> For the complete documentation index, see [llms.txt](https://gowthams.gitbook.io/bughunter-handbook/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://gowthams.gitbook.io/bughunter-handbook/intresting-vulnerabilities/graphql.md).

# GraphQL

* <https://carvesystems.com/news/the-5-most-common-graphql-security-vulnerabilities/?mkt_tok=eyJpIjoiTWpnMU5EWXdZekk0TnpneSIsInQiOiJHVlR6R2NFcEM5ZzgwNWtrajZzQzBQaTR0UmplRXhLSHZFcDhwNGRcL1JHYnJHaTQ0YlNQODNOSjFpNmNlSjB0bHF2T1JzRWkzSit6TktKSks2dld1VjNIS0lXNHJqUG1NanM3UVowWjVrWFhmYVJQTGQ2a3dWYmgyKzFzeGtjSlIifQ%3D%3D>
* <https://medium.com/@localh0t/discovering-graphql-endpoints-and-sqli-vulnerabilities-5d39f26cea2e>

{% embed url="<https://twitter.com/infosec_au/status/1435382712383119360?s=20>" %}
