#WAF Bypass
2 postsBugForge - Daily - Tanuki (Jul 14, 2026)
Tanuki's XML deck import blacklists the single quote and numeric entities on the deck name, but allows the standard ' entity, which decodes to a quote and reaches a concatenated SQL query.
SQLi SQL Injection Injection Xml Filter Bypass WAF Bypass Sqlite
Posted on 2026-07-14 20:00 7 min read
BugForge - Weekly - Fur Hire (Mar 14, 2026)
This walkthrough demonstrates a chained attack against a job recruitment application protected by a WAF. The application reflects unsanitised input in the…
XSS WAF Bypass CSRF
Posted on 2026-03-14 09:00 7 min read