← All series

Cafe Club

Daily · 8 writeups

A recurring daily challenge — each entry covers a different vulnerability. Listed oldest to newest.

BugForge - Daily - Cafe Club (Dec 28, 2025)

This vulnerability is a business logic flaw involving predictable identifiers and brute force, where gift card codes are generated with insufficient entropy…

Brute Force Business Logic Flaw
Posted on 2025-12-28 20:00 5 min read
BugForge - Daily - Cafe Club

BugForge - Daily - Cafe Club (Jan 4, 2026)

This challenge exploits a business logic vulnerability in the checkout process where the server fails to validate the points_to_use parameter against the…

Business Logic Flaw
Posted on 2026-01-04 20:00 5 min read
BugForge - Daily - Cafe Club

BugForge - Daily - Cafe Club (Jan 11, 2026)

A SQL Injection vulnerability exists in the product API endpoint where the product ID parameter is directly concatenated into a SQLite query without…

SQLi Sqlite
Posted on 2026-01-11 20:00 4 min read
BugForge - Daily - Cafe Club

BugForge - Daily - Cafe Club (Jan 18, 2026)

This challenge exploits a path traversal vulnerability in the application's image retrieval functionality where the server fails to sanitize user-supplied…

Path Traversal LFI
Posted on 2026-01-18 20:00 4 min read
BugForge - Daily - Cafe Club

BugForge - Daily - Cafe Club (Jan 25, 2026)

This challenge exploits a TOCTOU (Time-of-Check Time-of-Use) race condition in the checkout flow where the cart is read twice without synchronization, once for…

Race Condition Toctou
Posted on 2026-01-25 20:00 5 min read
BugForge - Daily - Cafe Club

BugForge - Daily - Cafe Club (Feb 8, 2026)

This challenge exploits an Insecure Direct Object Reference (IDOR) vulnerability in the profile password update functionality. The application includes the…

IDOR
Posted on 2026-02-08 19:00 4 min read
BugForge - Daily - Cafe Club

BugForge - Daily - Cafe Club (Mar 1, 2026)

The Cafe Club application contains a Path Traversal vulnerability in its product image loading endpoint. The endpoint accepts a user-controlled file path…

File Inclusion Path Traversal
Posted on 2026-03-01 19:00 3 min read
BugForge - Daily - Cafe Club

BugForge - Daily - Cafe Club (Mar 15, 2026)

The Cafe Club application contains a Business Logic Flaw in its PUT /api/profile endpoint. The endpoint accepts a user-controlled JSON body and applies all…

Broken Access Control
Posted on 2026-03-15 19:00 4 min read
BugForge - Daily - Cafe Club
Zw4rts

© 2026 Zw4rts. All rights reserved.

GitHub