Hostinger Program Statistics


View program

3 total issues disclosed

$0 total paid publicly

Most disclosed (2 disclosures) — Improper Access Control - Generic



Disclosed Reports


Report Title Vulnerability Type Disclosed By Severity Disclosed on
1 Click Account Takeover via Auth Token Theft on marketing.hostinger.com Improper Access Control - Generic aziz0x48 High 2025-06-06
Able to take over .zyrosite.com subdomains via `/v3/publish/connect-domain-hostinger` API endpoint Improper Access Control - Generic tosun Low 2022-12-05
subdomain takeover at status.hosting24.com Privilege Escalation omer Low 2022-05-16