2026

RESPONSIBLE DISCLOSURE
by Marcel

Motokeska.cz – Payment Bypass for Free Vouchers, Plus QR Token Leaks and Location Exposure

Five flaws on motokeska.cz: a payment bypass handing out free vouchers, leaked QR tokens, and profile photos exposing GPS location.

broken-access-controllogic-flawprivacy-riskresponsible-disclosure
CZK 25,000
RESPONSIBLE DISCLOSURE
by Marcel

Planetum.cz – Chained Vulnerabilities Led to RCE

A single SQL injection on observatory.cz opened a chain that ended in administrative access and Remote Code Execution on planetum.cz — plus three further findings.

attack-chainsql-injectionremote-code-executionlateral-movementcrackingprivacy-riskxssresponsible-disclosure
declined