vulnerability disclosure technical write ups - ap00rv/Appsec-wiki GitHub Wiki Publicly disclosed bugs on hackerone https://hackerone.com/hacktivity/new Articles about successful bug submissions that either had a high impact or were unique in nature or exploitation method. Paypal RCE Escalating XSS to SSRF and local file read Authentication bypasss on Airbnb using Oauth token theft pivoting from SSRF to RCE CSS injection related CSS injection attacks Data exfiltration via CSS injection @filedescriptor blog post on JavaScript execution in CSS