LY Corporation Program Statistics


View program

49 total issues disclosed

$115,977 total paid publicly

Most disclosed (10 disclosures) — Improper Access Control - Generic



Disclosed Reports


Report Title Vulnerability Type Disclosed By Severity Disclosed on
page.line.me Open Redirect Leading to OAuth Authorization Code Exposure and Access Token Compromise None supplied imnotr3al High 2026-06-02
Stored XSS via SVG Upload in chat.line.biz None supplied imnotr3al Low 2026-01-05
Client-Side Path Traversal on LINE Developers Console Cross-Site Request Forgery (CSRF) never_die Medium 2024-09-26
File sizes may be manipulated into negative numbers when uploading Business Logic Errors yinmo Medium 2024-07-10
XSS on LINE CAREERS Cross-site Scripting (XSS) - Reflected nightm4re Low 2024-07-10
Reflected XSS on https://travel.line.me Cross-site Scripting (XSS) - Reflected mheranco Low 2024-01-18
Reflected XSS in OAUTH2 login flow (https://access.line.me) Cross-site Scripting (XSS) - Reflected tosun Medium 2023-10-04
iOS group chat denial of service Use of a Broken or Risky Cryptographic Algorithm yinmo Low 2023-03-29
Stored XSS Via Filename On https://partners.line.me/ Cross-site Scripting (XSS) - Stored rioncool22 Low 2023-03-28
Debugging panel exposure Improper Access Control - Generic tosun Low 2023-03-28
Path traversal in a Tomcat server Information Disclosure tosun No rating 2023-03-28
Blind SSRF in social-plugins.line.me Server-Side Request Forgery (SSRF) sirleeroyjenkins Medium 2022-10-06
SSRF occurrence in website preview used by LINE Official Account Manager (https://manager.line.biz) Server-Side Request Forgery (SSRF) jafarakhondali Low 2022-04-18
Deleting someone else's profile image with a GraphQL query in programming education service (https://entry.line.me) Insecure Direct Object Reference (IDOR) tosun Medium 2022-04-18
Use of unreleased features in programming education service (https://entry.line.me) Business Logic Errors tosun Medium 2022-04-18
SSRF restricted to HTTP/HTML on LINE Social Plugins (https://social-plugins.line.me/) Server-Side Request Forgery (SSRF) duahaubadao Medium 2022-04-18
Improper authorization allows disclosing users' notification data in Notification channel server Improper Authorization aki__0421 High 2021-12-31
Bot setting information leakage in OpenChat room Improper Access Control - Generic akichia Low 2021-12-27
Access to images and videos in drafts on LINE BLOG Improper Access Control - Generic akichia Medium 2021-12-27
Missing authentication in buddy group API of LINE TIMELINE Improper Authentication - Generic e26174222 Medium 2021-12-27
See drafts and post articles if the account owner hasn't set password (livedoor CMS plugin) Improper Authentication - Generic akichia Critical 2021-12-27
Missing ownership check in 2FA for secondary client login None supplied q0jt Critical 2021-12-27
Developer uploaded files missing authentication on LINE GAME Developers site(gdc.game.line.me) Improper Access Control - Generic tosun High 2021-12-27
Password reset by malicious input on air.line.me Improper Access Control - Generic tosun No rating 2021-12-27
LINE Profile ID leaks in OpenChat None supplied aki__0421 High 2021-12-27
DoS of LINE client for Android via message containing multiple unicode characters (0x0e & 0x0f) Denial of Service lynx_vn Medium 2021-09-24
Webview address bar spoofing in LINE client for iOS Phishing reinforchu Low 2021-09-15
Theft of arbitrary files in LINE Lite client for Android Improper Access Control - Generic hulkvision_ Medium 2021-07-06
Arbitrary Code Execution via npm misconfiguration – installing internal libraries from the public registry Code Injection alexbirsan Critical 2021-07-05
Webview in LINE client for iOS will render application/octet-stream files as HTML Improper Access Control - Generic s5s Medium 2021-07-05
Path traversal in ZIP extract routine on LINE Android Path Traversal kanytu Medium 2020-11-17
Improper Access Control in LINE Timeline API that returns a list of hidden friends Improper Access Control - Generic 66ed3gs Medium 2020-11-17
CORS misconfiguration leads to users information disclosure at https://studyroom.line.me Information Disclosure dhbd88 Medium 2020-11-13
Spring Actuator endpoints publicly available and broken authentication Misconfiguration kazan71p Critical 2020-08-06
Spring Actuator endpoints publicly available and broken authentication Misconfiguration kazan71p Critical 2020-08-06
Spring Actuator endpoints publicly available, leading to account takeover Misconfiguration kazan71p Critical 2020-08-04
Insufficient access control on all BCRM instances leading to the ability to create admin accounts using the API Improper Access Control - Generic j0eii High 2020-08-03
Insufficient access control on all BCRM instances leading to the ability to create admin accounts using the API Improper Access Control - Generic j0eii High 2020-08-03
Get-based SSRF limited to HTTP protocol on https://resizer.line-apps.com/form Server-Side Request Forgery (SSRF) ledz1996 Medium 2020-08-02
Path traversal in filename in LINE Mac client Path Traversal hackerontwowheels High 2020-07-31
Request smuggling on admin-official.line.me could lead to account takeover HTTP Request Smuggling shaolin_tw High 2020-05-19
Request smuggling on admin-official.line.me could lead to account takeover HTTP Request Smuggling shaolin_tw High 2020-05-19
Request smuggling on admin-official.line.me could lead to account takeover HTTP Request Smuggling shaolin_tw High 2020-05-19
Reflected XSS in OAUTH2 login flow Cross-site Scripting (XSS) - Reflected derision Medium 2020-04-21
Reflected XSS in OAUTH2 login flow Cross-site Scripting (XSS) - Reflected derision Medium 2020-04-21
Able to Become Admin for Any LINE Official Account Privilege Escalation ngalog Critical 2020-03-25
Able to Become Admin for Any LINE Official Account Privilege Escalation ngalog Critical 2020-03-25
SSRF on music.line.me through getXML.php Server-Side Request Forgery (SSRF) hahwul High 2020-03-25
DOM-based XSS on mobile.line.me Cross-site Scripting (XSS) - DOM zophi High 2020-03-25