FA endpoint accepts unlimited attempts enabling brute force. CVSS 8.1 | African Payment Platform Africa | Rate Limit Bypass | Responsible Disclosure | High | 2026-04 |
| Mass KYC File Metadata Exposure (342+ Files) /files endpoint returns all platform KYC documents metadata with pagination. CVSS 8.1 | West African Crypto Exchange Africa | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Unrestricted Registration + OTP Brute Force Chain Zero rate limit on DO direct origin OTP endpoint enables mass account creation/takeover. CVSS 8.1 | West African Crypto Exchange Africa | Rate Limit Bypass | Responsible Disclosure | High | 2026-04 |
| Cloudflare Turnstile Server-Side Validation Missing Auth endpoints accept any or missing Turnstile token because server-side validation is absent. CVSS 8.1 | European iGaming Platform EU | Broken Authentication | Private Engagement | High | 2026-04 |
| No Rate Limiting on PIN Verification and Login PIN and login endpoints accept unlimited attempts allowing brute force for account compromise. CVSS 8.1 | EU EdTech Platform EU | Rate Limit Bypass | Responsible Disclosure | High | 2026-04 |
| [vendor] - P2P Partner, Race Condition, Financial Endpoint Security Test Report Tarih: 2026-03-23 Hedef: [vendor] (Vietnam merkezli kripto borsasi) User ID: 1925403 (eagle8265934 / resadsabir5@gmail.com) Yetkilendirme: Authorized Bug Bounty Stack: Next.js + Node.js/Express + MongoDB + Socket.IO + Cloudflare CVSS 8.1 | SEA Crypto Exchange SEA | Race Condition | Responsible Disclosure | High | 2026-04 |
| CORS Misconfiguration - Access-Control-Allow-Origin: with Sensitive Data The API returns Access-Control-Allow-Origin: on ALL responses, including those containing PII bank data. Combined with the IDOR (Finding 1), this means any website can read any user's bank information via JavaScript cross-origin requests CVSS 8.1 | SEA Crypto Exchange SEA | CORS | Responsible Disclosure | High | 2026-04 |
| Strapi CMS Unauthenticated Blog Content Modification > NEW FINDING CVSS 8.1 | African SME Lender Africa | XSS | Responsible Disclosure | High | 2026-04 |
| JWT twoFAToken Contains Plaintext Admin Password Decoded twoFAToken JWT payload embeds admin plaintext password, bypassing hashing protections. CVSS 8.0 | SEA P2P Crypto Exchange SEA | JWT Issues | Responsible Disclosure | High | 2026-04 |
| Hidden Admin Dashboard Route Exposed Undocumented admin route discoverable via source map reaches authenticated admin UI. CVSS 8.0 | Indian Crypto Exchange SEA | Admin Panel Exposure | Responsible Disclosure | High | 2026-04 |
| Hardcoded API Keys and Secrets in Client-Side JavaScript Multiple third-party API keys exposed in JS including analytics, push and object-store with verified active status. CVSS 8.0 | African Crypto Aggregator Africa | API Key Exposure | Responsible Disclosure | High | 2026-04 |
| Universal CORS Wildcard on 392 API Endpoints All 392 PHP API endpoints return ACAO * enabling cross-origin reads of authenticated data. CVSS 8.0 | African Crypto Gift Card Platform Africa | CORS | Responsible Disclosure | High | 2026-04 |
| 16+ Spring Boot Actuator Endpoints Exposed on 8 Domains Spring Boot actuator endpoints allow env dump and heap snapshots on 8 domains. CVSS 8.0 | Gaming Marketplace SEA | Admin Panel Exposure | Responsible Disclosure | High | 2026-04 |
| OTP Rate Limiting Set to Zero OTP endpoint has no throttle enabling SMS bomb and brute force. CVSS 8.0 | Gaming Marketplace SEA | Rate Limit Bypass | Responsible Disclosure | High | 2026-04 |
| SigNoz Enterprise Monitoring Platform Public Exposure [HIGH] Finding 5: SigNoz Enterprise Monitoring Platform Public Exposure [HIGH] Summary: signoz.[redacted].ng adresinde SigNoz v0.115.0 Enterprise Edition monitoring platformu public internet'e acik. Version bilgisi ve setup durumu unauthenticated olarak ogrenilebiliyor. Platform traces, lo CVSS 7.8 | Nigerian Neobank Africa | Auth Bypass | Responsible Disclosure | High | 2026-04 |
| Stored XSS via Feedback Form (HIGH - CVSS 7.3) Finding 16: Stored XSS via Feedback Form (HIGH - CVSS 7.3) Vulnerable Endpoint: `POST https://thor.[redacted].com/api/feedback` Type: Stored Cross-Site Scripting (CWE-79) Admin reviews feedback in Nova -> XSS fires -> admin session compromise. CVSS 7.8 | African Crypto Exchange Africa | XSS | Responsible Disclosure | High | 2026-04 |
| HIGH - Unauthenticated Currency Data Exposure Finding 3: HIGH - Unauthenticated Currency Data Exposure URL: `GET https://api.[redacted].site/v1/misc/fiat-currencies` CVSS 7.8 | Mixed Platforms Global | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Mass Db Scan Mass Database/Admin Panel Scan Results Objective: Find platforms with exposed [redacted], phpMyAdmin, Adminer, or Firebase RTDB with real user data Regions: Southeast Asia, Middle East, Eastern Europe, Africa | [redacted] instances found | 6 | CVSS 7.8 | Mass DB Scan Global | Admin Panel Exposure | Responsible Disclosure | High | 2026-04 |
| Spring Boot Actuator + [redacted] UI Exposure (bydatawelive.[redacted].ng) [HIGH] Finding 4: Spring Boot Actuator + [redacted] UI Exposure (bydatawelive.[redacted].ng) [HIGH] Summary: bydatawelive.[redacted].ng adresinde "Topupbox" (Zeedlabs) airtime/data vending servisi calisiyor. Spring Boot Actuator endpoint'leri ve [redacted] UI public erisime acik. Actuator health/in CVSS 7.8 | Nigerian Neobank Africa | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Security Finding Only the `Ocp-Apim-Subscription-Key` header is required - no authentication token needed. - PROD: `[target]` - PROD: `[target]` - DEV: `c CVSS 7.8 | African Remittance Provider Africa | Cloud Misconfig | Responsible Disclosure | High | 2026-04 |
| Stored XSS via Bank Account Fields (HIGH - CVSS 7.6) Finding 15: Stored XSS via Bank Account Fields (HIGH - CVSS 7.6) Vulnerable Endpoint: `POST https://thor.[redacted].com/api/banks` Type: Stored Cross-Site Scripting (CWE-79) Same as Finding 14 - when admin views user's bank account d[redacted]s in Nova panel, XSS executes. Can be combine CVSS 7.8 | African Crypto Exchange Africa | XSS | Responsible Disclosure | High | 2026-04 |
| HIGH - Agent Portal Source Maps Exposed Across Country Instances Finding 3: HIGH - Agent Portal Source Maps Exposed Across Country Instances The [redacted] Agent Portal at `agents.[redacted].com` and country-specific instances (`bf.agents.[redacted].com`, `ci.agents.[redacted].com`, etc.) serve source maps for all JavaScript bundles. - Multi-country deployment (bf, c CVSS 7.8 | African Neobank Africa | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| JWT Exploit Results Critical Discovery: Device tokens pass BOTH web AND admin auth middleware | Auth Method | web/transactions | admin/users | web/configs | admin/teams | |---------------------|-----------------|-------------|-------------|-------------| | No auth | 401 | 401 | 401 | 401 | CVSS 7.8 | Nigerian Payment Provider Africa | JWT Issues | Responsible Disclosure | High | 2026-04 |
| WSO2 API Manager Publisher Console + DevPortal Public Access [HIGH] Finding 3: WSO2 API Manager Publisher Console + DevPortal Public Access [HIGH] Summary: apiconsole.[redacted].ng adresinde WSO2 API Manager Publisher Console ve DevPortal public internet'e acik. Publisher API 401 donuyor (auth gerekli) ancak Publisher UI, DevPortal UI, settings dosy CVSS 7.8 | Nigerian Neobank Africa | Rate Limit Bypass | Responsible Disclosure | High | 2026-04 |
| Session Not Invalidated After Password Change on Payment Gateway Password change does not terminate existing sessions, allowing stolen-token reuse indefinitely. CVSS 7.5 | European Payment Gateway EU | Broken Authentication | Responsible Disclosure | High | 2026-04 |
| Full Application Source Code Exposure via Public Source Maps Auth and profile apps expose 18.5MB source maps (2227 files) disclosing full auth flow, KYC logic, OAuth config and 50+ API endpoints. CVSS 7.5 | European Payment Gateway EU | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Authentication Bypass on Consumer Financing Order Endpoints Financing order endpoints accessible without auth, exposing order data and enabling potential abuse of BNPL flow. CVSS 7.5 | European Payment Gateway EU | Auth Bypass | Responsible Disclosure | High | 2026-04 |
| HTML Email Injection via Purchase Receipts Enables Phishing Product name field is rendered in receipt HTML emails without encoding allowing arbitrary phishing payloads from merchant-branded sender. CVSS 7.5 | European Payment Gateway EU | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Arbitrary Live API Key Creation Without Password Confirmation Authenticated session can mint new live API keys without re-auth, enabling persistent access after session hijack. CVSS 7.5 | European Payment Gateway EU | Broken Authentication | Responsible Disclosure | High | 2026-04 |
| Zero-Amount Preauthorization Combined With mark_as_paid Zero-amount preauth then marked paid completes an order without a real payment capture. CVSS 7.5 | European Payment Gateway EU | Business Logic | Responsible Disclosure | High | 2026-04 |
| Live API Key Secret Exposed in Plaintext via List Endpoint /api/keys endpoint returns secret keys in plaintext on listing, violating key-display-once policy. CVSS 7.5 | European Payment Gateway EU | Credential Exposure | Responsible Disclosure | High | 2026-04 |
| Billing Invoice Abuse via mark_as_paid Without Real Payment Merchant can create invoices and mark them paid internally to inflate revenue figures or trigger delivery without payment. CVSS 7.5 | European Payment Gateway EU | Business Logic | Responsible Disclosure | High | 2026-04 |
| Unauthenticated Socket.IO Real-Time Stream Socket.IO endpoint broadcasts real-time trade notifications and user presence without requiring auth. CVSS 7.5 | SEA P2P Crypto Exchange SEA | WebSocket Issues | Responsible Disclosure | High | 2026-04 |
| Unauthenticated Invoice Creation via IDOR Invoice creation endpoint skips userId ownership check, allowing arbitrary invoices against any target. CVSS 7.5 | SEA P2P Crypto Exchange SEA | IDOR | Responsible Disclosure | High | 2026-04 |
| ReKYC Encryption Equals No Encryption (Fixed Static Key) ReKYC module ships with deterministic encryption key in APK, allowing decryption of any intercepted ReKYC payload. CVSS 7.5 | Indian Investment Broker SEA | Credential Exposure | Responsible Disclosure | High | 2026-04 |
| Ledger Service Kong Gateway Balance API Unauthorized Access Ledger balance API reachable via Kong without proper identity propagation allowing partial data retrieval. CVSS 7.5 | Indian Investment Broker SEA | Access Control | Responsible Disclosure | High | 2026-04 |
| Unauthenticated Discovery Config Exposes 287 Keys and 89 Internal Hosts Discovery config endpoint returns zlib-compressed map of 287 keys and 89 internal production hostnames. CVSS 7.5 | Indian Investment Broker SEA | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| SmartAPI Source Maps Exposed (6.2MB Full Frontend) SmartAPI developer portal ships source maps disclosing 47 internal API endpoints and auth flow. CVSS 7.5 | Indian Investment Broker SEA | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| UAT Trading Platform Exposed on Direct EC2 With Live Routes UAT trade host reachable on direct EC2 IP with 384 internal URLs and exposed robots.txt. CVSS 7.5 | Indian Investment Broker SEA | Admin Panel Exposure | Responsible Disclosure | High | 2026-04 |
| Hardcoded AES Key smartapi2024 + Full Source via Source Map Static AES key in SmartAPI portal decrypts all API calls, combined with source map leaks. CVSS 7.5 | Indian Investment Broker SEA | Credential Exposure | Responsible Disclosure | High | 2026-04 |
| HyperVerge KYC SDK Production Credentials in APK Production and UAT HyperVerge appId+secret in APK allow direct KYC workflow invocation and analytics ingestion. CVSS 7.5 | Indian Investment Broker SEA | API Key Exposure | Responsible Disclosure | High | 2026-04 |
| Exported Push Intent Enables Arbitrary Deep Link and WebView Routing Exported push-notification intent accepts attacker-controlled URL and forwards into authenticated TWA/WebView. CVSS 7.5 | Indian Investment Broker SEA | Deeplink Hijacking | Responsible Disclosure | High | 2026-04 |
| App-Link Wrappers With Nested link= Parameter Bypass Origin Control Allowed wrapper domain forwards nested link= param into TWA context skipping origin validation. CVSS 7.5 | Indian Investment Broker SEA | Deeplink Hijacking | Responsible Disclosure | High | 2026-04 |
| Java Trading Application JAR Publicly Downloadable Stock trading JNLP/JAR downloadable anonymously, exposing outdated libs vulnerable to deserialization CVEs. CVSS 7.5 | SEA Investment Platform SEA | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Backup-Prioritas Admin Panel Full Source Code Exposure Backup admin panel source maps leak investor management flows and session logic. CVSS 7.5 | SEA Investment Platform SEA | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| OTC Source Map Exposes 856 Files and Razorpay Key Production OTC bundle ships source map with 856 files and Razorpay public key. CVSS 7.5 | Indian Crypto Exchange SEA | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Exchange Source Maps Reveal 1337 Files and Admin JWT Exchange UI source map includes developer admin JWT and credentials in code comments. CVSS 7.5 | Indian Crypto Exchange SEA | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Wildcard CORS on Exchange API With Credentials Public exchange API reflects ACAO with credentials enabling cross-origin trade APIs. CVSS 7.5 | Indian Crypto Exchange SEA | CORS | Responsible Disclosure | High | 2026-04 |
| CORS Wildcard on API Backend All API endpoints reflect ACAO * allowing cross-origin reads of authenticated user data. CVSS 7.5 | EU Crypto ATM Operator EU | CORS | Responsible Disclosure | High | 2026-04 |
| Admin Dashboard Publicly Accessible With Full Route Exposure Admin SPA reachable without IP allowlist and ships route map to all admin modules. CVSS 7.5 | African Crypto Aggregator Africa | Admin Panel Exposure | Responsible Disclosure | High | 2026-04 |
| Development and Staging Environments Publicly Accessible Multiple dev/staging hosts serve identical codebase to prod, usable as test lab for exploits. CVSS 7.5 | African Crypto Aggregator Africa | Admin Panel Exposure | Responsible Disclosure | High | 2026-04 |
| Admin Panel Publicly Accessible With Full Frontend Source Admin panel reachable publicly and ships 753KB of frontend source revealing admin routes. CVSS 7.5 | MENA Crypto Exchange MENA | Admin Panel Exposure | Responsible Disclosure | High | 2026-04 |
| Rancher Dashboard UI Publicly Accessible Rancher UI publicly reachable, disclosing K8s/Rancher versions and cluster inventory. CVSS 7.5 | MENA Crypto Exchange MENA | Admin Panel Exposure | Responsible Disclosure | High | 2026-04 |
| CRM Admin Panel Publicly Accessible Bitdenex CRM admin reachable without IP allowlist, exposing internal dashboard. CVSS 7.5 | MENA Crypto Exchange MENA | Admin Panel Exposure | Responsible Disclosure | High | 2026-04 |
| Full Application Source Code Exposure via Source Maps bitexlive.com ships .map files exposing full JS application. CVSS 7.5 | SEA Crypto Exchange SEA | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Unauthenticated Sidekiq Dashboard coinome.com exposes legacy Sidekiq v5.0.4 dashboard without auth revealing job queues. CVSS 7.5 | Indian Crypto Exchange SEA | Admin Panel Exposure | Responsible Disclosure | High | 2026-04 |
| 18+ Production Backend Microservices Exposed koinpark.com exposes 18+ internal microservices directly to the internet. CVSS 7.5 | Indian Crypto Exchange SEA | Admin Panel Exposure | Responsible Disclosure | High | 2026-04 |
| Insufficient Rate Limiting on OTP Verification OTP verify endpoint permits enough attempts to brute force 6-digit code in minutes. CVSS 7.5 | African Fintech Neobank Africa | Rate Limit Bypass | Responsible Disclosure | High | 2026-04 |
| Full Source Map Exposure 48.6MB Production Build Production Next.js build ships source maps totaling 48.6MB exposing internal modules. CVSS 7.5 | African Fintech Expense Platform Africa | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Multiple Secret Keys Exposed in Production JS Bundle Production JS reveals multiple API secrets used in critical flows. CVSS 7.5 | African Fintech Expense Platform Africa | Credential Exposure | Responsible Disclosure | High | 2026-04 |
| Zoho OAuth Client Secret Exposed With Full API Scope Zoho OAuth client secret present in bundle with full scope enabling potential mailbox access. CVSS 7.5 | African Fintech Expense Platform Africa | Credential Exposure | Responsible Disclosure | High | 2026-04 |
| Mono Connect LIVE Keys Exposed (Banking Data Access) Mono Connect live keys leaked allowing widget impersonation and social-engineering tied to customer bank accounts. CVSS 7.5 | African Fintech Expense Platform Africa | API Key Exposure | Responsible Disclosure | High | 2026-04 |
| File Upload Extension Whitelist Bypass Potential Upload endpoints validate via allowlist matching but handle case/extension parsing unsafely. CVSS 7.5 | African Crypto Gift Card Platform Africa | File Upload | Responsible Disclosure | High | 2026-04 |
| Swagger-UI Exposed on 3 Domains Production Swagger UI exposed revealing full API contract. CVSS 7.5 | Gaming Marketplace SEA | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Admin Panel Source Map Exposed Billions.network admin panel ships source map revealing 96 API endpoints. CVSS 7.5 | Web3 Reputation Protocol Global | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Ngrok Dev URL Leak in Production + CORS Wildcard PocketBits production ships ngrok dev URL with CORS wildcard leak. CVSS 7.5 | Indian Crypto Exchange SEA | CORS | Responsible Disclosure | High | 2026-04 |
| Client Registration Credentials Present in Production JS Production JS embeds client registration credentials accepted by server (500 ISE, not 401). CVSS 7.5 | Indian Crypto Exchange SEA | Credential Exposure | Responsible Disclosure | High | 2026-04 |
| Admin Panel + Swagger API Docs + KYC Microservice Exposure Admin panel and Swagger for KYC microservice reachable publicly. CVSS 7.5 | Indian Crypto Exchange SEA | Admin Panel Exposure | Responsible Disclosure | High | 2026-04 |
| Swagger API Docs + Laravel Ignition Active in Production Laravel Ignition endpoint live with Swagger docs exposed in production environment. CVSS 7.5 | Indian Crypto Exchange SEA | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Uploadcare/Mono/Coinbase Pay API Keys Exposed Multiple payment and CDN keys bundled in frontend. CVSS 7.5 | African Crypto Infrastructure Africa | API Key Exposure | Responsible Disclosure | High | 2026-04 |
| Widget Bundle Source Map Exposure Public widget source map leaks integration patterns. CVSS 7.5 | African Crypto Infrastructure Africa | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Firebase Storage KYC Document Listing (7 KYC) flipex-app bucket allows unauthenticated listing of UAT/KYC_DOCUMENTS/ folder. CVSS 7.5 | African Crypto Trading Mobile App Africa | Firebase Misconfig | Responsible Disclosure | High | 2026-04 |
| Admin Panel Source Map Exposure (555 Files) admin.dtunes.ng exposes 1.4MB source map revealing 60+ admin API endpoints. CVSS 7.5 | African Digital Platform Africa | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| splitpay-app - Storage Open splitpay-app Firebase Storage allows anonymous reads. CVSS 7.5 | African Fintech Firebase Cohort Africa | Firebase Misconfig | Responsible Disclosure | High | 2026-04 |
| Metabase Setup-Token Leakage via /api/session/properties pricepally Metabase exposes setup-token + AWS EC2 IP via unauthenticated endpoint. CVSS 7.5 | African Fintech Metabase Cohort Africa | Credential Exposure | Responsible Disclosure | High | 2026-04 |
| Firestore Unauthenticated Access Firestore collections readable without auth due to default rules. CVSS 7.5 | African Investment Fintech Africa | Firebase Misconfig | Responsible Disclosure | High | 2026-04 |
| DMS Open Signup via Google OAuth ISO Document Management System accepts Google OAuth signup from any gmail account. CVSS 7.5 | African Investment Fintech Africa | Access Control | Responsible Disclosure | High | 2026-04 |
