writeups.xyz writeups.xyz / Shopify

Title Vulnerabilities Programs Authors
Customer account takeover in Shopify stores
Reflected Cross Site Scripting (Awards 3500$ bounty)
Hacking Swagger-UI - from XSS to account takeovers
Cache Poisoning at Scale
Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies
(Shopify.com) Blind Stored XSS Via Staff Name $$$$
How I Earned $1750 at Shopify Bug Bounty Program
How I gained access to revenue and traffic data of thousands of Shopify stores
Handlebars template injection and RCE in a Shopify app
Exploiting Google Calendars
Reflected XSS at https://photos.shopify.com
Subdomain Takeover via Shopify Vendor ( blog.exchangemarketplace.com ) with Steps
Shopify Athena Bug
How to do 55.000+ Subdomain Takeover in a Blink of an Eye
Should this be public though?
How we tookover shopify accounts with one single click
Let’s steal some tokens!