2 months free, then $29.95/mo.Start free trial
EstateSalesList.com

EstateSales.org Is Leaking Home Addresses, Phones, and Card Details

If you have an EstateSales.org account, your personal email, phone, credit/debit card information, and street address are in the public page.

EstateSalesList.com security research. EstateSales.org security vulnerability.

If you have an EstateSales.org account, we found a security vulnerability where anyone can read your private email address, phone number, credit/debit card information, and your home address.

On the surface, your profile page on EstateSales.org looks like there is no private information displayed. However, the underlying code that renders the page contains much more information than what is shown to you in the browser. A well-engineered website will only send the data that is necessary to render the page to the browser and leave private data out of the public view. EstateSales.org has made a series of security mistakes that leads to your data being exposed and allow phishing & other social engineering attacks.

How Anyone Can See Your Private Information

The first step is to understand how websites work.

When you open a webpage, the server sends a response to your browser that includes the page content, instructions for the browser on how to style it, and provides any data that the page may need. Some examples of this data are your company name, sale addresses, and the date you joined the platform.

The architectural mistake that EstateSales.org made is that they include private information in the response that is sent to the browser. This is a security vulnerability that allows anyone on the internet to see your private information. Anyone who knows where to look (every hacker and scammer immediately knows where to look) can see the private information for every single company profile on EstateSales.org. Shopper profiles leak email the same way.

With this information, a scammer could pose as EstateSales.org, your bank, or some other legitimate entity and ask you to update or verify your payment information. They would convince you that they are legitimate by repeating your full name, email, phone number, and credit card information. This is called phishing. EstateSales.org even has an article about how to spot phishing attacks.

Warning users about phishing attacks is a good thing. However when your platform makes it incredibly easy for a scammer to get ahold of the data required for a phishing attack, that is like warning people about a fire in your house, but not putting out the fire.

Open Redirect After Sign In

The next security vulnerability is called an open redirect vulnerability. Basically, after you sign in to EstateSales.org, an attacker can instruct the website to redirect you to any malicious website. This malicious website can look like the real EstateSales.org website and ask you to enter your email, password, or credit card information. Then, the attackers steal this information.

Hidden Sale Addresses

A critical safety feature is the ability to hide the estate sale address until right before the sale date. This prevents thieves from knowing the address, breaking in, and stealing the items.

On the surface, EstateSales.org appears to be successfully hiding the estate sale address and only showing the city, state, and zip code. However, EstateSales.org also has a public data endpoint for each sale that still returns the full street address while the listing is set to hidden. Anyone can request it without signing in, well before the sale date. This is like hiding your house keys under a rock on the front porch, but not locking the door.

A History of Being Slow to Fix Security Issues

EstateSales.org has a history of being slow to fix security issues with their website according to publicly available data.

One filing on June 6th, 2022 is for a bug that can let external scripts run inside the real site. Open Bug Bounty still lists it as unpatched. The same type of issue was reported on September 22nd, 2022 and is also still listed as unpatched.

There is also an open redirect vulnerability that was found on March 16th, 2025 and was not marked fixed until May 2nd, 2026. If you recall, we also found an open redirect vulnerability, showing that the bug was either not fixed or a new one was introduced.

Disclosure

We notified EstateSales.org of these issues on July 28th, 2026 through multiple channels. They have not responded to our emails nor have they fixed the security issues.

Conclusion

We are disclosing these vulnerabilities not to irrationally bash EstateSales.org, but rather for the best interests of EstateSales.org's customers.

EstateSalesList.com is a privacy-first estate sale listing platform, built with state-of-the-art technology and security in mind. Every line of code is carefully written to protect your privacy and security. If a security issue is found, we do not sleep until the bug is fixed and rolled out to all users.

If you want to switch to EstateSalesList.com and need help migrating, you can contact us at jeffrey@estatesaleslist.com or contact us here.