| Password Reset Token Brute Force No Rate Limit Password reset token brute-forceable with no throttle. CVSS 7.5 | African Payment Platform Africa | Rate Limit Bypass | Responsible Disclosure | High | 2026-04 |
| Paystack Live Key Exposed in Frontend pk_live Paystack key embedded in production bundle. CVSS 7.5 | African Pharma B2B Platform Africa | Credential Exposure | Responsible Disclosure | High | 2026-04 |
| Patient Medical Data Endpoints Discoverable /api/telimedicine/patient endpoint discoverable through debug route list. CVSS 7.5 | African Pharma B2B Platform Africa | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| OTC Subdomain CNAME Misconfiguration (Bubble.io) otc.cryptal.com points to Bubble.io without valid app; takeover feasible. CVSS 7.5 | European Crypto Exchange EU | Subdomain Takeover | Responsible Disclosure | High | 2026-04 |
| Shyft Mainnet RPC API Key Hardcoded config.ts exposes Shyft mainnet RPC key used for both RPC and sender URL. CVSS 7.5 | L1 Smart Contract Global | API Key Exposure | Responsible Disclosure | High | 2026-04 |
| Helius Mainnet RPC Key + DAS Enhanced API Key Helius RPC and DAS enhanced API key bundled in frontend; usable for 3 endpoints. CVSS 7.5 | L1 Smart Contract Global | API Key Exposure | Responsible Disclosure | High | 2026-04 |
| Aux00 Internal Django Dashboard Login Exposed aux00 internal Django dashboard reachable publicly with login form. CVSS 7.5 | LATAM Crypto Platform LATAM | Admin Panel Exposure | Responsible Disclosure | High | 2026-04 |
| Staging Exchange App + API Docs Public stg.notbank.exchange and stg.apidoc public with full staging schema. CVSS 7.5 | LATAM Crypto Platform LATAM | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Development API Publicly Accessible in Production api-test2 dev API and dev S3 bucket referenced in production bundle and reachable without auth. CVSS 7.5 | MENA Regulated Crypto Exchange MENA | Cloud Misconfig | Responsible Disclosure | High | 2026-04 |
| Zero Rate Limiting on All Authentication Endpoints Login, registration and 2FA endpoints have no rate limit enabling parallel brute force. CVSS 7.5 | European iGaming Platform EU | Rate Limit Bypass | Private Engagement | High | 2026-04 |
| Mass User PII Exposure (544 Users) via Admin Search User search API returns full 544-user list with PII including phone numbers without authorization. CVSS 7.5 | EU EdTech Platform EU | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Event Registration PII Mass Dump - 659 Records Event registration endpoint allows unauthenticated pagination through 659 attendee records with emails and phone numbers. CVSS 7.5 | EU EdTech Platform EU | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Full Source Code Exposure via Source Maps 540 application source files recoverable from production source maps revealing HMAC keys and flows. CVSS 7.5 | West African B2B Fintech Africa | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Unauthenticated Payment Token Generation Endpoint Payment token generation endpoint accessible without auth enabling unauthorized checkout session creation. CVSS 7.5 | West African B2B Fintech Africa | Access Control | Responsible Disclosure | High | 2026-04 |
| Admin Panel Source Code Exposure via Source Map Admin panel ships 364KB source map leaking 22 source files and admin flows. CVSS 7.5 | LATAM Crypto Platform LATAM | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Metabase Setup Token Exposed (bi.agrotoken) Third LATAM Metabase tenant exposes live setup token. CVSS 7.5 | LATAM Crypto Platform LATAM | Cloud Misconfig | Responsible Disclosure | High | 2026-04 |
| env.js/config.js Files Expose Internal Service Architecture Public config JS reveals internal service map and API keys. CVSS 7.5 | African Digital Bank Africa | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| HIGH - Auth Staging Source Map Exposure (5.7MB, 348 Files, Full Auth Logic) The staging authentication portal at auth-staging.[vendor] serves source maps containing complete TypeScript source code for the authentication system, including Cognito configuration, MFA flows, card security code validation, password reset logic, and embedded staging credentials CVSS 7.5 | European B2B Spend Management EU | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| GitLab Open Public Registration > NEW FINDING CVSS 7.5 | African SME Lender Africa | GraphQL Issues | Responsible Disclosure | High | 2026-04 |
| [vendor] Multi-Tenant Isolation Assessment Target: [vendor] (HashCash Consultants LLC) Scope: Cross-broker tenant isolation across 1,928 white-label broker instances CVSS 7.5 | Global Crypto Exchange Global | S3 Misconfig | Responsible Disclosure | High | 2026-04 |
| Move Pusher authentication to server-side only CVSS 7.5 | African Payment Gateway Africa | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| IdentityRadar Full Source Code Exposure via Source Map Vulnerable Endpoint: https://radar.[vendor]/static/js/main.ce51035c.js.map Size: 8,657,100 bytes (8.6 MB) / 1,268 source files / 173 application source files CVSS 7.5 | African Identity Verification Africa | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| WordPress Directory Listing Exposes 3,567+ Upload Files (HIGH) Finding 3: WordPress Directory Listing Exposes 3,567+ Upload Files (HIGH) Severity: High (CVSS 7.5 - AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) Summary: The WordPress blog at blog.[redacted].com has Apache directory listing enabled for the entire `/wp-content/uploads/` directory tree. Thi CVSS 7.5 | MENA Fintech MENA | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| OData Metadata & Internal Architecture Exposure (HIGH) Finding 3: OData Metadata & Internal Architecture Exposure (HIGH) The OData v4 metadata endpoints on both production and development API gateways are publicly accessible with only the subscription key (no bearer token required). These endpoints expose the complete database schema CVSS 7.5 | African Remittance Provider Africa | Cloud Misconfig | Responsible Disclosure | High | 2026-04 |
| Unauthenticated API Endpoints Expose Business Data (HIGH) Finding 4: Unauthenticated API Endpoints Expose Business Data (HIGH) Severity: High (CVSS 7.5 - AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) Summary: Multiple API v2 endpoints on both hiftigh.[redacted].com and [target] return business-critical data without any authentication, CVSS 7.5 | MENA Fintech MENA | IDOR | Responsible Disclosure | High | 2026-04 |
| (NEW): Complete Admin Console Architecture Leak via JavaScript Source Maps Finding 11 (NEW): Complete Admin Console Architecture Leak via JavaScript Source Maps Severity: HIGH (CVSS 7.5 - AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) The admin console at `console.[redacted].ng` exposes unobfuscated JavaScript bundles containing the complete admin API endpoint map CVSS 7.5 | Nigerian Payment Provider Africa | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Massive Source Map Exposure Across 3 Applications (HIGH) Finding 1: Massive Source Map Exposure Across 3 Applications (HIGH) - `https://app.[redacted].com/main.2ef2e977bb5dc9ba.js.map` (9.6 MB, 502 sources, 33 app files) - `https://admin.[redacted].com/main-P7MYWRXZ.js.map` (364 KB, 22 sources, 10 app files) - `https://ramp.manteca CVSS 7.5 | LATAM Crypto Platform LATAM | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Admin Login Approval Status IDOR -- Unauthenticated Monitoring (HIGH) Finding 2: Admin Login Approval Status IDOR -- Unauthenticated Monitoring (HIGH) Severity: High (CVSS 7.5 - AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) Summary: The endpoint `GET /login/check-approval/{id}` on hiftigh.[redacted].com returns the status of admin login approval requests witho CVSS 7.5 | MENA Fintech MENA | IDOR | Responsible Disclosure | High | 2026-04 |
| CORS Wildcard on v2 API v2-api.dtunes.ng returns ACAO:* which combined with AES key enables cross-origin session hijack. CVSS 7.4 | African Digital Platform Africa | CORS | Responsible Disclosure | High | 2026-04 |
| Google reCAPTCHA Secret Key Exposed in Frontend VITE_GOOGLE_RECAPTCHA_SECRET_KEY hardcoded in production SPA; bot-protection bypass. CVSS 7.4 | Crypto Payment Infrastructure Global | Credential Exposure | Responsible Disclosure | High | 2026-04 |
| OAuth Endpoints Operating Over HTTP OAuth authorization/token endpoints served over plain HTTP exposing tokens to network observers. CVSS 7.4 | EU EdTech Platform EU | Broken Authentication | Responsible Disclosure | High | 2026-04 |
| Amplitude API Write Access Enables Event Injection Amplitude API key with write permissions leaked permits injection of arbitrary analytics events to poison user profiles. CVSS 7.3 | European iGaming Platform EU | API Key Exposure | Private Engagement | High | 2026-04 |
| n8n Workflow Automation Platform Publicly Accessible n8n workflow platform reachable without auth allowing workflow inspection and webhook trigger abuse. CVSS 7.3 | African Digital Bank Africa | Admin Panel Exposure | Responsible Disclosure | High | 2026-04 |
| Admin Panel Publicly Accessible with Dev Tools Enabled (HIGH) Finding 2: Admin Panel Publicly Accessible with Dev Tools Enabled (HIGH) Affected Component: `https://admin.[redacted].com` Summary: The Manteca admin panel (admin.[redacted].com) is publicly accessible without any network-level restriction. The admin panel includes developme CVSS 7.3 | LATAM Crypto Platform LATAM | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Seven Internal Microservice APIs Exposed on Public Internet Backend microservices intended for internal VPC are reachable publicly with minimal auth, expanding attack surface. CVSS 7.2 | European Payment Gateway EU | Admin Panel Exposure | Responsible Disclosure | High | 2026-04 |
| Demo Environment Open Signup With Full Banking Access Demo ourSpell instance allows open registration with full ecommerce/banking admin, leaking product architecture. CVSS 7.2 | European Payment Gateway EU | Admin Panel Exposure | Responsible Disclosure | High | 2026-04 |
| TWA JavaScript Bridge Launches Arbitrary URLs Inside Auth Context TWA JS bridge exposes openUrl method without allowlist, usable by embedded ads or nested iframes. CVSS 7.2 | Indian Investment Broker SEA | Deeplink Hijacking | Responsible Disclosure | High | 2026-04 |
| Django Admin Panel Exposed on Production API Vulnerable Endpoint: https://api.[vendor]/admin/login/ Server: CPython/3.10.20, WSGIServer/0.2, Django (latest dark_mode CSS) CVSS 7.2 | African Identity Verification Africa | Admin Panel Exposure | Responsible Disclosure | High | 2026-04 |
| No Rate Limiting on Authentication Endpoints Enables Brute Force Login, reset, and verification endpoints have no throttle enabling password/OTP brute force and credential stuffing. CVSS 7.1 | European Payment Gateway EU | Rate Limit Bypass | Responsible Disclosure | High | 2026-04 |
| Staging Environment dev.* Exposed to Internet Staging host is publicly reachable exposing pre-release vulnerabilities to attackers. CVSS 7.1 | European iGaming Platform EU | Information Disclosure | Private Engagement | High | 2026-04 |
| Hardcoded X-PrivateKey smartapi_zRzIJ3bN Used Across API Calls Static privateKey identifier leaked enables signature replay against SmartAPI trading endpoints. CVSS 7.0 | Indian Investment Broker SEA | API Key Exposure | Responsible Disclosure | High | 2026-04 |
| Cleartext Traffic Allowed to Market Data Servers in APK Network security config allows cleartext HTTP to market-data hosts enabling MITM on hostile networks. CVSS 7.0 | Indian Investment Broker SEA | Broken Authentication | Responsible Disclosure | High | 2026-04 |
| Complete APK Environment Configuration Files Exposed flows.json and env configs bundled in APK enumerate 50+ KYC and payment endpoints per environment. CVSS 7.0 | Indian Investment Broker SEA | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Generic WebView Fragments Trust Raw Argument URLs Multiple WebView fragments accept arg-supplied URL without origin check, enabling phishing inside authenticated app. CVSS 7.0 | Indian Investment Broker SEA | Deeplink Hijacking | Responsible Disclosure | High | 2026-04 |
| JWT Cookie Security Completely Disabled Session JWT cookie lacks HttpOnly, Secure, SameSite, allowing XSS-based theft and replay. CVSS 7.0 | Indian Crypto Exchange SEA | Broken Authentication | Responsible Disclosure | High | 2026-04 |
| OTC API Accepts Hardcoded localhost:3003 as CORS Origin Hardcoded dev origin allowed with credentials lets attackers host malicious page on attacker-controlled localhost binding. CVSS 7.0 | Indian Crypto Exchange SEA | CORS | Responsible Disclosure | High | 2026-04 |
| CodeIgniter 3.1.0 Backend Exposed with User Guide Online EOL CodeIgniter backend exposes default pages and user guide identifying CVE-vulnerable version. CVSS 7.0 | Indian Crypto Exchange SEA | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Unprotected API Backend Without WAF or CDN Public API origin reachable directly with Apache/Ubuntu banner and no rate limiting. CVSS 7.0 | EU Crypto ATM Operator EU | Cloud Misconfig | Responsible Disclosure | High | 2026-04 |
| Self-Hosted Sentry Event Injection (Exchange) Self-hosted Sentry DSN accepts unauth events enabling log pollution. CVSS 7.0 | European Crypto Exchange EU | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Braze SDK API Key and Multiple Third-Party Credentials Exposed Braze and other analytics keys in JS allow impersonating the app to push notifications and read analytics. CVSS 7.0 | European Crypto Exchange EU | API Key Exposure | Responsible Disclosure | High | 2026-04 |
| Unauthenticated Username Enumeration via Public API Differential responses on username lookup expose account existence feeding password spraying. CVSS 7.0 | African Fintech Neobank Africa | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Debug Mode Enabled on Production API Endpoints Debug flag leaks verbose SQL errors and stack traces in production. CVSS 7.0 | African Crypto Gift Card Platform Africa | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| WooCommerce Plugin Callback Missing Signature Verification + SSL Off Official WooCommerce payment plugin skips callback signature validation and ships with SSL verification disabled. CVSS 6.5 | European Payment Gateway EU | Webhook Forgery | Responsible Disclosure | High | 2026-04 |
| Metabase v0.57.3 Public + Google OAuth Config Exposed metabase.eversend.co exposes Google OAuth client ID and version enabling targeted attacks. CVSS 6.5 | African Neobank Africa | Admin Panel Exposure | Responsible Disclosure | High | 2026-04 |
| Keycloak 25+ Public Configuration Exposure auth subdomain exposes Keycloak realms and internal configuration. CVSS 6.5 | European Crypto Exchange EU | Information Disclosure | Responsible Disclosure | High | 2026-04 |
| Sentry DSN + Event Injection Production Project Sentry DSN hardcoded and accepts forged events into production project. CVSS 6.5 | MENA Regulated Crypto Exchange MENA | Credential Exposure | Responsible Disclosure | High | 2026-04 |
| Admin Account Takeover via OTP Brute Force Finding 6: Admin Account Takeover via OTP Brute Force The OTP verification endpoints accept unlimited attempts without rate limiting or account lockout. Combined with Finding 3 (unauthenticated device token) and Finding 7 (email enumeration), an attacker can complete a full admin CVSS 8.8 | Nigerian Payment Provider Africa | Rate Limit Bypass | Responsible Disclosure | High | 2026-03 |
| CORS Origin Reflection + Credentials on Server Management Panel (CRITICAL) Finding 1: CORS Origin Reflection + Credentials on Server Management Panel (CRITICAL) CRITICAL (CVSS 8.8) — AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H platform.[redacted].com üzerindeki Tenantos server management paneli, gelen HER Origin header'ını `Access-Control-Allow-Origin` response h CVSS 8.8 | Web Hosting Provider EU | Credential Exposure | Responsible Disclosure | High | 2026-03 |
| CRITICAL - CORS Wildcard + Credentials:true business-banking.[vendor] API'si tum endpointlerinde Access-Control-Allow-Origin: ve Access-Control-Allow-Credentials: true header'larini birlikte dondurmektedir CVSS 8.7 | African Payment Processor Africa | CORS | Responsible Disclosure | High | 2026-03 |
| Google 2FA TOTP Secret Exposed in Plaintext via Profile API When a user enables Google Authenticator 2FA, their TOTP secret key is stored on the server. The problem is that this secret is returned in the API response when fetching the user's profile. Anyone with access to the user's token can read this secret, generate valid 2FA codes, and disable 2FA entirely CVSS 8.7 | Crypto Gaming Platform Global | Business Logic | Responsible Disclosure | High | 2026-03 |
| Swap Limit Order No OTP -- Funds Locked Without Verification Swap Limit Order No OTP -- Funds Locked Without Verification CVSS 8.7 | Crypto Gaming Platform Global | Credential Exposure | Responsible Disclosure | High | 2026-03 |
| SQL Injection on LIMIT Clause of Trade Endpoint Trade endpoint appends user-controlled LIMIT clause parameter allowing time-based SQLi. CVSS 8.6 | Indian Crypto Exchange SEA | SQLi | Responsible Disclosure | High | 2026-03 |
| SSRF IP Format Bypass - No SSRF Filter No SSRF filter exists; IP format variations all bypass. CVSS 8.6 | EU Gaming Marketplace EU | SSRF | Responsible Disclosure | High | 2026-03 |
| Telefon numarasi ekrani curl -s -o phone_number.jpg "https://firebasestorage.googleapis.com/v0/b/business-banking-93cc1.appspot.com/o/account-details%2F1749634011035.png?alt=media" CVSS 8.6 | African Payment Processor Africa | Firebase Misconfig | Responsible Disclosure | High | 2026-03 |
| DeveloperExceptionPage Enabled in Production (redeem-cards.com) ASP.NET Core DeveloperExceptionPageMiddleware is enabled in production. Every unhandled exception returns complete .NET stack traces with source file paths, line numbers, method signatures, the entire middleware pipeline, all HTTP request headers (including real IPs), and internal application architecture CVSS 8.6 | EU Gaming Key Marketplace EU | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Unauthenticated Debug Endpoint Leaks Internal Service Configuration The debug endpoint returns the complete request/response object of a server-side HTTP call to redeem-cards.com, exposing internal service credentials (UserType: [vendor]Bot), admin names (emre), the internal API URL, and server-to-server communication patterns -- all without authentication CVSS 8.6 | EU Gaming Key Marketplace EU | Credential Exposure | Responsible Disclosure | High | 2026-03 |
| Sandbox Horizon Dashboard Unauthenticated === Subdomains (21 via crt.sh) === www.[vendor] - 200 - Laravel + Livewire + Alpine.js (PRODUCTION) api.[vendor] - 403 - API Gateway (Cloudflare protected, IP restricted) sandbox.[vendor] - 200 - Laravel (DEBUG ON, HORIZON OPEN) document.[vendor] - 200 - Postman Documenter (API docs) cdn.[vendor] - 403 - CDN (Cloudf CVSS 8.6 | EU Digital Goods Marketplace EU | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| PostgreSQL Database Information Disclosure Endpoint: https://sandbox.[vendor]/api/v2/publishers CVSS 8.6 | EU Digital Goods Marketplace EU | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Email Enumeration via Password Reset /v2/auth/password-reset/start endpoint'i, verilen e-posta adresinin sistemde kayitli olup olmadigini acikca belirten hata mesajlari dondurmektedir. Rate limit sadece 5 request/window oldugu icin sinirli, ancak birden fazla IP kullanilarak veya X-Forwarded-For manipulasyonu ile bypass edilebilir CVSS 8.6 | African Crypto Exchange Africa | Broken Authentication | Responsible Disclosure | High | 2026-03 |
| (CRITICAL): Internal API Documentation Leaks Production Partner API Architecture The ReadMe-hosted API documentation at documentation.[vendor] exposes the complete Partner API architecture including 42+ endpoints, internal test URLs ([vendor].test:8010), a Postman workspace ID, and internal subdomain (kdhyuobbnv.[vendor].com). Combined with Finding 1, this provides a complete attack map CVSS 8.6 | African Crypto Exchange Africa | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| CRITICAL -- Unauthenticated Order Status IDOR -- 6.2M+ Sipariste Mass Enumeration ve Real-Time Cart Monitoring /ajax/get-order-status endpoint'i herhangi bir authentication veya authorization kontrolu olmadan, herhangi bir order_id icin siparis durumunu (status, refund_status) dondurur. ~6,210,000+ siparis numarasi enumerate edilebilir. 5 farkli status tipi ifsa edilmektedir: completed, expired, in_cart, sent, apply_refund. Real-time in_cart status izlem CVSS 8.6 | Gaming Marketplace Global | IDOR | HackerOne | High | 2026-03 |
