Quora Program Statistics
8 total issues disclosed
$1,650 total paid publicly
Most disclosed (4 disclosures) — Cross-site Scripting (XSS) - Generic
Disclosed Reports
| Report Title | Vulnerability Type | Disclosed By | Severity | Disclosed on |
|---|---|---|---|---|
| XSS through `__e2e_action_id` delivered by JSONP | Cross-site Scripting (XSS) - Reflected | 0xnan | Low | 2018-03-08 |
| XSS when clicking "Share to Twitter" at quora.com/widgets/embed_iframe?path=... | Cross-site Scripting (XSS) - Generic | stefanofinding | Low | 2018-01-11 |
| IDNs displayed in unicode | Violation of Secure Design Principles | hk755a | Medium | 2017-10-26 |
| [Quora Android] Possible to steal arbitrary files from mobile device | Information Disclosure | bagipro | Medium | 2017-08-30 |
| Possibility of DOS Through logging System | None supplied | imran-parray | Medium | 2017-08-17 |
| self xss in | Cross-site Scripting (XSS) - Generic | panther | Medium | 2017-05-23 |
| [Android] XSS via start ContentActivity | Cross-site Scripting (XSS) - Generic | bobrov | Low | 2017-04-05 |
| [controlsyou.quora.com] 429 Too Many Requests Error-Page XSS | Cross-site Scripting (XSS) - Generic | bobrov | Medium | 2017-03-31 |
Getting started
Learn about vulnerability types
Getting started in bug bounties
Test your knowledge
Free Web Application Challenges
Guides for your hunts
ZSeano's Methodology
Effective Note Taking for bug bounties
Useful Resources
Disclosed HackerOne Reports
Our community
Endorsed Members
Hackevents
Member Articles