An unsigned upload content type plus a wildcard cross-origin policy let one link read a crypto exchange user's identity, verification status, and wallet address on a single click.
Jun 19, 2026A simulation platform's script sandbox blocked modules by name only, letting any user run commands in the production worker pod and steal a long-lived API key.
Jun 18, 2026A retail group's shared sign-in service exposed a profile API with no authentication and no ownership check, allowing full data reads or a login-credential overwrite given a user's internal id.
Jun 17, 2026An unanchored host check let a leftover test parameter load attacker JavaScript on a trading platform's genuine signup page, swapping the form to capture credentials in cleartext.
Jun 17, 2026A smart-speaker linking flow let an attacker steer a victim's one-click authorization into the attacker's device, harvest a write-capable token, and permanently take over the music account.
Jun 16, 2026A disabled origin check plus a CSS injection let any website embed a money-transfer provider's genuine card form and silently steal full card details from inside its own secure environment.
Jun 15, 2026An unauthenticated token-minting chain let anyone log into a news subscription portal as any user knowing only a sequential account number, gaining full account control across multiple brands.
Jun 15, 2026An unauthenticated order-details endpoint with sequential order numbers exposed millions of news subscribers' contact details across multiple brands, harvestable straight from visitors' browsers.
Jun 15, 2026A data-source endpoint field with no host restrictions let any free-trial user force a production worker to leak live signed cloud credential headers and return internal content as search results.
Jun 12, 2026A crafted image uploaded to a fitness app's photo feature made the image-processing library read arbitrary files off production, with contents served back on a public image host.
Jun 11, 2026