| Game Tools API Mass Data Exfiltration -- 724 Business Records via IDOR Deep analysis of the Game Tools Backend API (app-gametools-api-proc.azurewebsites.net) reveals that 5 distinct data endpoints are completely unauthenticated and IDOR-vulnerable, exposing a total of 724+ business records including [vendor]' complete pricing algorithm parameters (value multipliers per game feature), monthly Average Order Val CVSS 8.6 | Gaming Marketplace NA | IDOR | Responsible Disclosure | High | 2026-03 |
| Strapi CMS Open Registration with JWT Issuance Vulnerable Endpoint: https://strapi.[vendor]/api/auth/local/register CVSS 8.6 | EU Gaming Marketplace EU | JWT Issues | Responsible Disclosure | High | 2026-03 |
| Moonbase Admin Panel Source Code Exposure via CF Access Bypass Moonbase Internal Admin Panel (4.5MB JavaScript) Exposed Without Authentication via [vendor] — Full Backoffice Architecture, 8 Admin Emails, 9 Internal API URLs, 200+ Admin Routes, Gorra Fraud System Config CVSS 8.6 | LATAM Crypto Platform LATAM | Admin Panel Exposure | HackerOne | High | 2026-03 |
| K-2: Vite Development Server Exposed in Production (CRITICAL) Finding K-2: Vite Development Server Exposed in Production (CRITICAL) Endpoint: `https://integrator.[redacted].com/` Summary: A Vite development server is running in production, exposing the complete application source code including TypeScript files, configuration, package.json, CVSS 8.6 | African Neobank Africa | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Docker Registry Unauthenticated Full Catalog Access Public Docker registry lists 29 repositories including google/cloud-sdk and golang with all tags. CVSS 8.5 | SEA Banking API Platform SEA | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| Partner API Full Account Management via Public NPM Package Public NPM package documents partner API including signing scheme and endpoints. CVSS 8.5 | Indian Crypto Exchange SEA | Credential Exposure | Responsible Disclosure | High | 2026-03 |
| Subdomain Takeover on bello Marketing Subdomain (Railway Dangling) Abandoned Railway deployment leaves CNAME dangling, permitting takeover to serve attacker content under bitafrika brand. CVSS 8.2 | African Crypto Exchange Africa | Subdomain Takeover | Responsible Disclosure | High | 2026-03 |
| Source Map Exposure 71MB with AWS Keys + Payment Keys 71MB of production source code served publicly including AWS credentials and payment keys. CVSS 8.2 | African KYC/Identity Provider Africa | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| HashiCorp Vault Leaks Internal K8s Infrastructure and OIDC Vault unauthenticated endpoints leak OIDC role names, Google OAuth client and root generation status. CVSS 8.2 | LATAM Crypto Exchange LATAM | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| HashiCorp Vault Unsealed and Publicly Accessible Production Vault instance is unsealed and reachable over internet exposing secret management surface. CVSS 8.2 | African Gift Card Platform Africa | Cloud Misconfig | Responsible Disclosure | High | 2026-03 |
| CORS Subdomain Wildcard Trust With Credentials on All Services Production services accept any *.brankas.com origin with credentials, enabling subdomain-takeover to ATO chain. CVSS 8.1 | SEA Banking API Platform SEA | CORS | Responsible Disclosure | High | 2026-03 |
| SQL Injection on Page Param + Stored Procedure Discovery Page parameter allows stored-procedure enumeration via injection. CVSS 8.1 | Indian Crypto Exchange SEA | SQLi | Responsible Disclosure | High | 2026-03 |
| Wildcard DNS + CORS Reflection Enhances Phishing-to-ATO Wildcard DNS resolves every subdomain to single IP, combined with permissive CORS chains into ATO. CVSS 8.1 | African Fintech Remittance Africa | Subdomain Takeover | Responsible Disclosure | High | 2026-03 |
| Race Condition in Financial Operations Parallel Wallet/Withdraw requests processed concurrently without mutex enabling double-spend. CVSS 8.1 | African Crypto Trading Platform Africa | Race Condition | Responsible Disclosure | High | 2026-03 |
| Webhook Trigger Forgery on Any Verification /send-webhook triggers customer webhooks for arbitrary verifications including completed ones. CVSS 8.1 | African KYC/Identity Provider Africa | Webhook Forgery | Responsible Disclosure | High | 2026-03 |
| CNPS Production API Client Auth Bypass Hardcoded client credentials on CNPS production API enable authenticated API access. CVSS 8.1 | Central African Crypto Fintech Africa | Auth Bypass | Responsible Disclosure | High | 2026-03 |
| Hetzner Cloud Metadata Reachable via Vault Misconfig Hetzner metadata endpoint accessible; Vault direct IP with misconfigured listener. CVSS 8.1 | Central African Crypto Fintech Africa | Cloud Misconfig | Responsible Disclosure | High | 2026-03 |
| 16 Guest Order Endpoints with Zero Authentication 16 guest endpoints enable order takeover, credential theft, dispute fraud. CVSS 8.1 | Gaming Marketplace EU | Access Control | Responsible Disclosure | High | 2026-03 |
| Race Condition Parallel Primer Tokens (No Mutex) 10/10 parallel Primer production tokens issued in <1s; discountPercent:100 accepted. CVSS 8.1 | Gaming Marketplace EU | Race Condition | Responsible Disclosure | High | 2026-03 |
| Push Notification Send to All Users via Firebase Firebase Cloud Messaging endpoint blocked only by missing credential file; otherwise sends to all users. CVSS 8.1 | Indian Crypto Exchange SEA | Firebase Misconfig | Responsible Disclosure | High | 2026-03 |
| 86 Public Pusher Trade Channels Front-Running 86 public trade channels subscribable unauthenticated enabling front-running. CVSS 8.1 | Indian Crypto Exchange SEA | Business Logic | Responsible Disclosure | High | 2026-03 |
| Strapi CORS Wildcard Origin Reflection with Credentials Vulnerable Endpoint: https://strapi.[vendor]/ (all endpoints) CVSS 8.1 | EU Gaming Marketplace EU | CORS | Responsible Disclosure | High | 2026-03 |
| currency-api.[vendor] CORS Wildcard with Credentials The currency-api.[vendor] endpoint returns Access-Control-Allow-Origin: combined with Access-Control-Allow-Credentials: true. While browsers technically ignore credentials with wildcard origin, the misconfiguration signals a deeper CORS issue. The preflight response also allows Authorization header, meaning authenticated API calls from any o CVSS 8.1 | African Remittance Platform Africa | CORS | Responsible Disclosure | High | 2026-03 |
| CORS Wildcard on 23+ Authenticated User/Order Endpoints with DELETE Method Allowed The SLS API at sls.[vendor] exposes 23+ authenticated user and order management endpoints behind a CORS wildcard () policy that also allows the DELETE HTTP method and accepts Authorization/X-Api-Key headers. While Access-Control-Allow-Credentials is not set (preventing cookie-based CSRF), the API uses Bearer token or API key authentication CVSS 8.1 | SEA Gaming Marketplace SEA | CORS | HackerOne | High | 2026-03 |
| Dev Access Token Backdoor in Source Code Source map reveals static dev token that is still validated server-side, granting privileged access. CVSS 8.0 | SEA Banking API Platform SEA | Auth Bypass | Responsible Disclosure | High | 2026-03 |
| Payment Webhook Signature Scheme Fully Disclosed Signature construction detailed in NPM doc allowing webhook forgery. CVSS 8.0 | Indian Crypto Exchange SEA | Webhook Forgery | Responsible Disclosure | High | 2026-03 |
| DigitalOcean Spaces Production Credentials Exposed (Changera) Production DO Spaces access key and secret present in bundle. CVSS 8.0 | African Fintech Remittance Africa | Credential Exposure | Responsible Disclosure | High | 2026-03 |
| Risevest Admin Panel with KYC Management Exposed Risevest admin panel reachable revealing KYC workflow and user management. CVSS 8.0 | African Investment Platform Africa | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| Defguard VPN Panel Exposed 10+ Vulnerabilities (v1.3.1) Defguard VPN v1.3.1 reachable publicly with 10+ known issues including open redirect and enum. CVSS 8.0 | African Fintech Remittance Africa | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| Lokalise API Full Access - Translation Manipulation Exposed Lokalise API token permits editing live translations across brand storefront. CVSS 8.0 | Saudi Gaming Marketplace MENA | API Key Exposure | Responsible Disclosure | High | 2026-03 |
| vpn.[redacted].com - Admin Panel Source Map + Hardcoded Secret [HIGH] Finding 1: vpn.[redacted].com - Admin Panel Source Map + Hardcoded Secret [HIGH] `vpn.[redacted].com` serves a full [redacted] Admin Panel (titled "[redacted] Admin" in HTML, `webpackJsonpvpn-governance`). Two source map files are publicly accessible, exposing the complete fronte CVSS 7.8 | SEA Fintech SEA | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| HIGH - Sub-Merchant PII Disclosure via listSubMerchantPF (VKN/TCKN/Address) Finding 52: HIGH - Sub-Merchant PII Disclosure via listSubMerchantPF (VKN/TCKN/Address) Severity: High (CVSS 7.5 - AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) Summary: `/ccpayment/api/listSubMerchantPF` endpoint'i, TUM alt-uye isyeri PF kayitlarini VKN (Vergi Kimlik Numarasi), TCKN (TC CVSS 7.8 | Turkish Payment Gateway MENA | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| [redacted] SSRF Applepay Apple Pay Web entegrasyonunda, merchant validation islemi icin browser tarafindan saglanan `validationURL` parametresi sunucuya gonderilir ve sunucu bu URL'ye POST istegi yapar. Normalde bu URL yalnizca `[target]` domain'lerine izin vermeli, ancak [redacted]'in imp CVSS 7.8 | African Payment Gateway Africa | SSRF | Responsible Disclosure | High | 2026-03 |
| [HIGH] - Public API Documentation on [target] Finding 5 [HIGH] - Public API Documentation on [target] Vulnerable Endpoint: `https://[target]` Summary: The full API reference documentation (Slate-generated) for the [redacted]/TCDX platform is publicly accessible on Alibaba Cloud OSS. The documentation d[redacted] CVSS 7.8 | SEA Crypto Exchange SEA | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| [HIGH] - [redacted] DSN Exposed + Event Injection Verified Finding 6 [HIGH] - [redacted] DSN Exposed + Event Injection Verified Summary: The [redacted] DSN is exposed in the compiled JavaScript and accepts arbitrary event injection from any origin. DSN: `https://2f87dbe19e8c72da1531842a99ad4a9f@[target].[redacted].io/4509219002122240` - In CVSS 7.8 | DeFi Lending/DEX Protocol Global | XSS | Responsible Disclosure | High | 2026-03 |
| — 30+ Production Microservices Publicly Accessible Finding 2 — 30+ Production Microservices Publicly Accessible CVSS: 6.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:N) 30+ production microservices handling KYC, AML, identity verification, billing, and transaction monitoring are directly accessible from the public internet withou CVSS 7.8 | African KYC Provider Africa | Auth Bypass | Responsible Disclosure | High | 2026-03 |
| Payment API Endpoints Accessible Without Authentication (HIGH) Finding 5: Payment API Endpoints Accessible Without Authentication (HIGH) The payment service API exposes sensitive endpoints including order management, refund processing, and balance queries. While a signature is required, the signing key is already exposed (Finding 2). Accessi CVSS 7.8 | Gaming Marketplace SEA | Access Control | Responsible Disclosure | High | 2026-03 |
| Mass Scan Lethal Mass Scan — Lethal Findings Summary Total Lethal Findings (6 categories): 0 Only these 6 finding types were searched: 1. Database access (MongoDB, MySQL, PostgreSQL, Redis, MSSQL, CouchDB) CVSS 7.8 | Mass Scan Global | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| env.js Production Configuration Leak [HIGH] Finding 3: env.js Production Configuration Leak [HIGH] - URL: `https://[target]/env.js` - Mixpanel token: `7f5f8bc7493a36e52f8b7218315ef5ca` - Flagsmith API key: `GPa6tcN2oZc4VbHzEPC5Yz` CVSS 7.8 | Crypto Fintech Mass Scan Global | Firebase Misconfig | Responsible Disclosure | High | 2026-03 |
| [redacted] Wr841N Pentest - `Secure` flag YOK (HTTP uzerinden iletilebilir) - `SameSite` attribute YOK (CSRF'e acik) 1. Ayni WiFi aginda ARP spoofing veya WiFi monitoring 2. HTTP traffic'i yakala (Wireshark/tcpdump) CVSS 7.8 | CCTV Infrastructure Global | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Realtime XSS Mass Scan Realtime Channel XSS Mass Scan Results Objective: Find crypto/fintech platforms where ALL users listen on a SINGLE realtime channel, and we can INJECT XSS via that channel ([target] pattern) Method: Passive JS bundle analysis, source map extraction, Pusher/Ably/[target] ch CVSS 7.8 | Mass XSS Scan Global | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| GrowthBook Base URL Override ([redacted]_CODE_GB_BASE_URL) Finding 4: GrowthBook Base URL Override ([redacted]_CODE_GB_BASE_URL) Severity: Medium-High (CVSS 6.5) Summary: The `[redacted]_CODE_GB_BASE_URL` environment variable allows overriding the GrowthBook feature flag service URL. This enables a man-in-the-middle or local proxy to serve arbit CVSS 7.8 | AI SaaS Provider NA | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| dashboard.[redacted].com - Dashboard Source Map Exposure [HIGH] Finding 3: dashboard.[redacted].com - Dashboard Source Map Exposure [HIGH] `dashboard.[redacted].com` is [redacted]'s client-facing dashboard for open banking operations. The source map exposes 591 source files with complete business logic for banking operations across Indonesia, Philippi CVSS 7.8 | SEA Fintech SEA | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| HIGH - CORS Wildcard on ALL 4 IMT Backend APIs (367 Endpoints Affected) Finding 36: HIGH - CORS Wildcard on ALL 4 IMT Backend APIs (367 Endpoints Affected) Severity: High (CVSS 7.4 - AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N) Summary: 4 IMT backend API'nin TAMAMI `Access-Control-Allow-Origin: ` ve `Access-Control-Expose-Headers: ` ile yapilandirilmistir. B CVSS 7.8 | Turkish Payment Gateway MENA | CORS | Responsible Disclosure | High | 2026-03 |
| Orm Injection Deep Exploitation ORM Injection Deep Exploitation Report — [redacted].az Status: VERIFIED — Full password hash extraction demonstrated on production The `/tickets` endpoint on `api.[redacted].az` accepts arbitrary Dynamic LINQ expressions via the `SortField` parameter without authentication. Through a CVSS 7.8 | EU iGaming Operator EU | SQLi | Responsible Disclosure | High | 2026-03 |
| [HIGH] - Admin Dashboard Full Source Code Exposure via Source Maps Finding 1 [HIGH] - Admin Dashboard Full Source Code Exposure via Source Maps Summary: The admin dashboard at admin.[redacted].finance exposes JavaScript source maps containing the complete admin panel source code (171 files, 14.6MB total). This reveals all admin API endpoints, authenti CVSS 7.8 | DeFi Lending/DEX Protocol Global | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| — CORS Origin Reflection on 24+ Microservices (DEV + PRODUCTION) Finding 1 — CORS Origin Reflection on 24+ Microservices (DEV + PRODUCTION) CVSS: 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N) 24 microservices across both development AND production environments reflect arbitrary Origin headers in their Access-Control-Allow-Origin response, CVSS 7.8 | African KYC Provider Africa | CORS | Responsible Disclosure | High | 2026-03 |
| Firebase Storage PUBLIC Listing [HIGH] Finding 2: Firebase Storage PUBLIC Listing [HIGH] - URL: `https://[target]/v0/b/[target]/o` - Impact: 998 files publicly listed (mostly bank logos/icons but includes .DS_Store) - POC: `curl -s "https://[target] CVSS 7.8 | Crypto Fintech Mass Scan Global | Firebase Misconfig | Responsible Disclosure | High | 2026-03 |
| New Platforms Scan New Crypto/Fintech Platforms Scan - 2026-03-26 Scan Summary (Round 2 - Crypto Exchanges + African Crypto) Platforms scanned: 30 NEW targets Platforms with critical findings: 1 (coinnest.africa - FULL COMPROMISE) CVSS 7.8 | Mixed Platforms Global | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| HIGH - ACL Email Enumeration via Login + Forgot Password Differential Response Finding 34: HIGH - ACL Email Enumeration via Login + Forgot Password Differential Response Severity: High (CVSS 7.5 - AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) Summary: imt-acl.[redacted].[target] uzerindeki `/login` ve `/forgot-password` endpoint'leri, var olan ve var olmayan email adresler CVSS 7.8 | Turkish Payment Gateway MENA | RCE | Responsible Disclosure | High | 2026-03 |
| [HIGH] - VPN Admin Brute Force: 5 Valid Employee Emails + Zero Rate Limit Finding 28 [HIGH] - VPN Admin Brute Force: 5 Valid Employee Emails + Zero Rate Limit Summary: [target]/admin/auth endpoint'inde email enumeration ile 5 gecerli VPN admin hesabi tespit edildi. WordPress kullanici bilgileriyle cross-reference yapilarak 2 yeni hesap kesfedild CVSS 7.8 | SEA Crypto Exchange SEA | Rate Limit Bypass | Responsible Disclosure | High | 2026-03 |
| EMA/Spot Price Divergence Excess Collateral Seizure in Lending Liquidation Liquidation eligibility uses EMA price but collateral seizure uses spot price with no tolerance check, enabling liquidators to extract excess collateral during price divergence. CVSS 7.5 | Sui L1 Lending Protocol Global | Oracle Manipulation | Sherlock | High | 2026-03 |
| Rate Limiter DoS via Cross-Segment Outflow Reduction Ineffectiveness reduce_outflow only adjusts the current segment, so repay in a later segment leaves the limiter saturated, blocking borrows and withdrawals. CVSS 7.5 | Sui L1 Lending Protocol Global | Business Logic | Sherlock | High | 2026-03 |
| Bridge Fee Quoted From User-Supplied Slippage Minimum Router quotes bridge fee using attacker-controlled minTrustOut but bridges post-swap amountOut, causing underpaid fees or reverts. CVSS 7.5 | Ethereum Attestation Protocol Global | Business Logic | Code4rena | High | 2026-03 |
| Legal Documents Bucket Public Listing With 22 User UUIDs Second bucket exposes 75+ objects and 22 user UUIDs enabling targeted PII correlation. CVSS 7.5 | African Crypto Exchange Africa | S3 Misconfig | Responsible Disclosure | High | 2026-03 |
| Full Source Code + .git Repository Exposure on Static Site Static site serves Express.js source and .git config revealing developer GitHub URL and root-process runtime. CVSS 7.5 | African Crypto Exchange Africa | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Mass User Enumeration Reveals 232,800+ User Profiles Unauth trader lookup reveals KYC country vs profile country mismatches and sequential user IDs. CVSS 7.5 | Global P2P Crypto Marketplace Global | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Vite Manifest + Source Map Exposure 299 Vue Components manifest.json downloads reveal 299 Vue component entries and SPA routing table. CVSS 7.5 | Global P2P Crypto Marketplace Global | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| ArgoCD v2.14.8 Settings Leak with execEnabled:true ArgoCD settings endpoint exposes execEnabled true and cluster overrides enabling pod exec potential. CVSS 7.5 | SEA Banking API Platform SEA | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| Source Map Exposure 10 Products 782.5 MB 748 Maps Ten product frontends serve source maps totaling 782.5MB revealing API logic and internal endpoints. CVSS 7.5 | SEA Banking API Platform SEA | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Public GCS Buckets: 6 of 17 Anonymously Listable Six GCS buckets allow anonymous object listing including transaction artifacts. CVSS 7.5 | SEA Banking API Platform SEA | Cloud Misconfig | Responsible Disclosure | High | 2026-03 |
| Complete Admin Panel API Architecture Exposed (65+ Endpoints) Admin JS bundle enumerates 65+ backend endpoints with parameter templates. CVSS 7.5 | African Fintech Neobank Africa | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Source Map Exposure on 3 Staging Apps (944 Source Files) Three staging apps ship maps with 944 source files revealing auth flow and secrets. CVSS 7.5 | African Crypto Exchange Africa | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Intercom Identity Verification HMAC Secret Exposed Intercom HMAC secret allows attacker to generate valid identity hashes for any user ID. CVSS 7.5 | African Crypto Exchange Africa | Credential Exposure | Responsible Disclosure | High | 2026-03 |
