Top reports from Paragon Initiative Enterprises program at HackerOne:
- BAD Code ! to Paragon Initiative Enterprises - 483 upvotes, $0
- DMARC Not found for paragonie.com URGENT to Paragon Initiative Enterprises - 136 upvotes, $0
- Subdomain Takeover to Paragon Initiative Enterprises - 67 upvotes, $0
- I am because bug to Paragon Initiative Enterprises - 38 upvotes, $0
- ssl info shown to Paragon Initiative Enterprises - 31 upvotes, $0
- [Critical] billion dollars issue to Paragon Initiative Enterprises - 29 upvotes, $0
- Stored Cross-Site-Scripting in CMS Airship's authors profiles to Paragon Initiative Enterprises - 23 upvotes, $50
- Email Spoof to Paragon Initiative Enterprises - 16 upvotes, $0
- Site support SNI But Browser can't to Paragon Initiative Enterprises - 15 upvotes, $0
- Content-type sniffing leads to stored XSS in CMS Airship on Internet Explorer to Paragon Initiative Enterprises - 15 upvotes, $0
- Spf to Paragon Initiative Enterprises - 14 upvotes, $0
- Stored XSS using SVG to Paragon Initiative Enterprises - 12 upvotes, $50
- Paragonie Airship Admin CSRF on Extensions Pages to Paragon Initiative Enterprises - 11 upvotes, $100
- Full directory path listing to Paragon Initiative Enterprises - 10 upvotes, $0
- Improper access control lead To delete anyone comment to Paragon Initiative Enterprises - 8 upvotes, $100
- Directory Disclose,Email Disclose Zendmail vulnerability to Paragon Initiative Enterprises - 8 upvotes, $50
- Stored XSS in comments to Paragon Initiative Enterprises - 6 upvotes, $25
- [Airship CMS] Local File Inclusion - RST Parser to Paragon Initiative Enterprises - 6 upvotes, $0
- Incorrect detection of onion URLs to Paragon Initiative Enterprises - 5 upvotes, $50
- Session Management to Paragon Initiative Enterprises - 5 upvotes, $0
- Issue with password reset functionality [Minor] to Paragon Initiative Enterprises - 5 upvotes, $0
- Incomplete fix for #181225 (target=_blank vulnerability) to Paragon Initiative Enterprises - 5 upvotes, $0
- Open-redirect on paragonie.com to Paragon Initiative Enterprises - 4 upvotes, $50
- Cross-site-Scripting to Paragon Initiative Enterprises - 4 upvotes, $50
- Invited user to a Author profile can remove the owner of that Author to Paragon Initiative Enterprises - 4 upvotes, $50
- CSRF AT SUBSCRIBE TO LIST to Paragon Initiative Enterprises - 4 upvotes, $0
- Broken Authentication & Session Management - Failure to Invalidate Session on all other browsers at Password change to Paragon Initiative Enterprises - 4 upvotes, $0
- Airship: Persistent XSS via Comment to Paragon Initiative Enterprises - 4 upvotes, $0
- CSRF token does not valided during blog comment to Paragon Initiative Enterprises - 3 upvotes, $25
- User enumeration via Password reset page [Minor] to Paragon Initiative Enterprises - 3 upvotes, $0
- Email Spoofing With Your Website's Email to Paragon Initiative Enterprises - 3 upvotes, $0
- SMTP server allows anonymous relay from internal addresses to internal addresses to Paragon Initiative Enterprises - 3 upvotes, $0
- Github repo's wiki publicly editable to Paragon Initiative Enterprises - 3 upvotes, $0
- Recaptcha Secret key Leaked to Paragon Initiative Enterprises - 3 upvotes, $0
- Missing rel=noopener noreferrer in target=_blank links (Phishing attack) to Paragon Initiative Enterprises - 2 upvotes, $50
- Information Disclosure in Error Page to Paragon Initiative Enterprises - 2 upvotes, $0
- Missing SPF to Paragon Initiative Enterprises - 2 upvotes, $0
- Email spoofing in [email protected] to Paragon Initiative Enterprises - 2 upvotes, $0
