Oh good, abused via an API. /s
Over the last 24 months, I have seen some weird increasing rate of vulnerable API endpoints in my own research. One of which would allow a bad actor direct access to over $2BB in funds (from a major organization worth more than $10BB), another plain-text credit card numbers and billing addresses (same application as the first); another were more plain-text credit card numbers (much smaller org, but still sizable). Both attacks were alarmingly non-trivial and would be scored as critical.
Why this trend is seemingly increasing, I don't know.