| Metabase v0.57.7.2 Setup Token + API Docs + Reset Oracle Metabase exposes setup token, 303-endpoint docs, password reset oracle and weak password validator without auth. CVSS 7.5 | African Crypto Exchange Africa | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| Intercom Identity Verification HMAC Secret Exposed (Bitmama) Intercom HMAC secret allows generating identity hashes for any user_id. CVSS 7.5 | African Crypto Exchange Africa | Credential Exposure | Responsible Disclosure | High | 2026-03 |
| Full Application Source Code Exposure via Source Maps (Bitmama) Dashboard + admin total 1081 source files (36MB) exposed publicly. CVSS 7.5 | African Crypto Exchange Africa | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Six API Keys/Secrets Hardcoded in Production JavaScript Production bundle contains six vendor API keys including real-time messaging and analytics. CVSS 7.5 | African Crypto Exchange Africa | API Key Exposure | Responsible Disclosure | High | 2026-03 |
| RabbitMQ Management Console Exposed to Internet Production RabbitMQ Management UI reachable publicly. CVSS 7.5 | African Crypto Exchange Africa | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| Soketi Self-Hosted Pusher Key Exposed + Real-Time Message Interception Base64 Pusher key discoverable publicly allowing real-time channel subscription. CVSS 7.5 | African Crypto Exchange Africa | WebSocket Issues | Responsible Disclosure | High | 2026-03 |
| 23MB Source Map Application Code Exposure (2752 Files) Single app build ships 23MB source map exposing 2752 source files. CVSS 7.5 | African Crypto Exchange Africa | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| wsorder.bitbns.com CORS Origin Reflection on Trade Engine Trade engine reflects arbitrary origin with credentials on WebSocket handshake. CVSS 7.5 | Indian Crypto Exchange SEA | CORS | Responsible Disclosure | High | 2026-03 |
| AES Encryption Secret Key Exposed (Client-Side Crypto Broken) Single static AES secret used for client-side request encryption disclosed in JS. CVSS 7.5 | African Fintech Remittance Africa | Credential Exposure | Responsible Disclosure | High | 2026-03 |
| Roqqu KYC System Source Map Exposure KYC system source map downloadable exposing verification routes. CVSS 7.5 | African Crypto Exchange Africa | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Dojah.io Full Application Source Code via Source Maps Dojah KYC provider ships source maps revealing internal verification logic. CVSS 7.5 | African KYC Provider Africa | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Unauthenticated Platform Settings Dump (36 Anomaly Thresholds) Settings endpoint exposes 36 risk thresholds unauth, enabling fraud-rule evasion. CVSS 7.5 | African Fintech Remittance Africa | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| 3 Admin Source Maps Publicly Accessible (17.9MB Source) Three admin bundles ship source maps totaling 17.9MB. CVSS 7.5 | African Fintech Remittance Africa | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| SonarQube v10.6.0 Exposed with CVE-2024-47004 SonarQube version vulnerable to CVE-2024-47004 reachable publicly. CVSS 7.5 | African Fintech Remittance Africa | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| Swagger UI Publicly Accessible on API Subdomain api.coincola.com exposes Swagger UI enumerating all routes. CVSS 7.5 | Global P2P Crypto Marketplace Global | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Advertisement IDOR Reveals 170K Ads Without Auth Sequential ad enumeration dumps ~170,000 advertisements including counterparty profile fragments. CVSS 7.5 | Global P2P Crypto Marketplace Global | IDOR | Responsible Disclosure | High | 2026-03 |
| S3 Bucket coincola.user Exposed Named user bucket discovered with public metadata reachable. CVSS 7.5 | Global P2P Crypto Marketplace Global | S3 Misconfig | Responsible Disclosure | High | 2026-03 |
| Alibaba Cloud OSS Bucket PUBLIC READ Confirmed NoSuchKey (vs AccessDenied) response confirms bucket ACL permits public object read. CVSS 7.5 | Global P2P Crypto Marketplace Global | Cloud Misconfig | Responsible Disclosure | High | 2026-03 |
| Wazuh SIEM Dashboard Public Wazuh guards.obiex.finance reachable publicly exposing security telemetry. CVSS 7.5 | African Fintech Crypto Exchange Africa | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| MinIO Bucket Enumeration Reveals kyc/payments/users Multiple sensitive buckets (kyc, documents, payments, users, backup) confirmed present via 403. CVSS 7.5 | Gaming Marketplace EU | Cloud Misconfig | Responsible Disclosure | High | 2026-03 |
| AdminJS Database Admin Panel Publicly Reachable db-admin.blix.gg hosts AdminJS providing direct DB access via login. CVSS 7.5 | Gaming Marketplace EU | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| GitLab Open Registration + Pipeline Trigger Token source.la3eb.com allows public GitLab sign-up giving read access to internal projects. CVSS 7.5 | Saudi Gaming Marketplace MENA | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| SuperAdmin ID Hardcoded + TOTP URI Pattern Leaked Hardcoded SuperAdmin ID 19 and TOTP URI pattern leaked enabling targeted 2FA reset. CVSS 7.5 | Gaming Recharge Platform SEA | Credential Exposure | Responsible Disclosure | High | 2026-03 |
| Grafana v12.3.0 Public + Strapi CMS Admin Public gcbuying ships Grafana and Strapi CMS admin reachable unauthenticated. CVSS 7.5 | Nigerian Gift Card Marketplace Africa | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| Internal Azure Backend Exposed PlayerAuctions toolsadmin Azure backend hostname reachable with decompiled React source (1.9MB). CVSS 7.5 | Global Gaming Marketplace Global | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| CORS Wildcard on Gateway (Laravel + Auth Header Reflection) gateway.smile.one allows any origin with Authorization header exposure. CVSS 7.5 | SEA Game Recharge Platform SEA | CORS | Responsible Disclosure | High | 2026-03 |
| Dev Environment Public With K8s Horizon Endpoints prestmit.io Laravel dev exposes Horizon queue endpoints and no reset throttle. CVSS 7.5 | African Crypto Swap Platform Africa | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| Sonata Admin Panel + Web Debug Toolbar Exposed hot.game exposes Sonata /admin/login and Symfony _wdt toolbar in production. CVSS 7.5 | Gaming Marketplace Global | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| Laravel Ignition Endpoints Active (CVE-2021-3129 Potential) zeusx.com ships Ignition endpoints enabling potential RCE per CVE-2021-3129. CVSS 7.5 | Game Top-Up Platform Global | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Operation Admin Panel Publicly Reachable cardgoal.com operation admin UI reachable without IP restriction. CVSS 7.5 | Gaming Marketplace SEA | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| Telegram Document Upload Abuse Unauth /Document/UploadFileToTelegram enables spam/abuse through platform bot. CVSS 7.5 | African Crypto Trading Platform Africa | File Upload | Responsible Disclosure | High | 2026-03 |
| Google OAuth Client ID Exposed + Admin SSO Loopholes Production Google OAuth client id embedded; admin SSO reachable over origin. CVSS 7.5 | Asian Gift-Card Marketplace SEA | Credential Exposure | Responsible Disclosure | High | 2026-03 |
| Tencent COS Bucket Public Listing Multiple Tencent COS buckets allow anonymous listing exposing order files. CVSS 7.5 | Asian Gift-Card Marketplace SEA | Cloud Misconfig | Responsible Disclosure | High | 2026-03 |
| PIM Admin Panel WASM DLL Source Code Disclosure Blazor WebAssembly DLLs decompilable exposing 70+ internal admin routes + game key architecture. CVSS 7.5 | EU Gaming Marketplace EU | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Prometheus Metrics 14,754 Lines Exposure 14,754-line Prometheus metrics endpoint reveals DB names, routes, backends. CVSS 7.5 | EU iGaming Operator EU | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| AWS ElastiCache Internal IP Leaked via Actuator Actuator metrics leak Redis ElastiCache internal IP endpoint. CVSS 7.5 | EU iGaming Operator EU | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| WordPress REST API CORS Origin Reflection + credentials:true 353 routes reflect any Origin and allow credentials, enabling cross-origin account takeover. CVSS 7.5 | European Crypto Payment Gateway EU | CORS | Responsible Disclosure | High | 2026-03 |
| Shopware6 Webhook CSRF Protection Disabled Webhook endpoint explicitly opts out of CSRF protection, compounding the absent token validation. CVSS 7.5 | European Crypto Payment Processor EU | Access Control | Responsible Disclosure | High | 2026-03 |
| Missing HMAC/Signature Across All Plugins No cryptographic signature header on webhook callbacks across 6 e-commerce plugins; unlike Stripe/PayPal. CVSS 7.5 | European Crypto Payment Processor EU | Webhook Forgery | Responsible Disclosure | High | 2026-03 |
| GraphQL Introspection Cluster Finding Multiple crypto exchanges expose full GraphQL introspection enabling schema extraction. CVSS 7.5 | Global Crypto Broker Cluster Global | GraphQL Issues | Responsible Disclosure | High | 2026-03 |
| Infura API Key Exposed on Minor Exchange Production Infura key embedded in client SPA and valid for mainnet requests. CVSS 7.5 | Global Crypto Broker Cluster Global | API Key Exposure | Responsible Disclosure | High | 2026-03 |
| Laravel Nova Admin Panel Staging Exposes 65+ Resource Models Public Laravel Nova admin staging discloses complete resource model inventory across user, trade and wallet domains. CVSS 7.5 | Nigerian Gift Card Platform Africa | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| Nova Admin Source Maps Publicly Accessible (9.9MB, 1574 files) Production Nova bundles ship with .map files revealing 1574 source files and internal API client code. CVSS 7.5 | Nigerian Gift Card Platform Africa | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Kubernetes KEDA HTTP Add-on Metadata Exposure via Headers KEDA HTTPScaledObject emits x-keda-http-cold-start headers exposing cluster internal routing metadata. CVSS 7.5 | Nigerian Gift Card Platform Africa | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Hardcoded AES-CBC Initialization Vector Across Devices Firmware ships identical AES-CBC IV across fleet enabling cross-device ciphertext manipulation. CVSS 7.5 | CCTV Infrastructure Global | Credential Exposure | Responsible Disclosure | High | 2026-03 |
| Session Key Architecture Disclosed in Source Source map reveals session key rotation logic and internal key derivation parameters. CVSS 7.5 | African Payment Gateway Africa | Credential Exposure | Responsible Disclosure | High | 2026-03 |
| Full Source Code Exposure via Source Maps (670 Files) Production build emits source maps reconstructing 670 TypeScript files with business logic. CVSS 7.5 | African P2P Crypto Platform Africa | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Unauthenticated OTP Flooding via GraphQL getLoyaltyOtp GraphQL mutation permits unlimited OTP send to arbitrary accounts enabling SMS bombing. CVSS 7.5 | MENA Travel Fintech MENA | Rate Limit Bypass | Responsible Disclosure | High | 2026-03 |
| Spring Boot Actuator /actuator/health Exposes Infrastructure Actuator health subpaths reveal database type, circuit breaker state and internal hostnames. CVSS 7.5 | EU Student Banking Fintech EU | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Internal Production Load Balancer Accessible from Internet Internal LB with prod-lb hostname is reachable publicly bypassing API gateway security controls. CVSS 7.5 | EU Student Banking Fintech EU | Cloud Misconfig | Responsible Disclosure | High | 2026-03 |
| Pre-Auth User Existence Oracle via /v3/customers/{id} Differential 401 vs 404 responses reveal whether a numeric customer ID exists enabling mass enumeration. CVSS 7.5 | EU Student Banking Fintech EU | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Unauthenticated Aion Banking Configuration Disclosure Public configuration endpoint leaks AML high-risk country list and banking agreement metadata. CVSS 7.5 | EU Student Banking Fintech EU | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Broken Access Control on All Content APIs All content APIs return catalogue and stream URLs without authentication. CVSS 7.5 | CIS Streaming Platform MENA | Access Control | Responsible Disclosure | High | 2026-03 |
| Admin Control Tower Source Map Exposure (123 Files) Admin Tower panel ships source maps revealing internal compliance, auth and payments endpoints. CVSS 7.5 | LATAM Crypto Exchange LATAM | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Complete Internal SDK Extracted - 166 Endpoints Malcolm SDK embedded in bundle reveals 166 internal endpoints across 48 service classes. CVSS 7.5 | LATAM Crypto Exchange LATAM | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Sentry DSN Exposed with Event Injection Sentry DSN in client accepts arbitrary events enabling log pollution and admin phishing via crafted payloads. CVSS 7.5 | DeFi DEX Protocol Global | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| CF Pages Branch Deployments Publicly Accessible Cloudflare Pages preview builds served without access policy expose pre-release staging configurations. CVSS 7.5 | DeFi DEX Protocol Global | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Kubernetes Internal Service Name Leak via Envoy Headers Envoy decorator headers leak Kubernetes internal service names revealing cluster service map. CVSS 7.5 | DeFi DEX Protocol Global | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Internal API Documentation on Public Apidog Internal API documentation published to public Apidog workspace exposing architecture. CVSS 7.5 | African Gift Card Platform Africa | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| OpenVPN-AS Server Publicly Accessible OpenVPN access server reachable from internet enabling credential stuffing for corporate VPN access. CVSS 7.5 | African Utility Payment Platform Africa | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| Admin Panels Publicly Accessible Admin dashboards lack IP restriction and expose login portals to internet. CVSS 7.5 | African DeFi Platform Africa | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| Production Source Maps Exposed Crypto investment platform emits production source maps exposing frontend source. CVSS 7.5 | European Crypto Investment Platform EU | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Admin Staging Panel Exposed Staging admin panel reachable without IP restriction with pre-release features exposed. CVSS 7.5 | African Remittance Platform Africa | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| Email Enumeration via Registration API POST /api/auth/register endpointi mevcut ve mevcut olmayan email adresleri icin farkli hata mesajlari donduruyor. Bu, saldirganin platform uzerindeki tum kayitli kullanicilarin email adreslerini dogrulayabilmesini saglar CVSS 7.5 | African Remittance Platform Africa | Business Logic | Responsible Disclosure | High | 2026-03 |
| Okta DEV Tenant Serving Production Authentication The production login portal at login.[vendor] is backed by an Okta tenant named my-[vendor]-dev, explicitly indicating a DEVELOPMENT environment is serving production authentication. The admin panel at my-[vendor]-dev-admin.okta.com is accessible and redirects to OIDC SSO login CVSS 7.5 | SEA Gaming Marketplace SEA | Admin Panel Exposure | HackerOne | High | 2026-03 |
| Subdomain Takeover: img.[vendor] (Dangling WP Engine CNAME) The subdomain img.[vendor] has a CNAME record pointing to 2y6hw8438dr81ty1hegbtle9.wpengine.netdna-cdn.com which no longer resolves (SERVFAIL). This dangling CNAME allows an attacker to claim the WP Engine CDN endpoint and serve arbitrary content under the [vendor] domain CVSS 7.5 | NA Gift Card Supplier NA | Subdomain Takeover | Responsible Disclosure | High | 2026-03 |
| Laravel Telescope Debug Dashboard Publicly Accessible on Staging The staging environment at staging.[vendor] exposes Laravel Telescope at /telescope without any authentication. Telescope is a debug/monitoring tool that records HTTP requests, database queries, exceptions, mail, cache operations, Redis commands, scheduled tasks, model changes, and more. This provides an attacker with deep visibility into the a CVSS 7.5 | SEA E-Commerce Platform SEA | Broken Authentication | Responsible Disclosure | High | 2026-03 |
| Disable WP_DEBUG in production <FilesMatch "\.(save|bak|old|orig|swp|~)$"> Require all denied </FilesMatch> CVSS 7.5 | SEA E-Commerce Platform SEA | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Source Map Exposure - Full Application Source Code (HIGH) Finding 4: Source Map Exposure - Full Application Source Code (HIGH) JavaScript source maps (.js.map) are exposed on ALL environments (production, staging, admin, agent), revealing the complete application source code including API endpoints, authentication logic, business logic, CVSS 7.5 | EU iGaming Operator EU | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Gambling Web3 Scan Gambling / Web3 / Gaming Marketplace Mass Scan - 2026-03-29 40+ gambling, betting, NFT, Web3, and gaming marketplace platforms scanned. 5 platforms with verified data exposure findings. Total: 3 HIGH + 4 MEDIUM + 3 LOW = 10 verified findings. CVSS 7.5 | Global Casino/DeFi Global | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Local Network Arp Audit Test Makinasi: [ip] (macOS Darwin 25.2.0, en0) Yetkilendirme: Authorized pentest [ip]/24 yerel agindan 6 guvenlik bulgusu tespit edildi. En kritik bulgu, test makinasinda IP forwarding'in aktif olmasi ve gateway ARP kaydinin statik (permanent) olarak tanimlanm CVSS 7.5 | Local Network Scan Global | RCE | Responsible Disclosure | High | 2026-03 |
| Me Tr Scan Orta Dogu ve Turkiye Kripto/Fintech/Bahis Platformlari - Veri Sizintisi Taramasi Scope: ME/TR kripto borsalari, fintech, odeme sistemleri, bahis platformlari Toplam Taranan Hedef: 80+ platform, 10 hedef derinlemesine tarama | Platform | Bulgu | Severity | Detay | CVSS 7.5 | MENA/TR Mass Scan MENA | CORS | Responsible Disclosure | High | 2026-03 |
| User Enumeration via Password Reset Endpoint Finding 3: User Enumeration via Password Reset Endpoint Severity: HIGH (CVSS 7.5 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) Summary: `password_reset/` endpoint'i kayitli ve kayitsiz email adresleri icin FARKLI yanit donduruyor. Kayitli email icin `{"status":"OK"}`, kayitsiz CVSS 7.5 | NA Online Casino NA | Rate Limit Bypass | Responsible Disclosure | High | 2026-03 |
| MinIO S3 Bucket Public Listing - `images` Bucket (HIGH) Finding 2: MinIO S3 Bucket Public Listing - `images` Bucket (HIGH) URL: https://cdn.blix.gg/images/ `images` bucket'i anonymous listing'e acik. S3 ListBucketResult XML formatinda tum dosyalar listeleniyor. 1000+ obje (IsTruncated: true), owner ID exposed. - collection/ - CS2 kole CVSS 7.5 | KYC Mass Scan Global | S3 Misconfig | Responsible Disclosure | High | 2026-03 |
| Tolgee User/Organization Data Exposure Finding 5: Tolgee User/Organization Data Exposure Type: CWE-200 (Information Exposure) 6 Entravel Developers — Full Profiles (NO MFA on any account) | ID | Name | Email | Role | MFA | CVSS 7.5 | Global Crypto Exchange Global | Broken Authentication | Responsible Disclosure | High | 2026-03 |
| Svix Webhook Dashboard Token Leak via webhookLogin Query Finding 1: Svix Webhook Dashboard Token Leak via webhookLogin Query `webhookLogin` GraphQL query'si Svix webhook yonetim platformuna tam erisim saglayan API token ve one-time login URL donduruyor. Bu token ile: - Tum webhook endpoint'leri listelenebilir - Webhook mesaj gecmisi (p CVSS 7.5 | African Payment Gateway Africa | Credential Exposure | Responsible Disclosure | High | 2026-03 |
| SSL Certificate Pinning Keys + Internal Config Exposed via Public API Finding 41: SSL Certificate Pinning Keys + Internal Config Exposed via Public API Endpoint: `GET https://www.[redacted].com/v1/common/system-config` Status: VERIFIED - Data returned without authentication The exchange's public `/v1/common/system-config` endpoint returns critical CVSS 7.5 | SEA Crypto Exchange SEA | WebSocket Issues | Responsible Disclosure | High | 2026-03 |
