Insightly Program Statistics


View program

5 total issues disclosed

$0 total paid publicly

Most disclosed (2 disclosures) — Cross-site Scripting (XSS) - Stored



Disclosed Reports


Report Title Vulnerability Type Disclosed By Severity Disclosed on
Stored XSS via LINK Name. Cross-site Scripting (XSS) - Stored xploiterr High 2025-09-23
Stored XSS in Email Notifcation Cross-site Scripting (XSS) - Stored khaledx Medium 2025-09-19
CSRF vulnerability allows disabling Gmail contacts link for user referrals Cross-Site Request Forgery (CSRF) khaledx Medium 2025-09-19
Email verification bypass via request to endpoint "accounts.insightly.com/signup/provisionuser" Improper Authorization akostak Critical 2025-08-18
returnUrl= allow attacker to redirect users to the another phising website and takeover credientials Improper Authentication - Generic basant0x01 Medium 2025-06-04