Top reports from Localize program at HackerOne:
- 2-factor authentication can be disabled when logged in without confirming account password to Localize - 136 upvotes, $500
- Stored XSS in Name of Team Member Invitation to Localize - 11 upvotes, $50
- The password limit is not set, [DoS]. to Localize - 11 upvotes, $50
- CSRF in adding phrase. to Localize - 10 upvotes, $0
- Full Path Disclosure / Info Disclosure in Creating New Group to Localize - 9 upvotes, $0
- Private Project Access Request Invitation Sent Via CSRF to Localize - 6 upvotes, $0
- XSS & HTML injection to Localize - 5 upvotes, $0
- Sign-up Form CSRF to Localize - 5 upvotes, $0
- XSS in Groups to Localize - 4 upvotes, $0
- XSS in invite approval to Localize - 4 upvotes, $0
- XSS in main page to Localize - 4 upvotes, $0
- Nginx version is disclosed in HTTP response to Localize - 4 upvotes, $0
- XSS in main page (invitation) to Localize - 3 upvotes, $0
- Sensitive file to Localize - 3 upvotes, $0
- HTML/Javascript possible in "Discussion" section of reviews to Localize - 3 upvotes, $0
- Business logic Failure - Browser cache management and logout vulnerability. to Localize - 3 upvotes, $0
- Path Disclosure (Info Disclosure) in http://www.localize.io to Localize - 2 upvotes, $0
- Apache Documentation to Localize - 2 upvotes, $0
- Numerous open ports/services to Localize - 2 upvotes, $0
- Criptographic Issue: Strisct Transport Security with not good max age..(TOO SHORT!) to Localize - 2 upvotes, $0
- Full Path Disclosure (FPD) in www.localize.im to Localize - 2 upvotes, $0
- Atttacker can send "Invitation Request" to a Project that is not even created yet! to Localize - 2 upvotes, $0
- XSS in Localize.io to Localize - 1 upvotes, $0
- User credentials are sent in clear text to Localize - 1 upvotes, $0
- HTML Form Without CSRF protection to Localize - 1 upvotes, $0
- Full path disclosure to Localize - 1 upvotes, $0
- No Cross-Site Request Forgery protection at multiple locations to Localize - 1 upvotes, $0
- Unexpected array leaks information about the system to Localize - 1 upvotes, $0
- Information Disclosure (Directory Structure) to Localize - 1 upvotes, $0
- Uninitialized variable error message leaks information to Localize - 1 upvotes, $0
- Full Path Disclosure (FPD) in www.localize.io to Localize - 1 upvotes, $0
- Full Path Disclosure / Info Disclosure in Importing XML Section! to Localize - 1 upvotes, $0
- Full Path Disclosure (2) to Localize - 1 upvotes, $0
- Full Path Disclosure to Localize - 1 upvotes, $0
- Assigning a non-existing role to user causes exception when opening project page to Localize - 1 upvotes, $0
- Password type input with auto-complete enabled to Localize - 1 upvotes, $0
- infinite number of new project creation! to Localize - 1 upvotes, $0
- XSS in password to Localize - 1 upvotes, $0
- Apache2 /icons/ folder accessible to Localize - 1 upvotes, $0
- Server header - information disclosure to Localize - 1 upvotes, $0
- PHP PDOException and Full Path Disclosure to Localize - 1 upvotes, $0
- Full Path Disclosure (FPD) in www.localize.im to Localize - 1 upvotes, $0
- full path disclosure from false language to Localize - 1 upvotes, $0
- missing sender policy framework (SPF) to Localize - 1 upvotes, $0
- Deleting groups in any project without permission to Localize - 0 upvotes, $0
- Making groups in any project without permission to Localize - 0 upvotes, $0
- Stored XSS to Localize - 0 upvotes, $0
- Possible sensitive files to Localize - 0 upvotes, $0
- Login page password-guessing attack to Localize - 0 upvotes, $0
- Group Deletion Via CSRF to Localize - 0 upvotes, $0
- Group Creation Via CSRF to Localize - 0 upvotes, $0
- Private Project Access Request Accpeted Via CSRF to Localize - 0 upvotes, $0
- OPTIONS Method Enabled to Localize - 0 upvotes, $0
- No Wildcard DNS to Localize - 0 upvotes, $0
- A Serious Bug on SIGNUP Process! to Localize - 0 upvotes, $0
- No BruteForce Protection to Localize - 0 upvotes, $0
- ClickJacking to Localize - 0 upvotes, $0
- Change user settings through CSRF to Localize - 0 upvotes, $0
- Password Policy to Localize - 0 upvotes, $0
- X-Content-Type-Options header missing to Localize - 0 upvotes, $0
- Projects Watch or Notifications Settings Change Via CSRF to Localize - 0 upvotes, $0
- XSS in Team Only Area to Localize - 0 upvotes, $0
- Bug on registration as new Translator user to Localize - 0 upvotes, $0
- PHP PDOException and Full Path Disclosure to Localize - 0 upvotes, $0
- PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings. to Localize - 0 upvotes, $0
- files likes of README.md is public to Localize - 0 upvotes, $0