| Unrestricted File Upload with PHP Short Tag Injection (HIGH) Finding 1: Unrestricted File Upload with PHP Short Tag Injection (HIGH) CVSS: 7.5 (High) - AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N The `/Faq/uploadFeedbackImg.html` endpoint accepts file uploads with the field name `feedback_img`. While it restricts file extensions to image types (jp CVSS 7.5 | Gaming Marketplace SEA | File Upload | Responsible Disclosure | High | 2026-03 |
| No HTTPS - All Credentials in Plaintext Over HTTP Finding 4: No HTTPS - All Credentials in Plaintext Over HTTP CVSS Vector: AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N Router yonetim paneli HTTPS destegi sunmuyor. RSA+AES encryption client-side yapilsa da, 512-bit RSA kolayca kirilabildigi icin (Finding 2), pratikte tum credential'lar p CVSS 7.5 | CCTV Infrastructure Global | Credential Exposure | Responsible Disclosure | High | 2026-03 |
| [redacted]_BASE_URL Override for API Endpoint Hijacking Finding 5: [redacted]_BASE_URL Override for API Endpoint Hijacking Severity: High (CVSS 7.5) - already documented but noteworthy Summary: The `[redacted]_BASE_URL` environment variable (found active in `~/.zshrc`) allows complete API endpoint redirection. Combined with `[redacted]_A CVSS 7.5 | AI SaaS Provider NA | RCE | Responsible Disclosure | High | 2026-03 |
| 168 Gaming Platform Credentials Exposed via Public Endpoint Finding 2: 168 Gaming Platform Credentials Exposed via Public Endpoint Severity: High (CVSS 7.5 - AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) The endpoint `/api/products/demo-accounts` returns 168 plaintext username/password combinations for 36 different gaming platforms without any aut CVSS 7.5 | NA Online Casino NA | Credential Exposure | Responsible Disclosure | High | 2026-03 |
| 22/26 Scopes Granted with Empty Client Secret Finding 2: 22/26 Scopes Granted with Empty Client Secret Test client ID `test-195944A9-E957-4532-B574-D37BD5FD9297` bos client_secret ile 26 scope'un 22'sini grant ediyor. Bu scope'lar `pci_unsafe`, `client_vault_manage`, `client_vault_proxy`, `client_disbursement`, `client_merch CVSS 7.5 | African Payment Gateway Africa | Credential Exposure | Responsible Disclosure | High | 2026-03 |
| Cloudflare WAF Bypass via Direct Origin IP Access Origin IP reachable directly, bypassing WAF rules on all API endpoints. CVSS 7.4 | African Crypto Exchange Africa | Cloud Misconfig | Responsible Disclosure | High | 2026-03 |
| HTTP Basic Auth Fallback with Credentials in SessionStorage Device accepts HTTP Basic fallback and stores AES-encrypted credentials in sessionStorage subject to XSS exfil. CVSS 7.4 | CCTV Infrastructure Global | Broken Authentication | Responsible Disclosure | High | 2026-03 |
| Wildcard DNS btmops.xyz Exposes Complete Infrastructure Topology Wildcard DNS resolves every subdomain to a single Caddy host revealing all hosted services. CVSS 7.3 | African Crypto Exchange Africa | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Segment Analytics Write Key Exposed — Event Injection Verified Segment Write Key (2hfUaoiBcaEUEyqjaYb5biu56ARGjcL3) Hardcoded in Client JS — Arbitrary Event/User Injection into [vendor]Analytics Pipeline CVSS 7.3 | LATAM Crypto Platform LATAM | Credential Exposure | HackerOne | High | 2026-03 |
| Security Finding FINDING 21: Smart Contract -- Rounding Direction Error in Withdraw (MEDIUM) All four `_withdrawSomeX()` functions use `.add(1)` (ceiling rounding), withdrawing 1 extra token unit from lenders per withdrawal. This benefits the withdrawer at the vault's expense. FINDING 22: Verbose CVSS 7.3 | African DeFi Protocol Africa | Reentrancy | Responsible Disclosure | High | 2026-03 |
| Hardcoded AES Key Derivation Salt Shared Across All Devices All camera units share the same AES key-derivation salt, weakening password-based secrets platform-wide. CVSS 7.2 | CCTV Infrastructure Global | Credential Exposure | Responsible Disclosure | High | 2026-03 |
| Chatwoot Super Admin Panel Publicly Accessible The Chatwoot instance at support.[vendor] exposes its Super Admin login panel at /super_admin/sign_in without any IP restriction or additional authentication layer. The Super Admin panel provides full control over all Chatwoot accounts, agents, conversations, and configuration CVSS 7.2 | NA Gift Card Supplier NA | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| LiteSpeed WebAdmin Console Publicly Exposed (HIGH) Finding 3: LiteSpeed WebAdmin Console Publicly Exposed (HIGH) Origin sunucu ([ip]) üzerinde LiteSpeed WebAdmin Console port 7080'de herhangi bir IP kısıtlaması olmadan internet'e açık. Brute-force saldırısı ile admin erişimi elde edilebilir. `https://[ip]:7080/l CVSS 7.2 | Web Hosting Provider EU | Default Creds | Responsible Disclosure | High | 2026-03 |
| Sentry DSN Exposure + Event Injection 2 Projects Dashboard and Pay production Sentry DSN keys exposed allowing event injection and quota exhaustion. CVSS 7.1 | European Crypto Payment Gateway EU | Credential Exposure | Responsible Disclosure | High | 2026-03 |
| Internal Admin Redirect URI Leaked OAuth redirect URI for internal admin SSO leaked permitting phishing-style redirect abuse. CVSS 7.1 | African Payment Gateway Africa | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Avalanche RPC CORS Wildcard with Credentials Avalanche RPC proxy returns wildcard Origin with credentials enabling cross-origin RPC calls from any site. CVSS 7.1 | DeFi DEX Protocol Global | CORS | Responsible Disclosure | High | 2026-03 |
| ADL Safety Mechanism Neutralized via Trivial Repayment in EMode Group Activation checks global reserve debt while deactivation checks emode-group debt, so any small repay deactivates ADL prematurely. CVSS 7.0 | Sui L1 Lending Protocol Global | Business Logic | Sherlock | High | 2026-03 |
| WordPress XMLRPC Brute Force Amplification wp xmlrpc.php returns verbose auth errors with no lockout, enabling fast password brute force. CVSS 7.0 | Global P2P Crypto Marketplace Global | Rate Limit Bypass | Responsible Disclosure | High | 2026-03 |
| gRPC Reflection on All Production Services (200+ Endpoints) Reflection enabled on every production gRPC service disclosing 200+ RPC methods. CVSS 7.0 | SEA Banking API Platform SEA | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Grafana 12.0.0 Public /metrics Exposes 39 Users and 23 Datasources Unauth /metrics endpoint leaks user inventory and datasource topology. CVSS 7.0 | SEA Banking API Platform SEA | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Production Runtime Config Exposed via /config Endpoints Multiple services expose /config endpoints returning sensitive runtime configuration. CVSS 7.0 | SEA Banking API Platform SEA | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Feature Toggle Bypass via Query Parameters Query param ?ff=xyz enables hidden product features bypassing server-side toggle. CVSS 7.0 | SEA Banking API Platform SEA | Business Logic | Responsible Disclosure | High | 2026-03 |
| Sentry DSN Exposed in Admin Panel Event Injection Verified Admin Sentry DSN accepts arbitrary crash events, enabling operator-facing log poisoning. CVSS 7.0 | African Fintech Neobank Africa | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Firebase Configuration Exposed With Full Project Details Web app leaks Firebase web config enabling direct Firestore queries. CVSS 7.0 | African Fintech Neobank Africa | Firebase Misconfig | Responsible Disclosure | High | 2026-03 |
| Airtable API Key With CREATE Permissions on 7 Bases Airtable key grants write access to seven business-critical bases via exposed secret. CVSS 7.0 | African Crypto Exchange Africa | API Key Exposure | Responsible Disclosure | High | 2026-03 |
| Bull Board Job Queue Metrics Unauthenticated Bull Board exposes queue metrics unauth leaking internal job parameters. CVSS 7.0 | African Fintech Remittance Africa | Admin Panel Exposure | Responsible Disclosure | High | 2026-03 |
| Azure AD Tenant + Client ID Leak PlayerAuctions admin JS leaks Azure AD tenant and client IDs. CVSS 7.0 | Global Gaming Marketplace Global | Credential Exposure | Responsible Disclosure | High | 2026-03 |
| Merchant Integration API Docs Fully Open Merchant docs enumerate signing scheme and endpoint list without auth. CVSS 7.0 | SEA Game Recharge Platform SEA | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| 5 AWS S3 Buckets Including cdn-user-photo zeusx.com references 5 S3 buckets including one named for user photos / KYC. CVSS 7.0 | Game Top-Up Platform Global | S3 Misconfig | Responsible Disclosure | High | 2026-03 |
| Swagger API + Postman Collection Fully Open kopazar.com exposes Swagger docs and Postman collection revealing full API shape. CVSS 7.0 | Turkish E-Pin Marketplace EU | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| PAYMAPI Payment API Documentation Fully Open epin.com.tr exposes PAYMAPI documentation listing all payment endpoints. CVSS 7.0 | Turkish Payment Processor EU | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Grafana Faro APM Key Valid – Telemetry Injection Verified Client-side APM key accepts arbitrary telemetry enabling alert fatigue and alert-based phishing. CVSS 6.5 | SEA Banking API Platform SEA | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Bugsnag and Datadog Client Tokens in Source Map Observability client tokens leaked enabling abuse of monitoring SaaS billing. CVSS 6.5 | African Payment Gateway Africa | API Key Exposure | Responsible Disclosure | High | 2026-03 |
| Document Upload and Payment Endpoints Accept Unauthenticated Requests Multiple KYC document and payment endpoints return 500 instead of 401 indicating missing auth check upstream. CVSS 6.5 | EU Student Banking Fintech EU | Access Control | Responsible Disclosure | High | 2026-03 |
| Partner Portal Source Map Exposure Partner portal ships source maps revealing internal partner API configuration. CVSS 5.3 | LATAM Crypto Platform LATAM | Information Disclosure | Responsible Disclosure | High | 2026-03 |
| Mailigen Webhook Signature Bypass on Payment Gateway Mailigen webhook accepts unsigned payloads, allowing attackers to inject email events and alter subscriber state. CVSS 7.5 | European Payment Gateway EU | Webhook Forgery | Responsible Disclosure | Medium | 2026-04 |
| Payment Gateway Admin Panel Publicly Accessible Ginger admin panel reachable from the internet without IP allowlist, exposing privileged administration UI. CVSS 7.5 | European Payment Gateway EU | Admin Panel Exposure | Responsible Disclosure | Medium | 2026-04 |
| Unprotected KYC Webhook (SumSub) The SumSub KYC webhook endpoint accepts POST requests without signature verification on both PROD and TEST CVSS 6.8 | EU Crypto Exchange EU | KYC Bypass | HackerOne | Medium | 2026-04 |
| Development Configuration Exposed in Production Frontend dev.*, auth-test.*, localhost URLs embedded in production build reveal internal staging hosts and environment layout. CVSS 6.5 | European Payment Gateway EU | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| AWS Cognito UserPoolId and ClientId Hardcoded in Frontend Cognito pool and client IDs shipped in frontend allow unauthenticated signup and enumeration against the user pool. CVSS 6.5 | European Payment Gateway EU | Credential Exposure | Responsible Disclosure | Medium | 2026-04 |
| Sub-Cent Product Pricing via Decimal Quantity Manipulation Decimal quantity in line items rounds prices below cent, enabling goods purchase at trivial value. CVSS 6.5 | European Payment Gateway EU | Business Logic | Responsible Disclosure | Medium | 2026-04 |
| Internal Worldline Gateway Endpoints Publicly Accessible Internal Worldline integration endpoints exposed on public API subdomain, leaking partner architecture. CVSS 6.5 | European Payment Gateway EU | Admin Panel Exposure | Responsible Disclosure | Medium | 2026-04 |
| Outdated Software Stack With Known CVEs commons-collections, commons-beanutils, iText, JasperReports all pinned to versions with public RCE CVEs. CVSS 6.5 | SEA Investment Platform SEA | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| 2FA Disable Without Password Confirmation 2FA disable endpoint accepts session alone without password re-entry. CVSS 6.5 | Indian Crypto Exchange SEA | Broken Authentication | Responsible Disclosure | Medium | 2026-04 |
| Password Reset Hash Code Disclosure in Response Reset-password endpoint returns the reset hash in the JSON response enabling takeover via email-log exposure. CVSS 6.5 | Indian Crypto Exchange SEA | Broken Authentication | Responsible Disclosure | Medium | 2026-04 |
| Cloudinary Unsigned Upload Configuration Exposed Cloudinary preset configured for unsigned upload allowing arbitrary asset ingestion under brand domain. CVSS 6.5 | African Crypto Aggregator Africa | Cloud Misconfig | Responsible Disclosure | Medium | 2026-04 |
| Unauthenticated Trade API With Full Asset Configuration Trade API endpoint lists all configured assets and parameters without auth. CVSS 6.5 | MENA Crypto Exchange MENA | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| Firebase Configuration With Multiple Google API Keys Firebase config JSON enumerates all Google Cloud API keys used by the exchange. CVSS 6.5 | European Crypto Exchange EU | Firebase Misconfig | Responsible Disclosure | Medium | 2026-04 |
| Admin Panel Public Without IP Restriction Admin panel reachable publicly without IP allowlist or SSO. CVSS 6.5 | Web3 Reputation Protocol Global | Admin Panel Exposure | Responsible Disclosure | Medium | 2026-04 |
| CORS Wildcard on API Backends Multiple backends return Access-Control-Allow-Origin:* enabling cross-origin abuse. CVSS 6.5 | African P2P Crypto Settlement Africa | CORS | Responsible Disclosure | Medium | 2026-04 |
| Dokploy Admin Panel Exposed tRPC Procedures Dokploy panel reachable with tRPC procedures valid. CVSS 6.5 | African Payment Platform Africa | Admin Panel Exposure | Responsible Disclosure | Medium | 2026-04 |
| S3 Bucket Public Listing Production User Content production-gameflip-listing-photo bucket proxied via CloudFront with open listing. CVSS 6.5 | Gaming Marketplace NA | S3 Misconfig | Responsible Disclosure | Medium | 2026-04 |
| CORS Wildcard with Secret-Token Header API returns wildcard CORS and allows x-secret-token header exposing hardcoded secret to any origin. CVSS 6.5 | West African B2B Fintech Africa | CORS | Responsible Disclosure | Medium | 2026-04 |
| Full Firebase Config Exposed ❌ No hardcoded Django admin passwords - ❌ No database connection strings (PostgreSQL/Redis) - ❌ No AWS AKIA access keys - ❌ No JWT secret keys - ❌ No Cognito/Amplify pool IDs in APK (loaded via native confi CVSS 6.5 | EU Crypto Exchange EU | Firebase Misconfig | Responsible Disclosure | Medium | 2026-04 |
| Bank Inquiry Endpoint - Server-Side Bank Account Validation (No Auth) The bank inquiry endpoint performs server-side validation of bank account numbers against Indonesia's banking network, without authentication. This can be abused to validate/verify arbitrary bank account numbers CVSS 6.5 | SEA Crypto Exchange SEA | Business Logic | Responsible Disclosure | Medium | 2026-04 |
| Race Condition in Withdrawal Rate Limit /api/auth/withdraw-balance endpoint-inde 5 deqiqelik rate limit var. Amma 10 eyni zamanli request gonderildikde, 1-i rate limit check-ini bypass edir ve sonraki validation merehlesine catir. Bu, withdrawal-in parallel islenildiyini ve TOCTOU (Time-of-Check-to-Time-of-Use) race condition-un movcud oldugunu gosterir CVSS 6.5 | Crypto Payment Processor Global | Rate Limit Bypass | Responsible Disclosure | Medium | 2026-04 |
| Origin IP Disclosure via Traefik (153.92.211.157) [MEDIUM] Vulnerable Component: Origin server 153.92.211.157 (Hostinger, Manchester UK) CVSS 6.5 | Crypto Exchange Platform Global | Business Logic | Responsible Disclosure | Medium | 2026-04 |
| [target] Admin Panel Not Behind Cloudflare -- Direct IP Exposed (MEDIUM) Finding 5: [target] Admin Panel Not Behind Cloudflare -- Direct IP Exposed (MEDIUM) Severity: Medium (CVSS 6.5 - AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L) Summary: The admin panel at [target] resolves directly to IP [ip] (not proxied through Cloudflare), CVSS 6.5 | MENA Fintech MENA | CORS | Responsible Disclosure | Medium | 2026-04 |
| Deep Exploit Results 1. D[redacted]ed error messages: Tells attacker exactly how many attempts remain 2. No CAPTCHA: Automated brute force possible 3. No IP-based rate limiting: Multiple emails can be tested from same IP 4. Corporate login same issue: `/corporate/auth/login` also vulnerable CVSS 6.5 | African Remittance Provider Africa | Rate Limit Bypass | Responsible Disclosure | Medium | 2026-04 |
| 7 Staging API Microservices Publicly Accessible Seven staging API subdomains reachable without authentication. CVSS 6.3 | African Neobank Africa | Cloud Misconfig | Responsible Disclosure | Medium | 2026-04 |
| Stored XSS via Product Name in Purchase Creation Product name propagates unescaped into merchant dashboard and receipts, allowing stored XSS against merchants. CVSS 6.1 | European Payment Gateway EU | XSS | Responsible Disclosure | Medium | 2026-04 |
| Prototype Pollution via __proto__ Key Finding 4: Prototype Pollution via __proto__ Key Injecting `__proto__` as a JSON key crashes the token generation: Response: Empty / no token returned. This indicates the `__proto__` key causes a server-side error during `jwt.sign()` or object processing, which could be: 1. A DoS CVSS 5.8 | Nigerian Payment Provider Africa | Prototype Pollution | Responsible Disclosure | Medium | 2026-04 |
| Multiple Laravel API Gateway Instances with Debug Information [MEDIUM] Finding 6: Multiple Laravel API Gateway Instances with Debug Information [MEDIUM] Summary: apigateway.[redacted].ng ve apigateway.prod.[redacted].ng adreslerinde Laravel API Gateway'leri public erisime acik. Her ikisinde de default Laravel welcome page gosteriliyor, login formları mevc CVSS 5.8 | Nigerian Neobank Africa | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| MEDIUM - Exposed Admin and Internal Endpoints (403 vs 404) Finding 5: MEDIUM - Exposed Admin and Internal Endpoints (403 vs 404) Multiple admin and internal management endpoints exist and respond with 403 Forbidden instead of 404 Not Found, confirming their existence. These endpoints may become accessible through authentication bypass. - CVSS 5.8 | EU iGaming Operator EU | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| Findings Deep | `/var/log/nginx/access.log` | 25 MB | All HTTP requests, IPs, User-Agents, paths | | `/var/log/nginx/error.log` | 315 KB | Server errors | | `/var/www/pegasus/storage/logs/laravel.log` | 236 KB | Laravel errors, stack traces, internal paths | | 14x rotated/gzipped access logs | CVSS 5.8 | African Crypto Exchange Africa | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| MEDIUM - WordPress REST API with 215 Routes Finding 5: MEDIUM - WordPress REST API with 215 Routes URL: `https://trade.[redacted].site/wp-json/` - PHP 7.4.33 (EOL since November 2022) - WordPress with RankMath SEO plugin CVSS 5.8 | Mixed Platforms Global | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| 736 Real User ObjectIDs Exposed via DO Spaces Finding 5: 736 Real User ObjectIDs Exposed via DO Spaces The DO Spaces bucket (`[redacted].[target]`) has public listing enabled, exposing 988 files with 736 unique MongoDB ObjectIDs from user profile photos: These ObjectIDs can be injected into the `_id`, ` CVSS 5.8 | Nigerian Payment Provider Africa | JWT Issues | Responsible Disclosure | Medium | 2026-04 |
| — CVSS 10.0 — GCE Root Shell (SSH Key Injection) Finding 3 — CVSS 10.0 — GCE Root Shell (SSH Key Injection) Sunucu: `website-cms` ([ip], us-central1-a, Debian 12) Yöntem: `[redacted]-lupin` SA (roles/owner) → Compute Engine `setMetadata` → SSH key enjeksiyon → root | `/var/www/html/proxy/.env` | `JWT_SECRET=714a7ea9a0ef4d788 CVSS 5.8 | African Remittance Provider Africa | Credential Exposure | Responsible Disclosure | Medium | 2026-04 |
