Report #3037447 – Stored XSS on TikTok's backend leads to the leakage of highly sensitive …
A stored cross-site scripting vulnerability was found in TikTok's contact form backend. When malicious code […]
Read moreDaily news about TikTok – fresh news, every day
A stored cross-site scripting vulnerability was found in TikTok's contact form backend. When malicious code […]
Read more
A broken access control vulnerability in TikTok Live Backstage allowed low-privilege users (group members and […]
Read more
An Insecure Direct Object Reference (IDOR) vulnerability was found on a TikTok LIVE backend platform, […]
Read more
An Insecure Direct Object Reference (IDOR) vulnerability was found on a TikTok Ads API, which […]
Read more
A vulnerability on a TikTok endpoint was found that could have resulted in unauthorized viewing […]
Read more
Within the "Search Product" function in TikTok Shop Seller API, the ability to access inactive […]
Read more
An improper authentication mechanism in TikTok's account recovery process could have been used for account […]
Read more
An open redirection vulnerability was found via a path traversal on the 'redirect_url' parameter when […]
Read more
A Cross-Site Scripting (XSS) vulnerability was found on two TikTok incentive endpoints, due to the […]
Read more
API on TikTok Webcast endpoints prevent CSRF by validating the Origin header which indicates the […]
Read more
A Cross-Site Scripting (XSS) vulnerability was found on a TikTok Ads endpoint via the "settings" […]
Read more
A blind stored Cross-Site Scripting (XSS) vulnerability was found on a TikTok Ads domain via […]
Read more
Stored Cross-Site Scripting (XSS) was found on the "Edit Product" page of a TikTok Seller […]
Read more
An IDOR (Insecure Direct Object Reference) vulnerability was found on the "org_id" and "account_id" parameters […]
Read more
A broken link was found on TikTok Newsroom, which could have allowed an attacker to […]
Read more
A XSS (cross-site scripting) vulnerability was found on a TikTok ads endpoint using the "from" […]
Read more
A XSS (cross-site scripting) vulnerability was found in TikTok ads through "text" field. We thank […]
Read more
Information Disclosure on TikTok Unplugged Site. Share: Summary by TikTok. An attacker could have retrieved […]
Read more
A CSRF (Cross Site Request Forgery) vulnerability was reported in TikTok's QR code login which […]
Read more
The video upload endpoint on the TikTok Ads portal was potentially susceptible to remote code […]
Read more