Quora Program Statistics
8 total issues disclosed
$1,650 total paid publicly
Most disclosed (4 disclosures) — Cross-site Scripting (XSS) - Generic
Disclosed Reports
Report Title | Vulnerability Type | Disclosed By | Severity | Disclosed on |
---|---|---|---|---|
XSS through `__e2e_action_id` delivered by JSONP | Cross-site Scripting (XSS) - Reflected | 0xnan | Low | 2018-03-08 |
XSS when clicking "Share to Twitter" at quora.com/widgets/embed_iframe?path=... | Cross-site Scripting (XSS) - Generic | stefanofinding | Low | 2018-01-11 |
IDNs displayed in unicode | Violation of Secure Design Principles | hk755a | Medium | 2017-10-26 |
[Quora Android] Possible to steal arbitrary files from mobile device | Information Disclosure | bagipro | Medium | 2017-08-30 |
Possibility of DOS Through logging System | None supplied | imran-parray | Medium | 2017-08-17 |
self xss in | Cross-site Scripting (XSS) - Generic | panther | Medium | 2017-05-23 |
[Android] XSS via start ContentActivity | Cross-site Scripting (XSS) - Generic | bobrov | Low | 2017-04-05 |
[controlsyou.quora.com] 429 Too Many Requests Error-Page XSS | Cross-site Scripting (XSS) - Generic | bobrov | Medium | 2017-03-31 |