| MEDIUM - S3 Bucket Discovery ([redacted]-documents) Finding 5: MEDIUM - S3 Bucket Discovery ([redacted]-documents) The S3 bucket `[redacted]-documents` exists and returns 403 (access denied but not 404), confirming its existence. - 167 subdomains discovered via crt.sh - [redacted] Organization: o407766 (shared across Flex + support app) CVSS 5.8 | African Neobank Africa | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| MEDIUM - WordPress User Enumeration Finding 4: MEDIUM - WordPress User Enumeration URL: `GET https://trade.[redacted].site/wp-json/wp/v2/users` - ID 5: Adul Hassan (slug: hazzan) CVSS 5.8 | Mixed Platforms Global | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| No Server-Side JWT Invalidation on Logout Logout only clears the client-side cookie while tokens remain valid server-side. CVSS 5.5 | Indian Crypto Exchange SEA | Broken Authentication | Responsible Disclosure | Medium | 2026-04 |
| Source Map Exposure With KYC Service Architecture cryptoforce.in JS bundles leak KYC microservice architecture and endpoints. CVSS 5.5 | Indian Crypto Exchange SEA | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| Full API Architecture Disclosed (250+ endpoints) Bundle discloses 250+ internal endpoints with parameter signatures. CVSS 5.5 | African Fintech Expense Platform Africa | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| X-Session-Override Header Enables Session Fixation Custom X-Session-Override header accepts attacker-supplied session IDs, enabling fixation attacks. CVSS 5.4 | European Payment Gateway EU | Broken Authentication | Responsible Disclosure | Medium | 2026-04 |
| Sentry DSN Event Injection Across Three Projects Three Sentry DSNs exposed in JS bundles accept arbitrary events, enabling log pollution and internal alert fatigue. CVSS 5.3 | European Payment Gateway EU | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| Public OpenAPI/Swagger Schemas Expose Full API Documentation OpenAPI schemas of three platforms are served without auth, enumerating internal endpoints and parameters. CVSS 5.3 | European Payment Gateway EU | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| Internal Hostname and Port Leak via 404 Page Default 404 response reveals internal Kubernetes hostnames and ports, aiding SSRF and lateral pivots. CVSS 5.3 | European Payment Gateway EU | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| 2FA Optional by Default on Payment Gateway Admin Accounts New admin accounts default to 2FA disabled across all instances, weakening account security posture. CVSS 5.3 | European Payment Gateway EU | Broken Authentication | Responsible Disclosure | Medium | 2026-04 |
| Internal User IDs and Application Configuration Exposure Assorted config endpoints reveal internal user IDs, feature flags and microservice addresses. CVSS 5.3 | SEA Investment Platform SEA | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| MongoDB ObjectID and Schema Leak in Error Responses Stack traces expose Mongo ObjectIDs and schema fields aiding injection-based attacks. CVSS 5.3 | Indian Crypto Exchange SEA | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| Sentry DSN Exposed + Event Injection Sentry DSN accepts arbitrary events usable for alert fatigue attacks. CVSS 5.3 | African Fintech Expense Platform Africa | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| RSA Public Key + Analytics Key Exposure PocketBits bundle leaks RSA public key and analytics key usable for targeted attacks. CVSS 5.3 | Indian Crypto Exchange SEA | Credential Exposure | Responsible Disclosure | Medium | 2026-04 |
| Infura + WalletConnect Project IDs Exposed Infura project ID and WalletConnect credentials in bundle. CVSS 5.3 | African Crypto Infrastructure Africa | API Key Exposure | Responsible Disclosure | Medium | 2026-04 |
| Source Map Exposure on App Bundle flipexapp.com exposes production source map revealing app structure. CVSS 5.3 | African Crypto Trading Mobile App Africa | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| Firebase Storage Public File Listing (31 items) dtunes-app bucket rules allow anonymous listing of user-uploaded images. CVSS 5.3 | African Digital Platform Africa | Firebase Misconfig | Responsible Disclosure | Medium | 2026-04 |
| save-live - Open Firestore with 6 Users PII Algerian blood donation app Firestore open exposing 6 users with phone/email/FCM tokens. CVSS 5.3 | African Fintech Firebase Cohort Africa | Firebase Misconfig | Responsible Disclosure | Medium | 2026-04 |
| Apache Airflow Unauthenticated Info Disclosure pricepally Airflow exposes DAG metadata without auth. CVSS 5.3 | African Fintech Metabase Cohort Africa | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| Metabase Login No Rate Limiting Metabase login and reset endpoints allow unlimited attempts enabling brute-force. CVSS 5.3 | African Investment Fintech Africa | Rate Limit Bypass | Responsible Disclosure | Medium | 2026-04 |
| Cloudinary Cloud Name + Upload Preset Discoverable Cloudinary cloud_name 'drugstoc' allows unsigned uploads if preset leaked. CVSS 5.3 | African Pharma B2B Platform Africa | Cloud Misconfig | Responsible Disclosure | Medium | 2026-04 |
| Development Configuration Deployed to Production VITE_APP_ENV=development and devnet RPC URLs deployed to production dashboard. CVSS 5.3 | Crypto Payment Infrastructure Global | Cloud Misconfig | Responsible Disclosure | Medium | 2026-04 |
| Strapi v4 CMS Publicly Reachable content subdomain serves Strapi admin without auth redirect. CVSS 5.3 | European Crypto Exchange EU | Admin Panel Exposure | Responsible Disclosure | Medium | 2026-04 |
| Birdeye DeFi API Key Hardcoded Birdeye paid API key embedded in SPA; enables quota exhaustion. CVSS 5.3 | L1 Smart Contract Global | API Key Exposure | Responsible Disclosure | Medium | 2026-04 |
| HitBTC/AlphaPoint Swagger UI Exposed api.exchange.cryptomkt.com Swagger exposes full REST schema. CVSS 5.3 | LATAM Crypto Platform LATAM | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| .env File Path Exists Behind WAF /.env returns 200 indicating file exists; only WAF blocks content. Bypass = full DB/APP_KEY. CVSS 5.3 | MENA Payment Giant MENA | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| Production Source Map Exposure on Affiliate Admin Panel Affiliate admin Vue source code and internal API routes exposed via publicly-served source map. CVSS 5.3 | SEA Crypto Derivatives Exchange SEA | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| Unlimited Wallet Creation Resource Exhaustion No limit on wallet creation per user; 20+ wallets per session feasible. CVSS 5.3 | West African Crypto Exchange Africa | Rate Limit Bypass | Responsible Disclosure | Medium | 2026-04 |
| eKYC Application Publicly Accessible on Subdomain External KYC verification app reachable without auth enabling reconnaissance of onboarding flow and potential data submission abuse. CVSS 5.3 | MENA Super-App Fintech MENA | KYC Bypass | Responsible Disclosure | Medium | 2026-04 |
| Unauthenticated Products/System-Settings Data Exposure Product details including AUM data, fee structures, wallet configurations, and system maintenance flags are exposed without any authentication CVSS 5.3 | SEA Crypto Exchange SEA | Business Logic | Responsible Disclosure | Medium | 2026-04 |
| PHP Error Disclosure GET /api/auth/menu-visibility {"success":false,"message":"Error","data":"Undefined variable $isMenu"} CVSS 5.3 | Crypto Payment Processor Global | Business Logic | Responsible Disclosure | Medium | 2026-04 |
| Server Error Information Disclosure on Multiple Endpoints [MEDIUM] Vulnerable Endpoints: Multiple CVSS 5.3 | Crypto Exchange Platform Global | Information Disclosure | HackerOne | Medium | 2026-04 |
| Staging Environments Publicly Accessible > NEW FINDING CVSS 5.3 | African SME Lender Africa | Firebase Misconfig | Responsible Disclosure | Medium | 2026-04 |
| Cloud Run Microservices — 16 Services Exposed > NEW FINDING CVSS 5.3 | African SME Lender Africa | File Upload | Responsible Disclosure | Medium | 2026-04 |
| Django REST Framework OpenAPI Schema Endpoint Server Error Vulnerable Endpoint: https://api.[vendor]/api/schema/ CVSS 5.3 | African Identity Verification Africa | Business Logic | Responsible Disclosure | Medium | 2026-04 |
| Complete IdentityPass API Endpoint Enumeration - 15+ Active Verification Endpoints API Base: https://api.[vendor]/identitypass/ CVSS 5.3 | African Identity Verification Africa | API Key Exposure | Responsible Disclosure | Medium | 2026-04 |
| Direct IP erisimini kapat CVSS 5.3 | African E-Commerce Platform Africa | Admin Panel Exposure | Responsible Disclosure | Medium | 2026-04 |
| WordPress User Enumeration and XML-RPC Enabled (MEDIUM) Finding 6: WordPress User Enumeration and XML-RPC Enabled (MEDIUM) Severity: Medium (CVSS 5.3 - AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) Summary: The WordPress blog at blog.[redacted].com exposes 4 user accounts via the REST API and has XML-RPC fully enabled with 80+ methods including c CVSS 5.3 | MENA Fintech MENA | Rate Limit Bypass | Responsible Disclosure | Medium | 2026-04 |
| [redacted] DSN Exposure with Verified Event Injection (MEDIUM) Finding 3: [redacted] DSN Exposure with Verified Event Injection (MEDIUM) - [redacted] App: `https://9c7d5cbc05d7ab151c379cf9bb2248e9@o4506558158471168.ingest.[redacted].io/4506558160437248` - Manteca Ramp: `https://ba91a78331d307cffbf7e77574d78ae9@o4506558158471168.ingest.[redacted].io/45 CVSS 5.3 | LATAM Crypto Platform LATAM | XSS | Responsible Disclosure | Medium | 2026-04 |
| Username and Email Enumeration via Registration Finding 3: Username and Email Enumeration via Registration Vulnerable Endpoint: `POST https://thor.[redacted].com/api/register` Type: Information Exposure (CWE-204) The registration endpoint returns different error messages depending on whether a username, email, or phone number is CVSS 5.3 | African Crypto Exchange Africa | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| Email Verification Not Required for Full Platform Access Unverified email accounts gain full platform access, making phishing/impersonation trivial. CVSS 5.0 | European Payment Gateway EU | Broken Authentication | Responsible Disclosure | Medium | 2026-04 |
| .git Directory Detected on Production Server / .git returns 403 not 404 confirming repo presence on production webroot. CVSS 5.0 | EU Crypto ATM Operator EU | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| Dev API Stack Trace Information Disclosure Dev API error handler returns stack traces exposing internal paths. CVSS 5.0 | African Fintech Expense Platform Africa | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| Third-Party Service Credentials Exposed in Bundle Multiple third-party SaaS API keys present in production build. CVSS 5.0 | African Fintech Expense Platform Africa | API Key Exposure | Responsible Disclosure | Medium | 2026-04 |
| Unauthenticated Platform Configuration Disclosure Across Instances Spell instance configs downloadable without auth, leaking feature flags and integration IDs. CVSS 4.3 | European Payment Gateway EU | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| Email Flood via Unlimited Password Reset and Verification Unlimited transactional email triggers enable victim mailbox flooding and cost attacks against the provider. CVSS 4.3 | European Payment Gateway EU | Rate Limit Bypass | Responsible Disclosure | Medium | 2026-04 |
| PHP Stack Trace Leak via API Error Malformed request returns PHP stack trace exposing Nette framework paths. CVSS 4.3 | EU Crypto ATM Operator EU | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| PHP Version Disclosure via X-Powered-By PHP 8.4.3 version advertised in every API response aiding CVE targeting. CVSS 4.3 | SEA Crypto Exchange SEA | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| Hardcoded Internal API URLs in Production JS Internal API endpoints and infra hostnames visible in compiled frontend. CVSS 4.3 | MENA Regulated Crypto Exchange MENA | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| Hardcoded Cryptocurrency Wallet Addresses and reCAPTCHA Key (MEDIUM) Finding 5: Hardcoded Cryptocurrency Wallet Addresses and reCAPTCHA Key (MEDIUM) Affected Component: Source maps (environment.prod.ts, balance.service.ts, qr-payment.service.ts) Summary: Production cryptocurrency wallet addresses, reCAPTCHA site key, and contract addresses are har CVSS 4.3 | LATAM Crypto Platform LATAM | Information Disclosure | Responsible Disclosure | Medium | 2026-04 |
| Internal Infrastructure Details Leaked Dev ortami HTML sayfasi ve HTTP response header'lari, dahili altyapi detaylarini ifsa etmektedir CVSS 6.8 | African Crypto Exchange Africa | Business Logic | Responsible Disclosure | Medium | 2026-03 |
| Ops Partner Portal - Unauthenticated Dashboard Redirect + CSRF Token Leak Ops Partner Portal'a kimlik dogrulamasi olmadan erisim saglanabiliyor. Ana sayfa dogrudan /dashboard'a redirect ediyor (auth check yok). CSRF token ve session cookie unauthenticated olarak veriliyor CVSS 6.8 | African Crypto Exchange Africa | Business Logic | HackerOne | Medium | 2026-03 |
| Unliquidatable Dust Position Creates Permanent Protocol Bad Debt floor() rounding in seize_ctokens combined with missing min_borrow enforcement leaves tiny positions that cannot be liquidated, accumulating bad debt. CVSS 6.5 | Sui L1 Lending Protocol Global | Rounding | Sherlock | Medium | 2026-03 |
| Flash Loan Fee Arbitrage via Caller-Controlled emode_group Parameter Unvalidated emode_group parameter lets flash loan borrower pick the group with the lowest fee_rate for any asset, draining protocol fee revenue. CVSS 6.5 | Sui L1 Lending Protocol Global | Business Logic | Sherlock | Medium | 2026-03 |
| EMode Borrow Limit Bypass via Stale Interest Tracking assets_borrows tracking never reflects interest accruing on idle obligations so the per-emode max_borrow_amount cap is progressively exceeded. CVSS 6.5 | Sui L1 Lending Protocol Global | Business Logic | Sherlock | Medium | 2026-03 |
| Chatwoot Super Admin Panel Exposed Chatwoot super admin login page publicly reachable on subdomain. CVSS 6.5 | SEA Banking API Platform SEA | Admin Panel Exposure | Responsible Disclosure | Medium | 2026-03 |
| Staging/Dev Admin Panels Publicly Accessible Dev/staging admin portals reachable publicly mirroring production codebase. CVSS 6.5 | African Fintech Neobank Africa | Admin Panel Exposure | Responsible Disclosure | Medium | 2026-03 |
| Client-Side Encryption Broken (secretPhrase + encryptionSecret Exposed) Bundle embeds secretPhrase and encryptionSecret used for client-side payload protection. CVSS 6.5 | African Crypto Exchange Africa | Credential Exposure | Responsible Disclosure | Medium | 2026-03 |
| Ory Kratos Admin API Publicly Accessible Kratos admin endpoints reachable without network control, exposing identity schemas. CVSS 6.5 | African Bitcoin Lightning Provider Africa | Admin Panel Exposure | Responsible Disclosure | Medium | 2026-03 |
| 6 Socket.IO Endpoints Accept Unauthenticated Connections Six Socket.IO endpoints accept unauth connections exposing real-time trade feeds. CVSS 6.5 | Indian Crypto Exchange SEA | WebSocket Issues | Responsible Disclosure | Medium | 2026-03 |
| Cross-Site WebSocket Hijacking (CSWSH) on Exchange WebSocket WebSocket handshake skips Origin validation allowing attacker pages to open authenticated channels. CVSS 6.5 | Global P2P Crypto Marketplace Global | WebSocket Issues | Responsible Disclosure | Medium | 2026-03 |
| Kubernetes Internal Service URL Leak topuplive.com leaks internal K8s svc URLs usable as SSRF target. CVSS 6.5 | Gaming Top-Up Platform Global | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| FlowM /events Auth Guard Bypass (Event Injection) /events and /events/simulate processed without auth enabling arbitrary event injection. CVSS 6.5 | Central African Crypto Fintech Africa | Access Control | Responsible Disclosure | Medium | 2026-03 |
| CORS Origin Reflection with Credentials on forms subdomain forms.* subdomain reflects arbitrary Origin with Access-Control-Allow-Credentials true enabling cross-origin credentialed requests. CVSS 6.5 | Nigerian Gift Card Platform Africa | CORS | Responsible Disclosure | Medium | 2026-03 |
| Login Page reCAPTCHA Sitekey and Architecture Disclosure (redeem-cards.com) The login page at redeem-cards.com exposes the reCAPTCHA v3 sitekey, form structure, and when a non-empty CaptchaToken is provided, triggers DeveloperExceptionPage with full stack traces CVSS 6.5 | EU Gaming Key Marketplace EU | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| Xbox Bot Store Schedule Manipulation (20 Stores) The collectglobalstore endpoint is accessible without authentication and triggers schedule rescheduling across ALL 20 Xbox stores. A single unauthenticated request modifies the update schedule for the entire Xbox game tracking system CVSS 6.5 | EU Gaming Key Marketplace EU | Rate Limit Bypass | Responsible Disclosure | Medium | 2026-03 |
| Sentry Open Registration Form (Registration Tab Active) The Sentry login page includes an active "Register" tab with a functional registration form (op=register). While the form fields appear to be empty (possibly a rendering issue), the form endpoint accepts POST requests with the register operation. Combined with invitesEnabled: true, this indicates the Sentry instance may accept new user registrat CVSS 6.5 | NA Gift Card Supplier NA | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| HIGH - Keycloak SSO & Internal Service Architecture Exposed Vulnerable Endpoints: - https://keycloak.[vendor]/auth/realms/[vendor]- https://keycloak.[vendor]/auth/realms/[vendor]/.well-known/openid-configuration - https://[vendor] / (CORS wildcard) CVSS 6.5 | African Payment Processor Africa | CORS | Responsible Disclosure | Medium | 2026-03 |
| HIGH - EMQX MQTT Broker Dashboard Publicly Accessible (emqx.[vendor]) Vulnerable Endpoint: https://emqx.[vendor] CVSS 6.5 | African Payment Processor Africa | Credential Exposure | Responsible Disclosure | Medium | 2026-03 |
| Metabase v0.53.6 Setup-Token Persistent Exposure metabase.[vendor] uzerindeki Metabase v0.53.6, setup tamamlanmis olmasina ragmen setup-token'i /api/session/properties endpointi uzerinden herkese acik birakiyor CVSS 6.5 | African Remittance Platform Africa | Admin Panel Exposure | Responsible Disclosure | Medium | 2026-03 |
| FortiGate SSL VPN Login Exposed + Internal IP Leak Endpoint: https://ofw.[vendor] CVSS 6.5 | EU Digital Goods Marketplace EU | Business Logic | Responsible Disclosure | Medium | 2026-03 |
| KChat Vue.js SPA Complete Source Code and API Architecture Exposure kchat.[vendor]'da host edilen Vue.js SPA, tum source chunk'lari ile birlikte public olarak erisilebilir durumdadir. Bu kaynak koddan tum API endpoint'leri, WebSocket komutlari, authentication flow'u, ve internal routing yapisi cikarilmistir. Ayni SPA, hem [vendor] ([vendor]) hem de SEAGM (seagm.com) icin kullanilmakta olup "SEAGM LiveChat" ola CVSS 6.5 | Gaming Marketplace Global | WebSocket Issues | HackerOne | Medium | 2026-03 |
| MEDIUM -- Login Form Missing CSRF Token -- Login CSRF Attack member.[vendor]/login sayfasindaki login formu, herhangi bir CSRF korumasina sahip degildir -- ne hidden CSRF token field'i, ne de SameSite cookie korumasina sahiptir (member.[vendor]'da cookie SameSite attribute'u YOK). Bu, saldirganin kurbanin tarayicisinda saldirganin kendi hesabiyla login yapmasina olanak tanir (Login CSRF). Kurbanin son CVSS 6.5 | Gaming Marketplace Global | Business Logic | HackerOne | Medium | 2026-03 |
| Navigation JSON Leaks Admin User IDs, Internal Category Structure, and DynamoDB Schema The publicly accessible navigation.json file at assets.[vendor] exposes the complete internal category tree including admin user IDs who made updates, DynamoDB partition/sort key schema (pk, sk fields), internal category UUIDs, INACTIVE/hidden categories, product counts, and timestamps. This data enables reconnaissance for privilege escalat CVSS 6.5 | SEA Gaming Marketplace SEA | Privilege Escalation | HackerOne | Medium | 2026-03 |
| Full Source Code Exposure via Source Maps (623 Files, 9.4 MB) The production JavaScript bundles at app.[vendor] have corresponding .map (source map) files publicly accessible. These files contain the complete original source code of the frontend application — 623 files totaling 9.4 MB. This includes all API endpoint paths, all business logic, admin routes, permission systems, internal comments, and e CVSS 6.5 | Crypto Gaming Platform Global | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| Staging Application Accessible Without CF Access [vendor] and [vendor] Staging Applications Publicly Accessible Without Cloudflare Access Authentication CVSS 6.5 | LATAM Crypto Platform LATAM | Access Control | HackerOne | Medium | 2026-03 |
