Insightly Program Statistics
5 total issues disclosed
$0 total paid publicly
Most disclosed (2 disclosures) — Cross-site Scripting (XSS) - Stored
Disclosed Reports
| Report Title | Vulnerability Type | Disclosed By | Severity | Disclosed on |
|---|---|---|---|---|
| Stored XSS via LINK Name. | Cross-site Scripting (XSS) - Stored | xploiterr | High | 2025-09-23 |
| Stored XSS in Email Notifcation | Cross-site Scripting (XSS) - Stored | khaledx | Medium | 2025-09-19 |
| CSRF vulnerability allows disabling Gmail contacts link for user referrals | Cross-Site Request Forgery (CSRF) | khaledx | Medium | 2025-09-19 |
| Email verification bypass via request to endpoint "accounts.insightly.com/signup/provisionuser" | Improper Authorization | akostak | Critical | 2025-08-18 |
| returnUrl= allow attacker to redirect users to the another phising website and takeover credientials | Improper Authentication - Generic | basant0x01 | Medium | 2025-06-04 |
Getting started
Learn about vulnerability types
Getting started in bug bounties
Test your knowledge
Free Web Application Challenges
Guides for your hunts
ZSeano's Methodology
Effective Note Taking for bug bounties
Useful Resources
Disclosed HackerOne Reports
Our community
Endorsed Members
Hackevents
Member Articles