OTP Verification Bypass via Response Manipulation on Email Change Authentication Flow

Click to read the full walkthrough.

April 2, 2026 · Fernandez

Price Manipulation via Client-Side Parameter Tampering

Click to read the full walkthrough

April 2, 2026 · Fernandez

Exposed Unrestricted Google API Key in Client-Side: JavaScript Allows Unauthorized API Abuse

Click to read the full walkthrough.

March 4, 2026 · Fernandez

IDOR - Unauthorized User Profile Update via Customer ID Manipulation

Click to read the full walkthrough

March 2, 2026 · Fernandez

Account Takeover via Password Reset Token Misconfiguration

Click to read the full walkthrough.

November 4, 2025 · Fernandez