| Router Pentest [ip] Router Penetration Test Report - [ip] Hedef: [ip] (Yerel ag gateway/router) Yetkilendirme: Yetkili pentest, yerel ag | Uretici | Huawei Technologies Co., Ltd. | CVSS 6.5 | Router Infrastructure Global | Rate Limit Bypass | Responsible Disclosure | Medium | 2026-03 |
| SSTI Payload Stored via Contact Form (CVE-2024-31447) Shopware CVE-2024-31447 SSTI triggerable via contact form storage. CVSS 6.1 | EU Gaming Marketplace EU | SSTI | Responsible Disclosure | Medium | 2026-03 |
| Heroku Subdomain Takeover Possibility Referenced Heroku subdomain is unclaimed allowing attacker to register and serve content under the target domain. CVSS 6.1 | African Crypto Infrastructure Africa | Subdomain Takeover | Responsible Disclosure | Medium | 2026-03 |
| Sentry Internal Configuration Data Leak The Sentry login page leaks extensive internal configuration data in the __initialData JavaScript object, accessible without authentication CVSS 6.1 | NA Gift Card Supplier NA | Privilege Escalation | Responsible Disclosure | Medium | 2026-03 |
| AWS API Gateway with CORS Wildcard () on sls.[vendor] The serverless API at sls.[vendor] (AWS API Gateway + CloudFront) returns Access-Control-Allow-Origin: with full method and header permissions, allowing any website to make cross-origin requests to the API CVSS 6.1 | SEA Gaming Marketplace SEA | CORS | HackerOne | Medium | 2026-03 |
| CORS Wildcard on Production API The production API at api.[vendor] returns Access-Control-Allow-Origin: on all API endpoints, including the admin dashboard API. This allows any website to make cross-origin requests to the API CVSS 6.1 | SEA E-Commerce Platform SEA | CORS | Responsible Disclosure | Medium | 2026-03 |
| Digest Auth MD5-only with Nonce Timestamp Leakage Digest authentication uses MD5 only and nonce encodes server timestamp enabling replay windows. CVSS 5.9 | CCTV Infrastructure Global | Broken Authentication | Responsible Disclosure | Medium | 2026-03 |
| XMLRPC pingback.ping SSRF pingback.ping XMLRPC method'u aktif. Sunucu, istenen herhangi bir URL'ye HTTP request gonderiyor. Bu, internal network scanning ve SSRF saldirisi icin kullanilabilir CVSS 5.8 | EU Digital Goods Marketplace EU | SSRF | Responsible Disclosure | Medium | 2026-03 |
| admin.[redacted].com - Admin Panel Source Map Exposure [MEDIUM] Finding 2: admin.[redacted].com - Admin Panel Source Map Exposure [MEDIUM] `admin.[redacted].com` is [redacted]'s internal admin panel for managing clients, KYC applications, merchants, and bank integrations. The webpack source map is publicly accessible, exposing 129 source files includi CVSS 5.8 | SEA Fintech SEA | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| MEDIUM - Order Generation DoS via paySmart2D Repeated Invalid Hash Requests Finding 59: MEDIUM - Order Generation DoS via paySmart2D Repeated Invalid Hash Requests Summary: paySmart2D endpoint'i her basarisiz hash_key denemesinde veritabaninda yeni bir order kaydi (order_no) olusturuyor. Saldirgan rate limit olmadan binlerce istek gonderip veritabanini g CVSS 5.8 | Turkish Payment Gateway MENA | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| Security Finding Platform WAF/CDN arkasında DEĞİL (doğrudan IP: [ip]), bu da saldırıyı kolaylaştırır. 1. Saldırgan `[target]` üzerinde exploit sayfası hazırlar 2. [redacted] admin'ine phishing email gönderir (örn: "Yeni sunucu sipariş durumu") 3. Admin linki tıkladığında, browser otomatik ol CVSS 5.8 | Web Hosting Provider EU | Credential Exposure | Responsible Disclosure | Medium | 2026-03 |
| P-2: CORS Wildcard on API Subdomains (MEDIUM) Finding P-2: CORS Wildcard on API Subdomains (MEDIUM) Endpoint: `api.[redacted].com`, `currency-api.[redacted].com`, `liquidity-api.[redacted].com` Note: `currency-api.[redacted].com` has the dangerous combination of `Access-Control-Allow-Origin: ` WITH `Access-Control-Allow-Credentials: CVSS 5.8 | African Neobank Africa | CORS | Responsible Disclosure | Medium | 2026-03 |
| [MEDIUM] - Staging API CORS Wildcard Misconfiguration Finding 2 [MEDIUM] - Staging API CORS Wildcard Misconfiguration Summary: The staging API at `apiprostaging.[redacted].africa` responds with `Access-Control-Allow-Origin: ` for all origins, combined with accepting all methods and headers including `Authorization`. Vulnerable Endpoint: ` CVSS 5.8 | DeFi Lending/DEX Protocol Global | CORS | Responsible Disclosure | Medium | 2026-03 |
| Unauthenticated ThirdParty Profile Creation on Production [MEDIUM] Finding 6: Unauthenticated ThirdParty Profile Creation on Production [MEDIUM] - POST /api/ThirdParty/CreateThirdPartyProfileOnProd - POST /api/LiquidityProviderRegistration/Initiate ThirdParty profil olusturma endpoint'i authentication olmadan erisilebilir. Dogru parametreler sag CVSS 5.8 | African DeFi Protocol Africa | Business Logic | Responsible Disclosure | Medium | 2026-03 |
| Security Finding 1. Production service running in "development" mode — `env: "development"` on `.svc.[redacted].co` 2. PEP screening methodology exposed — strict/fuzzy matching logic, country filtering, keyword search 3. Conviction check API — Criminal record screening endpoint structure revealed CVSS 5.8 | African KYC Provider Africa | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| Sandbox API 500 Error (Unhandled Exception) [MEDIUM] Finding 5: Sandbox API 500 Error (Unhandled Exception) [MEDIUM] - URL: `https://[target]/` - Response: `{"code":"500","description":"An unexpected system error occurred","status":false}` - Impact: Sandbox environment exposed with unhandled errors CVSS 5.8 | Crypto Fintech Mass Scan Global | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| Bounty Platformlari - [[redacted] DAO - HackerOne](https://[target]/[redacted]_dao) - [JustLend DAO - Immunefi](https://[target]/bounty/justlenddao/) - [ChainSecurity Java-[redacted] Audit](https://[target]/security-audit/java-[redacted]) - [dWallet Labs Multisig PoC](https://[target]/dwallet-labs/t CVSS 5.8 | L1 Smart Contract Global | Information Disclosure | HackerOne | Medium | 2026-03 |
| MEDIUM - Invoice Share Link Endpoint Processes Without Auth (Unauthenticated Error Oracle) Finding 38: MEDIUM - Invoice Share Link Endpoint Processes Without Auth (Unauthenticated Error Oracle) Severity: Medium (CVSS 5.3 - AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) Summary: `/invoices-share-with-link/{link}` endpoint'i JWT gerektirmeden istekleri isler (diger 239 endpoint'in CVSS 5.8 | Turkish Payment Gateway MENA | S3 Misconfig | Responsible Disclosure | Medium | 2026-03 |
| [redacted] Staging Infrastructure Exploitation Security finding identified during authorized security assessment. CVSS 5.8 | African Payment Gateway Africa | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| Wildcard CORS on Main Domain (Informational) Finding 6: Wildcard CORS on Main Domain (Informational) `www.[redacted].am`, `sport.[redacted].am`, and `go-cms.[redacted].am` all return `Access-Control-Allow-Origin: ` without `Access-Control-Allow-Credentials: true`. While this is not exploitable for authenticated requests (browsers won't send CVSS 5.8 | EU iGaming Operator EU | Credential Exposure | Responsible Disclosure | Medium | 2026-03 |
| [MEDIUM] - Staging API Accessible (apiprostaging.[redacted].africa) Finding 3 [MEDIUM] - Staging API Accessible (apiprostaging.[redacted].africa) Summary: The staging API at `apiprostaging.[redacted].africa/api/` is publicly accessible and returns structured JSON responses for all admin endpoints (HTTP 400 with auth error, not 404). This confirms the API is CVSS 5.8 | DeFi Lending/DEX Protocol Global | RCE | Responsible Disclosure | Medium | 2026-03 |
| Admin 2FA Configuration Exposure [MEDIUM] Finding 5: Admin 2FA Configuration Exposure [MEDIUM] Endpoint: GET /api/Admin/TwoFA/Configurations Admin panelinin 2FA konfigurasyonu authentication olmadan erisilebilir durumdadir. Sistem tarafindan kullanilan 2FA provider'lari, ID'leri ve aktiflik durumlari ifsa olmaktadir. - 2 CVSS 5.8 | African DeFi Protocol Africa | Admin Panel Exposure | Responsible Disclosure | Medium | 2026-03 |
| Drone CI v2.25.0 Publicly Accessible CI server UI reachable without auth, exposing repo and build metadata. CVSS 5.5 | SEA Banking API Platform SEA | Admin Panel Exposure | Responsible Disclosure | Medium | 2026-03 |
| Webhook Degisikligi OTP Gerektirmiyor Webhook Degisikligi OTP Gerektirmiyor CVSS 5.4 | Crypto Gaming Platform Global | JWT Issues | Responsible Disclosure | Medium | 2026-03 |
| Deposit Limit Double-Subtraction Bypass in Reserve Accounting cash_reserve is subtracted twice in the deposit_limit_breached check, effectively raising the admin-configured deposit cap. CVSS 5.3 | Sui L1 Lending Protocol Global | Rounding | Sherlock | Medium | 2026-03 |
| Zero-Amount Claims Bypass Per-Epoch Reward Claim Flag Claimed status inferred from reward amount > 0, so users with zero-reward epochs can re-claim later when inputs change. CVSS 5.3 | Ethereum Attestation Protocol Global | Business Logic | Code4rena | Medium | 2026-03 |
| PHPSESSID Cookie Without HttpOnly + SameSite=None Session cookie missing HttpOnly flag and SameSite=None enabling XSS theft and CSRF. CVSS 5.3 | Global P2P Crypto Marketplace Global | Broken Authentication | Responsible Disclosure | Medium | 2026-03 |
| Email Enumeration via user-mgm API user-mgm endpoint returns differential errors confirming registered emails. CVSS 5.3 | SEA Banking API Platform SEA | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| Unauthenticated User Registration (Progressive Field Disclosure) Registration service reveals required fields through error messages allowing structured enumeration. CVSS 5.3 | SEA Banking API Platform SEA | Business Logic | Responsible Disclosure | Medium | 2026-03 |
| Singular Attribution SDK Credentials Exposed Singular SDK key in bundle allows impersonating attribution events. CVSS 5.3 | African Fintech Neobank Africa | API Key Exposure | Responsible Disclosure | Medium | 2026-03 |
| Ory Kratos Self-Service API Unrestricted Registration Self-service registration accepts unlimited requests without captcha or throttling. CVSS 5.3 | African Bitcoin Lightning Provider Africa | Rate Limit Bypass | Responsible Disclosure | Medium | 2026-03 |
| SensorsData Event Injection Verified Three SensorsData endpoints accept unauthenticated analytics events enabling log poisoning. CVSS 5.3 | Global P2P Crypto Marketplace Global | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| New Relic License Key + App ID Exposed zeusx.com bundle exposes New Relic license key and app ID. CVSS 5.3 | Game Top-Up Platform Global | API Key Exposure | Responsible Disclosure | Medium | 2026-03 |
| S3 Bucket Name + Password Salt Exposed in JS coincola.com bundle reveals S3 bucket names and password-hashing salt. CVSS 5.3 | Global P2P Crypto Marketplace Global | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| Source Map Exposure on Frontend + Admin CRA source maps served publicly leaking admin routes and secrets. CVSS 5.3 | African Crypto Trading Platform Africa | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| Internal Error Codes & Redis Reset Public endpoints expose internal error codes and Redis tracking reset. CVSS 5.3 | African KYC/Identity Provider Africa | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| Microservice Naming Disclosure via Source hms/hpms/homs/hums microservice hostnames visible in frontend. CVSS 5.3 | Asian Gift-Card Marketplace SEA | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| Email Enumeration via Register Endpoint EMAIL_ALREADY_TAKEN error discloses account existence. CVSS 5.3 | EU iGaming Operator EU | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| WordPress Internal API Unauthenticated Exchange Rate Refresh Unauthenticated endpoint can refresh cached exchange rates, enabling cache pollution. CVSS 5.3 | European Crypto Payment Gateway EU | Access Control | Responsible Disclosure | Medium | 2026-03 |
| OpenCart Callback Token in URL Query String Token transmitted in URL query string, appearing in web server access logs and referrer headers. CVSS 5.3 | European Crypto Payment Processor EU | Credential Exposure | Responsible Disclosure | Medium | 2026-03 |
| Mass Source Map Exposure Across Payment Providers Paybis, Kuda and others serve production source maps with full frontend source. CVSS 5.3 | Global Crypto Broker Cluster Global | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| CORS Misconfiguration on Blog API Blog API allows arbitrary origin with credentials. CVSS 5.3 | Indian Crypto Exchange SEA | CORS | Responsible Disclosure | Medium | 2026-03 |
| Unauthenticated Source Code / JavaScript Disclosure Firmware UI exposes JavaScript and 439 ISAPI endpoint URLs without authentication. CVSS 5.3 | CCTV Infrastructure Global | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| Pusher Real-time Credentials Exposed Pusher app key/cluster exposed allowing event injection into real-time dashboards. CVSS 5.3 | African Payment Gateway Africa | API Key Exposure | Responsible Disclosure | Medium | 2026-03 |
| Unauthenticated API Data Access (User Profiles) Offers and profile endpoints reveal counterparty identities without authentication. CVSS 5.3 | African P2P Crypto Platform Africa | IDOR | Responsible Disclosure | Medium | 2026-03 |
| Semicolon Path Traversal Bypasses API Gateway Filtering Semicolon segment normalization differs between gateway and Spring Boot enabling bypass to backend actuator paths. CVSS 5.3 | EU Student Banking Fintech EU | Path Traversal | Responsible Disclosure | Medium | 2026-03 |
| Hardcoded Content API Key in Client JavaScript Content API key hard-coded in frontend enables replay against backend though lacks additional privileges. CVSS 5.3 | CIS Streaming Platform MENA | API Key Exposure | Responsible Disclosure | Medium | 2026-03 |
| Third-Party Payment/KYC Integration Architecture Full Leak Registration ve profile API'leri [vendor]'in kullandigi tum ucuncu parti servis entegrasyonlarini ortaya koyuyor. Bu bilgi rakip analizi, hedefli saldirilar ve social engineering icin kullanilaabilir CVSS 5.3 | African Remittance Platform Africa | KYC Bypass | Responsible Disclosure | Medium | 2026-03 |
| Ramp API Authentication Bypass — JWT Token Without User Auth ramp.[vendor] ramp/auth Endpoint Issues JWT Session Tokens Without Any User Authentication CVSS 5.3 | LATAM Crypto Platform LATAM | JWT Issues | HackerOne | Medium | 2026-03 |
| Firebase Configuration & Google Analytics Tracking ID Exposed All admin panel JavaScript bundles contain the complete Firebase project configuration including API key, project ID, storage bucket, messaging sender ID, app ID, and measurement ID. This is shared across admin.[vendor] and subadmin.[vendor] CVSS 5.3 | SEA E-Commerce Platform SEA | Firebase Misconfig | Responsible Disclosure | Medium | 2026-03 |
| Guvenlik Bulgulari Detay: Port 554 (RTSP) TCP baglantisi kabul ediyor ancak hemen Connection Reset by Peer donuyor. Bu davranis birden fazla sebepten kaynaklanabilir CVSS 5.3 | CCTV Infrastructure Global | Auth Bypass | HackerOne | Medium | 2026-03 |
| Unauthenticated Payment Infrastructure & Business Logic Disclosure Vulnerable Endpoint: https://[vendor]/api/deposit CVSS 5.3 | EU Gaming Marketplace EU | Business Logic | Responsible Disclosure | Medium | 2026-03 |
| Comprehensive API Endpoint Exposure via JavaScript Bundle Analysis Vulnerable Endpoint: https://[vendor]static.com/_nuxt/ad02966.js (467KB main bundle) CVSS 5.3 | EU Gaming Marketplace EU | WebSocket Issues | Responsible Disclosure | Medium | 2026-03 |
| GraphQL Full Schema Introspection Enabled Without Authentication Finding 1: GraphQL Full Schema Introspection Enabled Without Authentication Summary: The production GraphQL API at `api.[redacted].money/graphql` allows FULL schema introspection without any authentication. This exposes the complete API architecture including 817 types (310 objects, CVSS 5.3 | African Payment Gateway Africa | Credential Exposure | Responsible Disclosure | Medium | 2026-03 |
| Binance OAuth Client ID + Permission Scopes Exposed via Unauthenticated API Finding 44: Binance OAuth Client ID + Permission Scopes Exposed via Unauthenticated API Endpoint: `GET https://www.[redacted].com/v1/binance/oauth` The Binance OAuth integration configuration is exposed via an unauthenticated GET request, revealing the OAuth client_id (`80EvkbrBg CVSS 5.3 | SEA Crypto Exchange SEA | Subdomain Takeover | Responsible Disclosure | Medium | 2026-03 |
| Customer Email Enumeration via Login (MEDIUM, CVSS 5.3) Finding 11: Customer Email Enumeration via Login (MEDIUM, CVSS 5.3) - "No matching customer" vs "Invalid username" error differential - 6 confirmed accounts: support@, marketing@, office@, szymon.osadowski@, test@, test1@[redacted].com CVSS 5.3 | Gaming Marketplace EU | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| Admin API Endpoint Structure Fully Enumerated with Method D[redacted]s Finding 10: Admin API Endpoint Structure Fully Enumerated with Method D[redacted]s Severity: Medium (CVSS 5.3 - AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) Through OPTIONS requests to each admin endpoint, the complete method structure of the admin API has been mapped. While endpoints require CVSS 5.3 | NA Online Casino NA | Rate Limit Bypass | Responsible Disclosure | Medium | 2026-03 |
| MinIO Console Publicly Accessible (MEDIUM) Finding 1: MinIO Console Publicly Accessible (MEDIUM) URL: https://minio-console.blix.gg/ MinIO Console (AGPL lisansli) internet uzerinden erisime acik. Login formu gorunuyor: - Login strategy: "form" (username/password) CVSS 5.3 | KYC Mass Scan Global | Rate Limit Bypass | Responsible Disclosure | Medium | 2026-03 |
| Blog Internal API URL Disclosure (API_INNER_URL) (MEDIUM) Finding 5: Blog Internal API URL Disclosure (API_INNER_URL) (MEDIUM) Summary: Blog'un Nuxt.js SSR publicRuntimeConfig'i, dahili API URL'sini (`http://[ip]:7008`) ifsa etmektedir. Bu bilgi SSRF saldirilarinda kullanilabilir. Vulnerable Endpoint: `https://blog.[redacted].store/` (SS CVSS 5.3 | SEA Crypto Exchange SEA | SSRF | Responsible Disclosure | Medium | 2026-03 |
| Yii2 Framework Debug Information Disclosure on dev-account-api.[redacted].com (MEDIUM) Finding 3: Yii2 Framework Debug Information Disclosure on dev-account-api.[redacted].com (MEDIUM) Summary: The development account API at dev-account-api.[redacted].com leaks full Yii2 framework exception d[redacted]s including PHP class names, exception types, and error messages. This CVSS 5.3 | Gaming Marketplace SEA | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| [redacted]_CODE_BLOCKING_LIMIT_OVERRIDE - Context Window Limit Bypass Finding 1: [redacted]_CODE_BLOCKING_LIMIT_OVERRIDE - Context Window Limit Bypass Summary: The `[redacted]_CODE_BLOCKING_LIMIT_OVERRIDE` environment variable allows overriding the blocking limit for context window size, potentially allowing users to send larger context windows than their CVSS 5.3 | AI SaaS Provider NA | RCE | Responsible Disclosure | Medium | 2026-03 |
| Staging Environment Shares Production Database and Backend Finding 6: Staging Environment Shares Production Database and Backend Severity: MEDIUM (CVSS 5.3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) Summary: `staging.[redacted].cc` ayni production backend ve veritabanina baglidir. Staging uzerinde bulunan tum vulnerability'ler dogrud CVSS 5.3 | NA Online Casino NA | Rate Limit Bypass | Responsible Disclosure | Medium | 2026-03 |
| WordPress Directory Listing Active 2021-2026 Apache directory listing exposes WP upload tree including pum-debug log. CVSS 5.0 | Global P2P Crypto Marketplace Global | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| Unauthenticated User Report Submission Enables Abuse User report endpoint accepts anonymous submissions allowing mass false-reports against traders. CVSS 5.0 | Global P2P Crypto Marketplace Global | Business Logic | Responsible Disclosure | Medium | 2026-03 |
| WordPress Blog User Enumeration + XML-RPC Enabled WP blog permits author enumeration and XML-RPC amplification. CVSS 5.0 | African Fintech Neobank Africa | Information Disclosure | Responsible Disclosure | Medium | 2026-03 |
