Forem

YogSec profile picture

YogSec

YogSec is a web security research initiative. We analyze how web applications break, why vulnerabilities happen, and how developers can fix them.

Work

YogSec - Web Application Security

How a Simple “Upload by Link” Feature Can Hack Your Own Servers
Cover image for How a Simple “Upload by Link” Feature Can Hack Your Own Servers

How a Simple “Upload by Link” Feature Can Hack Your Own Servers

Comments
2 min read
A Silent Website Killer: SSRF Bugs in APIs
Cover image for A Silent Website Killer: SSRF Bugs in APIs

A Silent Website Killer: SSRF Bugs in APIs

Comments
3 min read
Why BOLA Is #1 in OWASP API Top 10
Cover image for Why BOLA Is #1 in OWASP API Top 10

Why BOLA Is #1 in OWASP API Top 10

Comments
3 min read
Authentication vs Object Authorization: The API Security Mistake Everyone Makes
Cover image for Authentication vs Object Authorization: The API Security Mistake Everyone Makes

Authentication vs Object Authorization: The API Security Mistake Everyone Makes

Comments
3 min read
What BOLA Really Means in APIs (And Why UI Authorization Is Not Security)
Cover image for What BOLA Really Means in APIs (And Why UI Authorization Is Not Security)

What BOLA Really Means in APIs (And Why UI Authorization Is Not Security)

Comments
3 min read
Understanding APIs Beyond the Textbook: A Bug Hunter’s Perspective
Cover image for Understanding APIs Beyond the Textbook: A Bug Hunter’s Perspective

Understanding APIs Beyond the Textbook: A Bug Hunter’s Perspective

Comments
2 min read
BugBoard: A Centralized Dashboard for Bug Bounty Hunters & Security Researchers

BugBoard: A Centralized Dashboard for Bug Bounty Hunters & Security Researchers

Comments
3 min read
DorkTerm: A Simple Tool That Makes Websites Safer
Cover image for DorkTerm: A Simple Tool That Makes Websites Safer

DorkTerm: A Simple Tool That Makes Websites Safer

Comments
2 min read
One-Liner Bug Bounty CheatSheet
Cover image for One-Liner Bug Bounty CheatSheet

One-Liner Bug Bounty CheatSheet

1
Comments
53 min read
CVE-2025-5419 - Google Chrome V8 Engine Out-of-Bounds Read/Write Vulnerability
Cover image for CVE-2025-5419 - Google Chrome V8 Engine Out-of-Bounds Read/Write Vulnerability

CVE-2025-5419 - Google Chrome V8 Engine Out-of-Bounds Read/Write Vulnerability

Comments
9 min read
CVE-2026-0831 - Arbitrary File Write Vulnerability in WordPress Templately Plugin
Cover image for CVE-2026-0831 - Arbitrary File Write Vulnerability in WordPress Templately Plugin

CVE-2026-0831 - Arbitrary File Write Vulnerability in WordPress Templately Plugin

Comments
12 min read
CVE-2026-0629 - TP-Link Camera Authentication Bypass Vulnerability
Cover image for CVE-2026-0629 - TP-Link Camera Authentication Bypass Vulnerability

CVE-2026-0629 - TP-Link Camera Authentication Bypass Vulnerability

5
Comments
11 min read
CVE-2026-21268 - Adobe Dreamweaver Input Validation Vulnerability
Cover image for CVE-2026-21268 - Adobe Dreamweaver Input Validation Vulnerability

CVE-2026-21268 - Adobe Dreamweaver Input Validation Vulnerability

5
Comments
11 min read
CVE-2026-0594 - Reflected Cross-Site Scripting (XSS) in WordPress
Cover image for CVE-2026-0594 - Reflected Cross-Site Scripting (XSS) in WordPress

CVE-2026-0594 - Reflected Cross-Site Scripting (XSS) in WordPress

5
Comments
10 min read
CVE-2026-0712 - Grafana Open Redirect Leading to Cross-Site Scripting (XSS) Vulnerability
Cover image for CVE-2026-0712 - Grafana Open Redirect Leading to Cross-Site Scripting (XSS) Vulnerability

CVE-2026-0712 - Grafana Open Redirect Leading to Cross-Site Scripting (XSS) Vulnerability

5
Comments
9 min read
Understanding WordPress Architecture for Pentesters
Cover image for Understanding WordPress Architecture for Pentesters

Understanding WordPress Architecture for Pentesters

Comments
2 min read
Scam Alert!
Cover image for Scam Alert!

Scam Alert!

Comments
1 min read
Best Hacking Tools for Bug Bounty & Penetration Testing | A Complete Open-Source Collection (Updated Guide)
Cover image for Best Hacking Tools for Bug Bounty & Penetration Testing | A Complete Open-Source Collection (Updated Guide)

Best Hacking Tools for Bug Bounty & Penetration Testing | A Complete Open-Source Collection (Updated Guide)

Comments
1 min read
Can My Ex Still See My Photos After I Deleted Them?

Can My Ex Still See My Photos After I Deleted Them?

Comments
1 min read
How a Blog Lost All Its Data in One Night

How a Blog Lost All Its Data in One Night

Comments
1 min read
What is YogSec?

What is YogSec?

Comments
1 min read
Case Study: How a Small Shop’s Website Got Hacked and How It Was Saved

Case Study: How a Small Shop’s Website Got Hacked and How It Was Saved

Comments
1 min read
Case Study: How a Small WordPress Blog Almost Lost Everything

Case Study: How a Small WordPress Blog Almost Lost Everything

Comments
1 min read
SQL Injection - The Silent Break-In You Didn’t Know About
Cover image for SQL Injection - The Silent Break-In You Didn’t Know About

SQL Injection - The Silent Break-In You Didn’t Know About

Comments
2 min read
Who is Abhinav Singwal?

Who is Abhinav Singwal?

Comments
1 min read
Found a CORS Misconfiguration on a Live Website

Found a CORS Misconfiguration on a Live Website

Comments
1 min read
Real Case Study: How I Found a Photo Exposure Bug on a Website
Cover image for Real Case Study: How I Found a Photo Exposure Bug on a Website

Real Case Study: How I Found a Photo Exposure Bug on a Website

Comments
1 min read
How to Install and Use Virtualenv on Linux
Cover image for How to Install and Use Virtualenv on Linux

How to Install and Use Virtualenv on Linux

Comments
1 min read
Get a Free Privacy Check, See What You're Exposing Online

Get a Free Privacy Check, See What You're Exposing Online

Comments
1 min read
Introducing BugBoard - An Open Source Dashboard for Bug Bounty Hunters

Introducing BugBoard - An Open Source Dashboard for Bug Bounty Hunters

Comments
1 min read
This Google trick shows exposed backups of websites

This Google trick shows exposed backups of websites

Comments
1 min read
How to Secure Your Website from Cyber Threats

How to Secure Your Website from Cyber Threats

Comments
2 min read
Essential Tips to Secure Your WordPress Website

Essential Tips to Secure Your WordPress Website

Comments
3 min read
Bug Bounty One-Liner Cheat Codes & Cheatsheet

Bug Bounty One-Liner Cheat Codes & Cheatsheet

Comments
2 min read
Introducing YogSec - Personal Online Security Audit Service

Introducing YogSec - Personal Online Security Audit Service

Comments
1 min read
loading...