- Nginx Version Disclosure On Forbidden Page to Paragon Initiative Enterprises - 2 upvotes, $0
- Full path disclosure when CSRF validation failed to Paragon Initiative Enterprises - 2 upvotes, $0
- Session Management Issue CMS Airship to Paragon Initiative Enterprises - 2 upvotes, $0
- [URGENT] Password reset emails are sent in clear-text (without encryption) to Paragon Initiative Enterprises - 2 upvotes, $0
- Full Path Disclosure by removing CSRF token to Paragon Initiative Enterprises - 2 upvotes, $0
- Not clearing hex-decoded variable after usage in Authentication to Paragon Initiative Enterprises - 2 upvotes, $0
- directory information disclose to Paragon Initiative Enterprises - 2 upvotes, $0
- Full Path Disclousure on https://airship.paragonie.com to Paragon Initiative Enterprises - 2 upvotes, $0
- no session logout after changing the password in https://bridge.cspr.ng/ to Paragon Initiative Enterprises - 2 upvotes, $0
- Improper validation of Email to Paragon Initiative Enterprises - 2 upvotes, $0
- Your Application Have Cacheable SSL Pages to Paragon Initiative Enterprises - 2 upvotes, $0
- Github wikis are editable by anyone https://github.com/paragonie/password_lock/wiki to Paragon Initiative Enterprises - 2 upvotes, $0
- Full Path Disclosure to Paragon Initiative Enterprises - 1 upvotes, $50
- Vunerability : spf to Paragon Initiative Enterprises - 1 upvotes, $0
- DNSsec not configured to Paragon Initiative Enterprises - 1 upvotes, $0
- The Anti-CSRF Library fails to restrict token to a particular IP address when being behind a reverse-proxy/WAF to Paragon Initiative Enterprises - 1 upvotes, $0
- Missing SPF for paragonie.com to Paragon Initiative Enterprises - 1 upvotes, $0
- SSL certificate public key less than 2048 bit to Paragon Initiative Enterprises - 1 upvotes, $0
- Email Authentication Bypass to Paragon Initiative Enterprises - 1 upvotes, $0
- Full path disclosure vulnerability on paragonie.com to Paragon Initiative Enterprises - 1 upvotes, $0
- Email Authentication bypass Vulnerability to Paragon Initiative Enterprises - 1 upvotes, $0
- Cross-domain AJAX request to Paragon Initiative Enterprises - 1 upvotes, $0
- Email spoofing to Paragon Initiative Enterprises - 1 upvotes, $0
- Missing SPF records for paragonie.com to Paragon Initiative Enterprises - 1 upvotes, $0
- file full path discloser. to Paragon Initiative Enterprises - 1 upvotes, $0
- Missing SPF for paragonie.com to Paragon Initiative Enterprises - 1 upvotes, $0
- Blind SQL INJ to Paragon Initiative Enterprises - 1 upvotes, $0
- Airship doesn't reject weak passwords to Paragon Initiative Enterprises - 1 upvotes, $0
- Using plain git protocol (vulnerable to MITM) to Paragon Initiative Enterprises - 1 upvotes, $0
- There is an vulnerability in https://bridge.cspr.ng where an attacker can users directory to Paragon Initiative Enterprises - 1 upvotes, $0
- Missing SPF for https://paragonie.com/ to Paragon Initiative Enterprises - 0 upvotes, $0
- Missing GIT tag/commit verification in Docker to Paragon Initiative Enterprises - 0 upvotes, $0
- Not using Binary::safe* functions for substr/strlen function to Paragon Initiative Enterprises - 0 upvotes, $0
- Non-secure requests are not automatically upgraded to HTTPS to Paragon Initiative Enterprises - 0 upvotes, $0
- Full Path Disclosure in airship.paragonie.com '/cabins/' to Paragon Initiative Enterprises - 0 upvotes, $0
- Full Path Disclosure in password lock to Paragon Initiative Enterprises - 0 upvotes, $0
- Full Path Disclosure In EasyDB to Paragon Initiative Enterprises - 0 upvotes, $0