Daily Writeups
3.47K subscribers
2 photos
127K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Lab: Reflected XSS into HTML context with nothing encoded
════════════════════════
𐀪 Author: jaejun835
════════════════════════
Time: Thu, 26 Feb 2026 05:31:20 GMT
════════════════════════
Tags: #csp #html #burpsuite #xs #portswigger
Title: Forcing an AI App to generate Payloads to Cause HTML Injection
════════════════════════
𐀪 Author: Rahul Singh Chauhan
════════════════════════
Time: Wed, 04 Mar 2026 01:11:07 GMT
════════════════════════
Tags: #html_injection #bug_bounty #cybersecurity #ai #bug_bounty_reports
Title: ️‍♂️ A Fun HTML Injection Story — When a “File Name” Became My Entry Point
════════════════════════
𐀪 Author: Diwas mundra
════════════════════════
Time: Wed, 18 Mar 2026 21:42:18 GMT
════════════════════════
Tags: #penetration_testing #cybersecurity #sql_injection #vulnerability #html_injection
Title: Invisible Ink: Critical 9.6 CVSS jsPDF Flaw Turns Generated Documents into XSS Traps
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 19 Mar 2026 13:30:38 +0000
════════════════════════
Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2026_31938 #cybersecurity #HTML Injection #infosec #JavaScript Security #jsPDF #Vulnerability #web development #XSS
Title: HTML Injection Bug Bounty: How I Found a Persistent Vulnerability on a Government of India Portal
════════════════════════
𐀪 Author: Vanshrathore
════════════════════════
Time: Mon, 06 Apr 2026 18:22:08 GMT
════════════════════════
Tags: #bug_bounty #html_injection #pentesting #money #bug_hunting
Title: From P4 to Critical: How I Weaponized target.com’s Email Infrastructure
════════════════════════
𐀪 Author: Vanshrathore
════════════════════════
Time: Thu, 16 Apr 2026 15:18:58 GMT
════════════════════════
Tags: #penetration_testing #bug_bounty #html_injection #bug_hunting #money
Title: How A Simple Bug That Refused to Die, Paid Twice.
════════════════════════
𐀪 Author: kjulius
════════════════════════
Time: Sun, 26 Apr 2026 03:03:44 GMT
════════════════════════
Tags: #injection #ui_interaction #html #bug_bounty #inconsistencies
Title: How A Simple Bug That Refused to Die, Paid Twice.
════════════════════════
𐀪 Author: kjulius
════════════════════════
Time: Sun, 26 Apr 2026 03:03:42 GMT
════════════════════════
Tags: #injection #ui_interaction #html #bug_bounty #inconsistencies
Title: bWAPP: HTML Injection — Reflected (GET) Challenge (Low & Medium Security)
════════════════════════
𐀪 Author: Kamal S
════════════════════════
Time: Sat, 09 May 2026 12:04:24 GMT
════════════════════════
Tags: #injection #owasp #html_injection #bwapp #bug_bounty
Title: HTML Should Have Embedded Markdown 30 Years Ago
════════════════════════
𐀪 Author: Outermostkt
════════════════════════
Time: Sun, 17 May 2026 02:08:54 GMT
════════════════════════
Tags: #thariq #ai #xs #html #markdown
Title: The Sleeper Agent Bug: How One HTML Payload Lay Hidden for Months to Attack My Inbox
════════════════════════
𐀪 Author: LordofHeaven
════════════════════════
Time: Tue, 19 May 2026 09:00:53 GMT
════════════════════════
Tags: #html_injection #web_security #infosec #coffinxp #bug_bounty
Title: Living Off the HTA Land: How Hackers Weaponize a 1999 Windows Utility for Silent Malware Delivery
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 21 May 2026 07:04:27 +0000
════════════════════════
Tags: #Malware #Amatera Info Harvester #ClickFix Social Engineering LummaStealer #ClipBanker Crypto Stealer #CountLoader Staging Framework #Emmenhtal Loader #HTML Application HTA Payload #Living off the Land Binaries #MSHTA Weaponization Malware Delivery #mshta.exe Windows Binary #PurpleFox Rootkit Lineage
Title: HTML Injection in Outbound Emails: An Overlooked Security Risk
════════════════════════
𐀪 Author: vibhuti bhatt
════════════════════════
Time: Fri, 05 Jun 2026 12:26:37 GMT
════════════════════════
Tags: #html_injection #vulnerability #application_security #pentesting #injection_in_email
Title: Telegram Bots Receive Rich HTML and Markdown Formatting Options
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Tue, 16 Jun 2026 08:44:45 +0000
════════════════════════
Tags: #Technology #bot development #HTML formatting #Markdown #Rich Text #Telegram Bots
Title: I Turned a “What’s Your Name?” Field Into a Malicious Link — My First HTML Injection
════════════════════════
𐀪 Author: Prashant Raj
════════════════════════
Time: Wed, 17 Jun 2026 10:46:00 GMT
════════════════════════
Tags: #bug_bounty #cybersecurity #bug_hunting #html_injection #technology
Title: I Found a Bug That Looks Harmless But Can Still Get You Paid
════════════════════════
𐀪 Author: Yamini Yadav_369
════════════════════════
Time: Thu, 18 Jun 2026 00:03:53 GMT
════════════════════════
Tags: #cybersecurity #ethical_hacking #html #medium #bug_bounty
Title: bWAPP HTML Injection — Reflected (URL) and Stored (Blog)
════════════════════════
𐀪 Author: Kamal S
════════════════════════
Time: Sun, 21 Jun 2026 14:03:38 GMT
════════════════════════
Tags: #injection #html_injection #owasp #bug_bounty #bwapp
Title: CSRF: When Your Browser Snitches Behind Your Back
════════════════════════
𐀪 Author: Ziyad
════════════════════════
Time: Tue, 23 Jun 2026 01:34:55 GMT
════════════════════════
Tags: #web_development #html #csrf #cybersecurity #penetration_testing
Title: From a “Self-XSS” to a Convincing UI Spoof: A Bug Bounty Story That Ended as a Duplicate.
════════════════════════
𐀪 Author: kjulius
════════════════════════
Time: Fri, 26 Jun 2026 19:47:30 GMT
════════════════════════
Tags: #phishing #html #reflected_xss #self_xss #bug_bounty
Title: GitLab Patch Release Fixes Eight Flaws, Including a High-Severity XSS Bug (CVE-2026-6896)
════════════════════════
𐀪 Author: Do Son
════════════════════════
Time: Thu, 09 Jul 2026 02:15:16 +0000
════════════════════════
Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2026_13320 #CVE_2026_6896 #DevSecOps #GitLab EE #GitLab patch release #HTML Injection