Autodesk Program Statistics


View program

14 total issues disclosed

$0 total paid publicly

Most disclosed (4 disclosures) — Cross-site Scripting (XSS) - Stored



Disclosed Reports


Report Title Vulnerability Type Disclosed By Severity Disclosed on
Stored XSS in AREA tutorials Cross-site Scripting (XSS) - Stored i_0x0 High 2025-08-25
Reflected XSS Vulnerability in SVG File at area-resources-stg.autodesk.com Cross-site Scripting (XSS) - Stored ahmednasr1 Medium 2025-04-17
HTML Injection in Business Name Parameter in Payapps Code Injection 0xsom3a Medium 2025-04-07
Twitter broken link hijacking in thewild.com Origin Validation Error yunxohang_ Low 2025-03-24
SSRF in Autodesk Rendering leading to account takeover Server-Side Request Forgery (SSRF) metereorpreter Critical 2025-03-18
Django Debug Mode Enabled - Information Disclosure on api.wwm-dev.autodesk.com Information Exposure Through Debug Information khoof Medium 2025-03-18
Stored Cross-Site Scripting found in custom integration app on https://admin.b360.autodesk.com. Cross-site Scripting (XSS) - Stored the-white-evil Medium 2025-03-14
Exposing debug.log file leads to server full path disclosure Information Disclosure kanon4 Low 2025-03-06
CVE-2023-5561 on Payapps.com Information Disclosure khoof Medium 2025-03-05
Stored XSS via Post Tittle Enabling Non-Privileged User to Privileged User Exploitation on https://forums.autodesk.com/ Cross-site Scripting (XSS) - Stored the-white-evil High 2025-02-26
Insecure Direct Object Reference (IDOR) in GraphQL deleteProfileImages Mutation Insecure Direct Object Reference (IDOR) alphahacks High 2025-02-21
IDOR Vulnerability Allowing Unauthorized Profile Picture Change Insecure Direct Object Reference (IDOR) l1ackersalman Medium 2025-02-19
Insecure Direct Object Reference (IDOR) Vulnerability in Autodesk User Profile Insecure Direct Object Reference (IDOR) eyax0 Medium 2025-02-19
Wordpress users Disclosure Information Disclosure karimtantawy Critical 2025-02-12