Stellar.org Program Statistics


View program

10 total issues disclosed

$0 total paid publicly

Most disclosed (3 disclosures) — Violation of Secure Design Principles



Disclosed Reports


Report Title Vulnerability Type Disclosed By Severity Disclosed on
Bypassing Verify Humans Page Improper Authentication - Generic suvrat7 None 2020-02-23
Direct URL access to PDF files Forced Browsing ramakanthk35 Medium 2020-02-23
xss None supplied vyshnav_nk High 2020-02-23
brute force attack allowed on admin page https://www.stellar.org/wp-admin/ Improper Restriction of Authentication Attempts abo-jehad Medium 2020-02-23
Admin panel of https://www.stellar.org/wp-admin/ Violation of Secure Design Principles hach3ro Medium 2020-02-23
It's possible to put SDX orderbook into invalid state and execute trades at arbitrary price Business Logic Errors nebolsin High 2018-10-14
Exploitable vulnerability in SDEX Business Logic Errors orbitlens High 2018-10-14
heap-buffer-overflow (READ of size 1) in cpptoml::parser::consume_whitespace() Heap Overflow geeknik No rating 2017-06-30
Session Cookie without HttpOnly and secure flag set Violation of Secure Design Principles k4yy1s None 2017-06-14
HTTP - Basic Authentication on https://www.stellar.org/wp-login.php Violation of Secure Design Principles mrr3boot Medium 2017-06-13