| Cached Feature Flags (GrowthBook + Statsig) - Local Tampering Finding 2: Cached Feature Flags (GrowthBook + Statsig) - Local Tampering Summary: Billing-relevant feature flags are cached in plaintext JSON in `~/.[redacted].json` (GrowthBook) and `~/.[redacted]/statsig/statsig.cached.evaluations.` (Statsig). These can be modified locally. - `~/.claud CVSS 5.0 | AI SaaS Provider NA | RCE | Responsible Disclosure | Medium | 2026-03 |
| Password Reset Endpoint Without Rate Limit Unlimited password reset triggers enable inbox flooding at scale. CVSS 4.3 | SEA Banking API Platform SEA | Rate Limit Bypass | Responsible Disclosure | Medium | 2026-03 |
| Open Redirect on Email Verify Endpoint Verify endpoint honors unvalidated `returnUrl`, usable for phishing via branded domain. CVSS 4.3 | Indian Crypto Exchange SEA | Open Redirect | Responsible Disclosure | Low | 2026-04 |
| Email Verification Token Returned in Response Body Registration response contains verification token removing need for email access. CVSS 4.3 | African Fintech Neobank Africa | Broken Authentication | Responsible Disclosure | Low | 2026-04 |
| Differential Error Messages Reveal Account Existence Login/signup endpoints use distinct error strings aiding enumeration. CVSS 4.3 | African Fintech Neobank Africa | Information Disclosure | Responsible Disclosure | Low | 2026-04 |
| LOW - Storage Subdomain Active Finding 6: LOW - Storage Subdomain Active URL: `https://storage.[redacted].site` - Returns 403 (storage server exists) - `[redacted].site` - Main landing (Netlify) - `app.[redacted].site` - User app (Netlify) CVSS 3.8 | Mixed Platforms Global | Information Disclosure | Responsible Disclosure | Low | 2026-04 |
| gtws.bareksa Legacy Subdomain With Old PHP Login/Register Legacy trading gateway still serves login/register on EOL PHP version without modern hardening. CVSS 3.7 | SEA Investment Platform SEA | Information Disclosure | Responsible Disclosure | Low | 2026-04 |
| No Rate Limiting on OAuth Token Endpoint Token endpoint accepts unlimited failed attempts enabling credential stuffing. CVSS 3.7 | EU Crypto ATM Operator EU | Rate Limit Bypass | Responsible Disclosure | Low | 2026-04 |
| Spark Plan Transition Vulnerability Window Files cannot download on Spark but upgrade to Blaze would expose all content. CVSS 3.7 | African Crypto Trading Mobile App Africa | Cloud Misconfig | Responsible Disclosure | Low | 2026-04 |
| Subdomain Infrastructure Disclosure (11 subs) 11 subdomains including accounting, crm, payment visible via DNS. CVSS 3.7 | African Digital Platform Africa | Information Disclosure | Responsible Disclosure | Low | 2026-04 |
| Source Map Exposure on Shipping Dashboard (CRA + maps) topship dashboard exposes CRA source maps; 24 JS files with original sources. CVSS 3.7 | African Fintech Cohort Africa | Information Disclosure | Responsible Disclosure | Low | 2026-04 |
| Tushop Current - Storage Open (non-PII) Current Tushop project Storage bucket readable but without PII. CVSS 3.7 | African Fintech Firebase Cohort Africa | Firebase Misconfig | Responsible Disclosure | Low | 2026-04 |
| Grafana v11.6.0 /metrics Endpoint Public stashfin Grafana exposes Prometheus metrics without authentication. CVSS 3.7 | African Fintech Metabase Cohort SEA | Information Disclosure | Responsible Disclosure | Low | 2026-04 |
| JWT Error Message Enumeration on Staging Auth JWT validation errors differentiate signature vs expiry enabling token probing. CVSS 3.7 | African Investment Fintech Africa | Information Disclosure | Responsible Disclosure | Low | 2026-04 |
| MongoDB Error Stack Trace Leakage Backend errors expose MongoDB collection and path information. CVSS 3.7 | African P2P Crypto Settlement Africa | Information Disclosure | Responsible Disclosure | Low | 2026-04 |
| Odoo ERP Integration Hostnames Exposed Odoo integration endpoints visible in settings. CVSS 3.7 | African Pharma B2B Platform Africa | Information Disclosure | Responsible Disclosure | Low | 2026-04 |
| Sentry DSN Exposed on Dashboard Sentry DSN exposed in production bundle enabling event injection. CVSS 3.7 | Crypto Payment Infrastructure Global | Credential Exposure | Responsible Disclosure | Low | 2026-04 |
| CORS Wildcard on Production + Dev API Both prod and dev APIs return ACAO:*. CVSS 3.7 | L1 Smart Contract Global | CORS | Responsible Disclosure | Low | 2026-04 |
| Broffice Redirect to Main App (Exposure) Back-office subdomain 302 reveals internal naming convention. CVSS 3.7 | LATAM Crypto Platform LATAM | Information Disclosure | Responsible Disclosure | Low | 2026-04 |
| Laravel Framework Information Disclosure Error pages reveal Laravel framework usage and _debugbar path. CVSS 3.7 | MENA Payment Giant MENA | Information Disclosure | Responsible Disclosure | Low | 2026-04 |
| Hardcoded PostHog/3rd-Party Analytics Keys Frontend exposes analytics project tokens usable for event injection. CVSS 3.7 | MENA Regulated Crypto Exchange MENA | Credential Exposure | Responsible Disclosure | Low | 2026-04 |
| Extensive Infrastructure Subdomain Exposure Large set of internal-looking subdomains resolve publicly disclosing infrastructure architecture. CVSS 3.7 | MENA Super-App Fintech MENA | Information Disclosure | Responsible Disclosure | Low | 2026-04 |
| Deep Link Scheme Hijacking Custom URL schemes [vendor]:// and bitstore:// registered without proper validation. A malicious app can register the same scheme for intent hijacking CVSS 3.7 | EU Crypto Exchange EU | Business Logic | Responsible Disclosure | Low | 2026-04 |
| Production Environment Variables Hardcoded in JavaScript Source: radar.[vendor]/static/js/main.ce51035c.js CVSS 3.7 | African Identity Verification Africa | Credential Exposure | Responsible Disclosure | Low | 2026-04 |
| AWS Account ID Disclosure via S3 Error [LOW] [vendor]-documents S3 bucket'ina yapilan isteklerde AWS Account ID (935364935069) hata mesajinda ifsa edilmektedir. Bu bilgi, IAM role enumeration ve cross-account saldirlar icin kullanilabilir CVSS 3.7 | Crypto Payment Processor Global | S3 Misconfig | Responsible Disclosure | Low | 2026-04 |
| CSRF Token Static/Long-lived Within Session [LOW] Vulnerable Component: All authenticated forms CVSS 3.7 | Crypto Exchange Platform Global | Business Logic | HackerOne | Low | 2026-04 |
| MapTiler API Key Without Domain Restriction Hardcoded MapTiler key lacks referer restrictions enabling quota abuse. CVSS 3.1 | European Payment Gateway EU | API Key Exposure | Responsible Disclosure | Low | 2026-04 |
| Yonetici Ozeti 192.168.100.0/24 aginda ARP spoofing MITM saldirisi audit'i yapildi. Ag uzerinde 31 aktif cihaz tespit edildi. IP forwarding'in zaten aktif oldugu (net.inet.ip.forwarding=1) ve agin ARP spoofing'e karsi hicbir koruma mekanizmasinin bulunmadigi belirlendi. Script hazirlandi ve 10 hedef cihazin tamami aktif olarak dogrulandi. Root yetkisi ile cali CVSS 3.1 | CCTV Infrastructure Global | Business Logic | Responsible Disclosure | Low | 2026-04 |
| Breach Notification Urgency Critical factors: 1. Breach is ACTIVE -- data is being uploaded to public buckets right now 2. userkycdoc allows DELETE -- attacker could destroy KYC records 3. userkycdoc allows WRITE -- attacker could inject fraudulent KYC documents 4. Government IDs exposed -- identity theft risk is immediate and irreversible 5. Biometric data cannot be "chan CVSS 3.1 | Global Crypto Exchange Global | KYC Bypass | Responsible Disclosure | Low | 2026-04 |
| Google OAuth Misconfiguration (Strapi) Google OAuth configured with localhost redirect URI: - Client ID: 610914703543-ifqukul5a6o7870l8s3nn77okq16qacl.apps.googleusercontent.com - Redirect URI: http://localhost:1337/api/connect/google/callback CVSS 3.1 | African SME Lender Africa | Firebase Misconfig | Responsible Disclosure | Low | 2026-04 |
| Intercom HMAC User Hash Exposed in API Response Identity hash returned in API response can be misused to impersonate authenticated users in Intercom. CVSS 2.1 | European Payment Gateway EU | Credential Exposure | Responsible Disclosure | Low | 2026-04 |
| [target] - SonarQube v10.0.0 Exposed [LOW] Finding 4: [target] - SonarQube v10.0.0 Exposed [LOW] `[target]` runs SonarQube v10.0.0 and is accessible from the internet. While authentication is required and no public projects were found, the exposed version information aids reconnaissance. Additional [target] CVSS 3.8 | SEA Fintech SEA | Information Disclosure | Responsible Disclosure | Low | 2026-03 |
| LOW - POS Configuration and Dynamic Hash Key Generation Exposure via getpos Finding 42: LOW - POS Configuration and Dynamic Hash Key Generation Exposure via getpos Severity: Low (CVSS 4.3 - AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) Summary: `/ccpayment/api/getpos` endpoint'i, her istek icin farkli kart BIN'leri ve miktarlar bazinda unik POS konfigurasyonu ve CVSS 3.8 | Turkish Payment Gateway MENA | Information Disclosure | Responsible Disclosure | Low | 2026-03 |
| [LOW] - Missing Security Headers on Admin Panel Finding 4 [LOW] - Missing Security Headers on Admin Panel Summary: The admin panel at admin.[redacted].finance lacks critical security headers. - `X-Frame-Options` - Allows clickjacking attacks - `Content-Security-Policy` - No CSP protection CVSS 3.8 | DeFi Lending/DEX Protocol Global | Admin Panel Exposure | Responsible Disclosure | Low | 2026-03 |
| [redacted] Phase2 Findings 1. Saldirgan [redacted].com'da bir hesap olusturur (normal kullanici) 2. Authenticated session ile /[redacted]'a erisir 3. [redacted] UI tum API endpoint'lerini, parametrelerini ve data model'lerini gosterir 4. /graphql ile tum GraphQL schema'si kesfedilebilir (introspection) CVSS 3.8 | Gaming Marketplace SEA | Information Disclosure | Responsible Disclosure | Low | 2026-03 |
| Missing Security Headers (Low) Finding 3: Missing Security Headers (Low) Multiple security-critical HTTP headers are missing across all `.[redacted].am` domains: | Header | www.[redacted].am | cms.[redacted].am | go-cms.[redacted].am | |--------|------------|-------------|----------------| CVSS 3.8 | EU iGaming Operator EU | XSS | Responsible Disclosure | Low | 2026-03 |
| LOW - Merchant Panel Login Form Action URL Leaks Backend Architecture (app.[redacted].[target]/merchant) Finding 42: LOW - Merchant Panel Login Form Action URL Leaks Backend Architecture (app.[redacted].[target]/merchant) Summary: merchant.[redacted].[target] login sayfasi, form action URL'si ve asset yollari araciligiyla backend mimarisini (Laravel CSRF token, adminca theme, app.[redacted].[target]/mer CVSS 3.8 | Turkish Payment Gateway MENA | CORS | Responsible Disclosure | Low | 2026-03 |
| [LOW] - Third-Party API Keys Exposed Finding 5 [LOW] - Third-Party API Keys Exposed Summary: Multiple third-party API keys are embedded in the admin JavaScript: | TinyMCE | `8pcipe5hjq4vkklqt7jhaiphdwc00w1qa893u7mqwmd12g1r` | Active | | Blocknative | `a7f90c48-943a-4d3a-a8df-6ca5d0f7522a` | Active | CVSS 3.8 | DeFi Lending/DEX Protocol Global | API Key Exposure | Responsible Disclosure | Low | 2026-03 |
| ASP.NET Stack Trace Disclosure Server returns full .NET stack traces on error including file paths. CVSS 3.7 | African Crypto Trading Platform Africa | Information Disclosure | Responsible Disclosure | Low | 2026-03 |
| Mixdesk Chat Integration Session Leak Mixdesk chat bundles session IDs in URL. CVSS 3.7 | Asian Gift-Card Marketplace SEA | Information Disclosure | Responsible Disclosure | Low | 2026-03 |
| Customer ID/Hash Disclosure on Registration Registration response leaks customer ID and hash. CVSS 3.7 | EU Gaming Marketplace EU | Information Disclosure | Responsible Disclosure | Low | 2026-03 |
| WordPress User Enumeration + SAML SSO Workspace ID 6 users enumerable via WP REST; Google Workspace domain customer ID leaked. CVSS 3.7 | European Crypto Payment Gateway EU | Information Disclosure | Responsible Disclosure | Low | 2026-03 |
| PrestaShop Error Message Token Leak Error messages echo callback tokens back, aiding token recovery via forced errors. CVSS 3.7 | European Crypto Payment Processor EU | Information Disclosure | Responsible Disclosure | Low | 2026-03 |
| Hardcoded Hangfire Dashboard Path Hangfire dashboard path discoverable via source map. CVSS 3.7 | Gaming Marketplace EU | Admin Panel Exposure | Responsible Disclosure | Low | 2026-03 |
| Client IP Disclosure via mtc-customerip Header Five subdomains return the real client IP address in the mtc-customerip response header and country code in mtc-country CVSS 3.7 | EU Gaming Key Marketplace EU | CORS | Responsible Disclosure | Low | 2026-03 |
| Chatwoot /auth/password/new - 500 Internal Server Error The Chatwoot password reset page at /auth/password/new returns a 500 Internal Server Error, indicating a misconfiguration (likely SMTP/email not properly configured for password reset emails) CVSS 3.7 | NA Gift Card Supplier NA | Admin Panel Exposure | Responsible Disclosure | Low | 2026-03 |
| LOW - Third-Party API Keys Exposed CVSS 3.7 | African Payment Processor Africa | API Key Exposure | Responsible Disclosure | Low | 2026-03 |
| WooCommerce on Help Center - Unnecessary Attack Surface help.[vendor] (yardim merkezi) uzerinde WooCommerce 9.1.0 yuklu. Bir yardim merkezi icin e-ticaret plugin'i gereksiz bir saldiri yuzeyi olusturur. WooCommerce REST API v1/v2/v3 endpointleri ve 200+ route acik CVSS 3.7 | African Remittance Platform Africa | Rate Limit Bypass | Responsible Disclosure | Low | 2026-03 |
| Apache Server Version Disclosure Apache versiyonu response header'larinda ve hata sayfalarinda aciga cikiyor: Apache/2.4.58 (Ubuntu) CVSS 3.7 | EU Digital Goods Marketplace EU | Business Logic | Responsible Disclosure | Low | 2026-03 |
| API Documentation Publicly Accessible documentation.[vendor] uzerinde barindirilan API dokumanasyonu (ReadMe.io), HMAC-SHA256 kimlik dogrulama akisi, API-Hash header olusturma yontemleri ve tum endpoint detaylarini acik olarak paylasmaktadir CVSS 3.7 | African Crypto Exchange Africa | Business Logic | Responsible Disclosure | Low | 2026-03 |
| Alibaba Cloud ARMS RUM Monitoring PID Exposed -- Application Monitoring Data Leakage Risk KChat Vue.js SPA'sinda Alibaba Cloud ARMS (Application Real-time Monitoring Service) yapilandirmasi, monitoring PID'si ve data endpoint'i acik olarak ifsa edilmektedir. Bu bilgi, monitoring verilerine erisim veya veri enjeksiyonu icin kullanilabilir CVSS 3.7 | Gaming Marketplace Global | Business Logic | HackerOne | Low | 2026-03 |
| Akamai WAF Bypass via Differential Response The Akamai WAF on account-api.[vendor] exhibits differential behavior based on headers. Without auth headers, the request reaches the Yii2 backend (404 JSON). With Authorization: Bearer or X-API-Key headers, Akamai intercepts and returns a 403 Access Denied page. This reveals WAF rule logic CVSS 3.7 | SEA Gaming Marketplace SEA | Business Logic | HackerOne | Low | 2026-03 |
| Strapi CMS Instance Information Disclosure Vulnerable Endpoint: https://strapi.[vendor]/ CVSS 3.7 | EU Gaming Marketplace EU | Information Disclosure | Responsible Disclosure | Low | 2026-03 |
| 15+ Microservice Health Endpoints Publicly Accessible Vulnerable Endpoints: Multiple /health endpoints on api.[vendor] CVSS 3.7 | Crypto Gaming Platform Global | Business Logic | Responsible Disclosure | Low | 2026-03 |
| Unicorn API with Laravel Horizon Installed (Authenticated) The unicorn.[vendor] subdomain hosts a Laravel API with Horizon queue monitoring installed. While Horizon returns 401 Unauthorized (properly authenticated), its presence reveals infrastructure details and the subdomain serves cookies with the session name ricki_session, indicating it's part of the core platform CVSS 3.7 | SEA E-Commerce Platform SEA | Admin Panel Exposure | Responsible Disclosure | Low | 2026-03 |
| DRF Browsable API Enabled in Production Finding 9: DRF Browsable API Enabled in Production Severity: Low (CVSS 3.7 - AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) The Django REST Framework Browsable API is enabled in production, providing an interactive HTML interface for API exploration at `/api/admin/?format=api`. This expose CVSS 3.7 | NA Online Casino NA | Information Disclosure | Responsible Disclosure | Low | 2026-03 |
| api.blix.gg Backend Down - 502 Bad Gateway (LOW) Finding 4: api.blix.gg Backend Down - 502 Bad Gateway (LOW) API backend tum endpoint'lerde 502 donduruyor. Bu backend crash'i veya misconfiguration gosteriyor. Impact: API hizmet disi, monitoring ve alerting eksikligi. CVSS 3.7 | KYC Mass Scan Global | Information Disclosure | Responsible Disclosure | Low | 2026-03 |
| Retroactive Reward Manipulation via Mutable Epoch Parameters Historical epoch rewards are recomputed using current globals (multiVault, utilization bound) so governance updates retroactively change payouts. CVSS 3.5 | Ethereum Attestation Protocol Global | Business Logic | Code4rena | Low | 2026-03 |
| Utilization Ratio Division-by-Zero DoS Blocks Reward Claims _getNormalizedUtilizationRatio divides by an unchecked target value; an attacker can force a zero denominator, DoSing reward claims. CVSS 3.5 | Ethereum Attestation Protocol Global | Business Logic | Code4rena | Low | 2026-03 |
| Postman Collection Access Key in Public HTML Documentation page exposes a Postman collection access key in HTML source. CVSS 3.5 | SEA Banking API Platform SEA | API Key Exposure | Responsible Disclosure | Low | 2026-03 |
| GraphQL Field Enumeration via Error Messages GraphQL server returns descriptive errors enabling schema field enumeration without authentication. CVSS 3.1 | African Crypto Infrastructure Africa | GraphQL Issues | Responsible Disclosure | Low | 2026-03 |
| Decommissioned Staging Subdomains with Dangling CF DNS Multiple Staging Subdomains Return HTTP 530 (Origin DNS Failure) — Decommissioned Services Not Cleaned Up CVSS 3.1 | LATAM Crypto Platform LATAM | Subdomain Takeover | HackerOne | Low | 2026-03 |
| Webhook HMAC Signing Secret Exposure + Forgery (CRITICAL) Finding 2: Webhook HMAC Signing Secret Exposure + Forgery (CRITICAL) CVSS 3.1: 8.7 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) Tum 13 webhook endpoint'in HMAC signing secret'lari Svix API uzerinden okunabiliyor. Bu secret'lar, sahte webhook event'leri imzalamak icin kullanilabilir. | E CVSS 3.1 | African Payment Gateway Africa | Credential Exposure | Responsible Disclosure | Low | 2026-03 |
| Analytics & Tracking IDs Disclosure Finding 4: Analytics & Tracking IDs Disclosure | Google Analytics 4 | `G-3PVFW01CEZ` | toko_index.html | | Google Tag Manager | `GTM-WWBN8CP` | toko_index.html | | Google Analytics (UA) | `UA-162512367-1` | 1b7de00.modern.js | CVSS 3.1 | SEA Crypto Exchange SEA | Information Disclosure | Responsible Disclosure | Low | 2026-03 |
| Statsig Evaluation Cache Contains PII and Account Identifiers Finding 3: Statsig Evaluation Cache Contains PII and Account Identifiers Severity: Low (CVSS 3.1) - Information Disclosure Summary: The Statsig cached evaluations file at `~/.[redacted]/statsig/statsig.cached.evaluations.3ab63d3fa2` contains sensitive identifiers in plaintext. Impact CVSS 3.1 | AI SaaS Provider NA | Information Disclosure | Responsible Disclosure | Low | 2026-03 |
| Webhook Endpoint Injection (CRITICAL) Finding 1: Webhook Endpoint Injection (CRITICAL) CVSS 3.1: 9.1 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N) Svix API token uzerinden yeni webhook endpoint olusturulabilir. Bu, saldirganin TUM gelecekteki payment, bank account, consent ve transaction event'lerini kendi sunucusuna yonlend CVSS 3.1 | African Payment Gateway Africa | RCE | Responsible Disclosure | Low | 2026-03 |
| OSS Bucket Catch-All Misconfiguration Finding 5: OSS Bucket Catch-All Misconfiguration The `[target]` Alibaba OSS bucket is configured with a catch-all redirect that returns the SPA HTML page (HTTP 200) for ANY path including non-existent resources: The inconsistency (some paths return 200 CVSS 3.1 | SEA Crypto Exchange SEA | Information Disclosure | Responsible Disclosure | Low | 2026-03 |
Curated selection, anonymized by default. Named vendors, report IDs, and CVEs available to qualified prospects under NDA. New disclosures land here as embargoes lift.
Want the full list under NDA?
Named vendors, report IDs, CVEs, and PoCs available to qualified prospects after a signed NDA.