Clickjacking
Disclosed: 2025-08-22
Clickjacking via CyfareGPT Export
Report vulnerabilities in cyfare.net and earn your spot on our wall of gratitude. We appreciate responsible disclosure and celebrate all researchers who help keep our users safe.
Security researchers who have helped make Cyfare more secure
Disclosed: 2025-08-22
Clickjacking via CyfareGPT Export
Disclosed: 2025-06-13
DNS Rebinding via Link Shortner
Disclosed: 2025-06-11
HTML Injection filter evasion (bypass) in CyfareGPT Chat
Disclosed: 2025-06-07
Reflected XSS filter evasion (bypass) in CyfareGPT Chat
Disclosed: 2025-01-31
Inadequate HSTS implementation and missing secure flag for cookies.
Disclosed: 2024-12-04
Reflected XSS in CyfareGPT Chat
Disclosed: 2024-11-03
Application DoS via JSON Injection Throughout Site
Honoring disclosures that don't match the vulnerability criteria for cyfare.net, but are valid issues in most scenarios.
Disclosed: 2025-06-12
Cyfare File Upload allows users to upload any type of file (could be malicious file) without rejection.
We respond quickly to high-impact reports and credit all valid disclosures here.
security@cyfare.net