| rXSS on https://mackeeperapp.mackeeper.com/landings/download-blue/ |
Cross-site Scripting (XSS) - Reflected |
trungnd95 |
Low |
2021-06-30 |
| Social media link hijack of team member [Linkedin] at https://mackeeper.com/team/ |
Misconfiguration |
beerboy_ankit |
Low |
2021-04-21 |
| Google API key leaks and security misconfiguration leads Open Redirect Vulnerability |
Open Redirect |
br33z3 |
Medium |
2021-04-01 |
| No rate Limit on Licenses Activation |
Business Logic Errors |
akash-labade |
Medium |
2021-02-18 |
| Cookie injection leads to complete DoS over whole domain *.mackeeper.com. Injection point accountstage.mackeeper.com/ |
Denial of Service |
mayurudiniya |
Low |
2020-10-21 |
| Local Privilege escalation to root via XPC |
Privilege Escalation |
r3ggi-on-h1 |
High |
2020-06-14 |
| rxss at https://mackeeper.com page not found via rid parameter |
Cross-site Scripting (XSS) - Reflected |
g0dzira |
Low |
2020-06-14 |
| Affiliates - Session Fixation |
Session Fixation |
jair |
Low |
2020-06-14 |
| Open Redirect at https://store.mackeeper.com/767/cookie via redirectto parameter |
Open Redirect |
sec0ndw0lf |
Low |
2020-06-14 |
| RXSS on landings/land/3/ron_clean_17_app3_alerts/index.php (mackeeperapp3.mackeeper.com) |
Cross-site Scripting (XSS) - Reflected |
sec0ndw0lf |
Low |
2020-06-13 |
| RXSS on unsubscribe feature (affiliates.kromtech.com) |
Cross-site Scripting (XSS) - Reflected |
sec0ndw0lf |
Low |
2020-06-13 |
| Reflected XSS (mackeeperapp2.mackeeper.com) |
Cross-site Scripting (XSS) - Reflected |
sec0ndw0lf |
Low |
2020-06-13 |
| RXSS on /landings/123.1/index.php (mackeeperapp.mackeeper.com) |
Cross-site Scripting (XSS) - Reflected |
sec0ndw0lf |
Medium |
2020-06-13 |
| RXSS on thankyou.pixels.php (yapi.mackeeper.com) |
Cross-site Scripting (XSS) - Reflected |
sec0ndw0lf |
Low |
2020-06-13 |
| Multiple Information Disclosure with Go PPROF on api-ne.mackeeper.com |
Information Disclosure |
m4ll0k |
Low |
2020-06-11 |
| Open redirect on https://account.mackeeper.com |
Open Redirect |
jin0ne |
Low |
2020-06-10 |
| XSS in https://affiliates.kromtech.com |
Cross-site Scripting (XSS) - Reflected |
kphaks |
Medium |
2020-05-25 |
| CRLF Injection - http://stage.mackeeper.com/ |
CRLF Injection |
kphaks |
Low |
2020-05-25 |
| XSS in https://mackeeper.com |
Cross-site Scripting (XSS) - Reflected |
kphaks |
Medium |
2020-05-25 |
| CRLF Injection - http://stage-static-cdn.mackeeper.com/ |
CRLF Injection |
kphaks |
Low |
2020-05-25 |
| Lack of HTTPS in service communications |
Cleartext Transmission of Sensitive Information |
patient_zero |
Medium |
2020-05-23 |
| Reflected XSS |
Cross-site Scripting (XSS) - Reflected |
patient_zero |
Low |
2020-05-23 |
| Unauthenticated Reflected Cross-Site Scripting on https://account.mackeeper.com/signin page |
Cross-site Scripting (XSS) - Reflected |
patient_zero |
Low |
2020-05-23 |
| CORS Misconfiguration, could lead to disclosure of sensitive information (translate.kromtech.com) |
None supplied |
sec0ndw0lf |
Low |
2020-05-18 |
| Multiple Links Vulnerable to Reflected xss |
Cross-site Scripting (XSS) - Reflected |
dilawer |
Low |
2020-05-17 |
| Reflected xss |
Cross-site Scripting (XSS) - Reflected |
dilawer |
Low |
2020-05-17 |
| Reflected xss on mackeeper.com |
Cross-site Scripting (XSS) - Reflected |
dilawer |
Low |
2020-05-17 |
| open redirect at https://account.mackeeper.com/auth/signin/continue via improper uri sanitization |
Open Redirect |
dilawer |
Low |
2020-05-17 |
| Bypass front server restrictions and access to forbidden files and directories through X-Rewrite-Url/X-original-url header on account.mackeeper.com |
Misconfiguration |
rumiljonov |
Medium |
2020-05-15 |
| CSS Injection on static.mackeeper.com - Potential XSS |
Resource Injection |
m4ll0k |
Low |
2020-05-15 |
| No rate limiting on password reset page |
Business Logic Errors |
karna__ |
Low |
2020-05-15 |
| Account Takeover because of the mis-configuration on the Password Reset Page |
Business Logic Errors |
karna__ |
Medium |
2020-05-15 |
| Information disclosure of Internal php files on [mackeeper.com/blog/api/send-event] |
Information Exposure Through an Error Message |
darkerhack |
Low |
2020-05-15 |
| MK Site Cross-Site Scripting (XSS) in script context |
Cross-site Scripting (XSS) - Reflected |
adelin30 |
Low |
2020-05-15 |
| Reflected XSS on stage.mackeeper.com |
Cross-site Scripting (XSS) - Reflected |
karna__ |
Low |
2020-05-15 |
| IDOR at https://account.mackeeper.com/at/load-reports/profile/<profile_id> leaks information about devices/licenses |
Insecure Direct Object Reference (IDOR) |
m4ii0k |
Medium |
2020-05-15 |
| Account verification bypass on translate.kromtech.com |
Authentication Bypass Using an Alternate Path or Channel |
rumiljonov |
Medium |
2020-05-05 |