Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks

Search by term

Search filters

Discovered by

All

Severity

All

AI SAST Scanner

Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering

4.8

Medium

CVE-2026-40230

Published date:

Apr 29, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Helpy 2.8.0 - Stored XSS in post author display via PostsHelper

5.1

Medium

CVE-2026-40229

Published date:

Apr 29, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Pimcore Platform v12.3.3 - Stored XSS in Document Editable Embed rendering

4.8

Medium

CVE-2026-5362

Published date:

Apr 27, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

Pimcore Platform v12.3.3 - SQL Injection in DataObject composite index handling

7

High

CVE-2026-5394

Published date:

Apr 27, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

Frappe Framework v16.10.0 - Stored DOM XSS in Multiple Field Formatters

4.6

Medium

CVE-2026-3837

Published date:

Apr 21, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Frappe Framework 16.10.0 - Stored DOM XSS in Tag Pill Renderer

4.6

Medium

CVE-2026-3673

Published date:

Apr 21, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Our pentesters

DOMPurify mXSS via Re-Contextualization

5.3

Medium

CVE-2026-0540

Published date:

Mar 24, 2026

Discovered by

Camilo Vera, Cristian Vargas and Scott Moore

External pentesters

Actual Sync Server 26.2.1 - Authenticated Path Traversal

5.3

Medium

CVE-2026-3089

Published date:

Mar 9, 2026

Discovered by

Juan Patarroyo

Load more

Search by term

Search filters

Discovered by

All

Severity

All

AI SAST Scanner

Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering

4.8

Medium

CVE-2026-40230

Published date:

Apr 29, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Helpy 2.8.0 - Stored XSS in post author display via PostsHelper

5.1

Medium

CVE-2026-40229

Published date:

Apr 29, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Pimcore Platform v12.3.3 - Stored XSS in Document Editable Embed rendering

4.8

Medium

CVE-2026-5362

Published date:

Apr 27, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

Pimcore Platform v12.3.3 - SQL Injection in DataObject composite index handling

7

High

CVE-2026-5394

Published date:

Apr 27, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

Frappe Framework v16.10.0 - Stored DOM XSS in Multiple Field Formatters

4.6

Medium

CVE-2026-3837

Published date:

Apr 21, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Frappe Framework 16.10.0 - Stored DOM XSS in Tag Pill Renderer

4.6

Medium

CVE-2026-3673

Published date:

Apr 21, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Our pentesters

DOMPurify mXSS via Re-Contextualization

5.3

Medium

CVE-2026-0540

Published date:

Mar 24, 2026

Discovered by

Camilo Vera, Cristian Vargas and Scott Moore

External pentesters

Actual Sync Server 26.2.1 - Authenticated Path Traversal

5.3

Medium

CVE-2026-3089

Published date:

Mar 9, 2026

Discovered by

Juan Patarroyo

Load more

Search by term

Search filters

Discovered by

All

Severity

All

AI SAST Scanner

Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering

4.8

Medium

CVE-2026-40230

Published date:

Apr 29, 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Helpy 2.8.0 - Stored XSS in post author display via PostsHelper

5.1

Medium

CVE-2026-40229

Published date:

Apr 29, 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Pimcore Platform v12.3.3 - Stored XSS in Document Editable Embed rendering

4.8

Medium

CVE-2026-5362

Published date:

Apr 27, 2026

Discovered by

Oscar Naveda

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

Pimcore Platform v12.3.3 - SQL Injection in DataObject composite index handling

7

High

CVE-2026-5394

Published date:

Apr 27, 2026

Discovered by

Oscar Naveda

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

Frappe Framework v16.10.0 - Stored DOM XSS in Multiple Field Formatters

4.6

Medium

CVE-2026-3837

Published date:

Apr 21, 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Frappe Framework 16.10.0 - Stored DOM XSS in Tag Pill Renderer

4.6

Medium

CVE-2026-3673

Published date:

Apr 21, 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Our pentesters

DOMPurify mXSS via Re-Contextualization

5.3

Medium

CVE-2026-0540

Published date:

Mar 24, 2026

Discovered by

Camilo Vera, Cristian Vargas and Scott Moore

External pentesters

Actual Sync Server 26.2.1 - Authenticated Path Traversal

5.3

Medium

CVE-2026-3089

Published date:

Mar 9, 2026

Discovered by

Juan Patarroyo

Load more

Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.

Start your 21-day free trial

Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.

Start your 21-day free trial

Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.

Start your 21-day free trial

Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.

Get an AI summary of Fluid Attacks

Subscribe to our newsletter

Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.

© 2026 Fluid Attacks. We hack your software.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.

Subscribe to our newsletter

Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.

Get an AI summary of Fluid Attacks

© 2026 Fluid Attacks. We hack your software.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.

Subscribe to our newsletter

Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.

Get an AI summary of Fluid Attacks

© 2026 Fluid Attacks. We hack your software.