Bounties
Partners
Community
Info
causefx / organizr
Project repository
HTPC/Homelab Services Organizer - Written in PHP
Submit a report
FIRST INTERACTION
WITHIN
N/A DAYS
REVIEW
WITHIN
13 DAYS
FIX
WITHIN
14 DAYS
Stored XSS in image name
Feb 14th 2023
brackishio
•
pending
Rate Limiting Bypass Leading to Account Takeover
Jan 25th 2023
brackishio
•
pending
Stored XSS in "Tab Image" and "Group Image"
May 26th 2022
sampritdas8
•
Critical
•
$10
Critical
•
$10
•
CVE-2022-1909
CVE-2022-1909
Improper Control of a Resource Through its Lifetime in the input field "Bookmark...
May 13th 2022
sampritdas8
•
Critical
•
$30
Critical
•
$30
Allocation of Resources Without Limits in "Bookmark Categories"
May 11th 2022
sampritdas8
•
Critical
•
$30
Critical
•
$30
Uncontrolled Resource Consumption in "Category Editor"
May 11th 2022
sampritdas8
•
Critical
•
$30
Critical
•
$30
Allowing long password leads to denial of service
May 11th 2022
sampritdas8
•
Critical
•
$30
Critical
•
$30
•
CVE-2022-1698
CVE-2022-1698
Uncontrolled Resource Consumption
May 11th 2022
sampritdas8
•
Critical
•
$30
Critical
•
$30
•
CVE-2022-1699
CVE-2022-1699
Insecure Storage of Sensitive Information
May 10th 2022
sampritdas8
•
pending
Regular Expression Denial of Service (ReDoS)
Apr 27th 2022
appsectr
•
not applicable
Unrestricted Image Upload
Apr 20th 2022
baharuddinzulkifli
•
Medium
Medium
Store XSS at uTorrentUsername parameter on Homepage Items
Apr 13th 2022
minhnb11
•
pending
Store XSS at TabEditor->Homepage Items->BookMarks -> title
Apr 13th 2022
minhnb11
•
pending
Stored XSS on add Group Name
Apr 13th 2022
baharuddinzulkifli
•
Medium
Medium
Multiple Stored XSS
Apr 11th 2022
sampritdas8
•
Critical
•
$30
Critical
•
$30
•
CVE-2022-1346
CVE-2022-1346
Stored XSS due to no sanitization in the filename
Apr 11th 2022
sampritdas8
•
Critical
•
$30
Critical
•
$30
•
CVE-2022-1344
CVE-2022-1344
Stored XSS viva .svg file upload
Apr 11th 2022
sampritdas8
•
Critical
•
$10
Critical
•
$10
•
CVE-2022-1345
CVE-2022-1345
Stored XSS in the "Username" & "Email" input fields leads to account takeover of...
Apr 11th 2022
sampritdas8
•
Critical
•
$30
Critical
•
$30
•
CVE-2022-1347
CVE-2022-1347
XSS affecting "Logs" Page
Apr 10th 2022
galapag0s
•
Critical
•
$30
Critical
•
$30
Cross-site Scripting (XSS) - Stored
Apr 10th 2022
kstarkloff
•
Medium
•
$40
Medium
•
$40
Code Injection
Jul 23rd 2021
aravindd007
•
Critical
•
$40
Critical
•
$40
Open Redirect
Jun 28th 2021
wr3nch0x1
•
High
•
$40
High
•
$40
Improper Access Control
May 27th 2021
d43mone
•
High
•
$40
High
•
$40
CRITICAL
$0
HIGH
$0
MEDIUM
$0
LOW
$0