- Reported issue
- Improper Restriction of Excessive Authentication Attempts (login brute-force / credential stuffing)
- Date
- September 2026
- Status
- Fixed
Responsible disclosure
Better security is a shared responsibility.
Every responsible report helps us protect the people and organizations who trust AIHR with their data. Thank you for taking the time to make the platform stronger.
03
Researcher
2026
Latest report
100%
Resolved
Our researchers
Thank you for helping us improve
| Researcher | Reported issue | Date | Status |
|---|---|---|---|
| Improper Restriction of Excessive Authentication Attempts (login brute-force / credential stuffing) | September 2026 | Fixed | |
NBNishant Singh Bhaisora | Information Disclosure via robots.txt & Missing Anti-Framing Protections (Clickjacking) | September 2026 | Fixed |
VRVivek Rajendra Udane | Hyperlink Injection & Insufficient Phone Number Validation | September 2026 | Fixed |
NB
Nishant Singh Bhaisora
Security researcher
- Reported issue
- Information Disclosure via robots.txt & Missing Anti-Framing Protections (Clickjacking)
- Date
- September 2026
- Status
- Fixed
VR
Vivek Rajendra Udane
Security researcher
- Reported issue
- Hyperlink Injection & Insufficient Phone Number Validation
- Date
- September 2026
- Status
- Fixed
Found a security issue?
Please report it responsibly so our team can investigate.