Dark C0d3rs
HackerOne Disclosed Reports - 2025-08-03 - Printable Version

+- Dark C0d3rs (https://darkcoders.wiki)
+-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log)
+--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports)
+--- Thread: HackerOne Disclosed Reports - 2025-08-03 (/Thread-HackerOne-Disclosed-Reports-2025-08-03)



HackerOne disclosed reports - 2025-08-03 - hashXploiter - 08-04-2025

Logo
Medium
resolved

Unauthorized Disclosure of Private Emails via WakaTime Private Leaderboards


Bug reported by was disclosed at August 3, 2025, 3:23 am   |   Information Disclosure

The vulnerability allowed unauthorized disclosure of private email addresses of WakaTime users through the private leaderboards feature. The email addresses were exposed to leaderboard creators and members, even when the users had not chosen to make their emails public.