Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks

Search by term

Search filters

Discovered by

All

Severity

All

External pentesters

i-Educar 2.10.0 - Stored Cross-Site Scripting (XSS) in admin panel

4.8

Medium

CVE-2025-9638

Published date:

Dec 9, 2025

Discovered by

Marcelo Queiroz

Our pentesters

Frappe Helpdesk 1.14.0 — SQL Injection in dashboard get_dashboard_data

8.6

High

CVE-2025-10655

Published date:

Dec 9, 2025

Discovered by

Cristian Vargas

Our pentesters

Frappe CRM 1.53.1 — Multiple SQL Injections in Dashboard Controller

7.1

High

CVE-2025-11461

Published date:

Nov 26, 2025

Discovered by

Cristian Vargas

Our pentesters

OpenSearch 3.2.0 - Nested Boolean/Disjunction Asymmetric DoS

8.3

High

CVE-2025-9624

Published date:

Nov 25, 2025

Discovered by

Camilo Vera

Our pentesters

iStat Menus 7.10.4 - Local Privilege Escalation

9.3

Critical

CVE-2025-11921

Published date:

Nov 7, 2025

Discovered by

Oscar Uribe

Our pentesters

OpenSupports 4.11.0 — SSRF via test imap and smtp endpoints

6.9

Medium

CVE-2025-10695

Published date:

Oct 3, 2025

Discovered by

Cristian Vargas

Our pentesters

MacForge 1.2.0 Beta 1 - Local Privilege Escalation

9.3

Critical

CVE-2025-10751

Published date:

Oct 3, 2025

Discovered by

Oscar Uribe

Our pentesters

OpenSupports 4.11.0 — Insecure Direct Object Reference in supervised list

7.1

High

CVE-2025-10696

Published date:

Oct 3, 2025

Discovered by

Cristian Vargas

Load more

Search by term

Search filters

Discovered by

All

Severity

All

External pentesters

i-Educar 2.10.0 - Stored Cross-Site Scripting (XSS) in admin panel

4.8

Medium

CVE-2025-9638

Published date:

Dec 9, 2025

Discovered by

Marcelo Queiroz

Our pentesters

Frappe Helpdesk 1.14.0 — SQL Injection in dashboard get_dashboard_data

8.6

High

CVE-2025-10655

Published date:

Dec 9, 2025

Discovered by

Cristian Vargas

Our pentesters

Frappe CRM 1.53.1 — Multiple SQL Injections in Dashboard Controller

7.1

High

CVE-2025-11461

Published date:

Nov 26, 2025

Discovered by

Cristian Vargas

Our pentesters

OpenSearch 3.2.0 - Nested Boolean/Disjunction Asymmetric DoS

8.3

High

CVE-2025-9624

Published date:

Nov 25, 2025

Discovered by

Camilo Vera

Our pentesters

iStat Menus 7.10.4 - Local Privilege Escalation

9.3

Critical

CVE-2025-11921

Published date:

Nov 7, 2025

Discovered by

Oscar Uribe

Our pentesters

OpenSupports 4.11.0 — SSRF via test imap and smtp endpoints

6.9

Medium

CVE-2025-10695

Published date:

Oct 3, 2025

Discovered by

Cristian Vargas

Our pentesters

MacForge 1.2.0 Beta 1 - Local Privilege Escalation

9.3

Critical

CVE-2025-10751

Published date:

Oct 3, 2025

Discovered by

Oscar Uribe

Our pentesters

OpenSupports 4.11.0 — Insecure Direct Object Reference in supervised list

7.1

High

CVE-2025-10696

Published date:

Oct 3, 2025

Discovered by

Cristian Vargas

Load more

Search by term

Search filters

Discovered by

All

Severity

All

External pentesters

i-Educar 2.10.0 - Stored Cross-Site Scripting (XSS) in admin panel

4.8

Medium

CVE-2025-9638

Published date:

Dec 9, 2025

Discovered by

Marcelo Queiroz

Our pentesters

Frappe Helpdesk 1.14.0 — SQL Injection in dashboard get_dashboard_data

8.6

High

CVE-2025-10655

Published date:

Dec 9, 2025

Discovered by

Cristian Vargas

Our pentesters

Frappe CRM 1.53.1 — Multiple SQL Injections in Dashboard Controller

7.1

High

CVE-2025-11461

Published date:

Nov 26, 2025

Discovered by

Cristian Vargas

Our pentesters

OpenSearch 3.2.0 - Nested Boolean/Disjunction Asymmetric DoS

8.3

High

CVE-2025-9624

Published date:

Nov 25, 2025

Discovered by

Camilo Vera

Our pentesters

iStat Menus 7.10.4 - Local Privilege Escalation

9.3

Critical

CVE-2025-11921

Published date:

Nov 7, 2025

Discovered by

Oscar Uribe

Our pentesters

OpenSupports 4.11.0 — SSRF via test imap and smtp endpoints

6.9

Medium

CVE-2025-10695

Published date:

Oct 3, 2025

Discovered by

Cristian Vargas

Our pentesters

MacForge 1.2.0 Beta 1 - Local Privilege Escalation

9.3

Critical

CVE-2025-10751

Published date:

Oct 3, 2025

Discovered by

Oscar Uribe

Our pentesters

OpenSupports 4.11.0 — Insecure Direct Object Reference in supervised list

7.1

High

CVE-2025-10696

Published date:

Oct 3, 2025

Discovered by

Cristian Vargas

Load more

Search by term

Search filters

Discovered by

All

Severity

All

External pentesters

i-Educar 2.10.0 - Stored Cross-Site Scripting (XSS) in admin panel

4.8

Medium

CVE-2025-9638

Published date:

Dec 9, 2025

Discovered by

Marcelo Queiroz

Our pentesters

Frappe Helpdesk 1.14.0 — SQL Injection in dashboard get_dashboard_data

8.6

High

CVE-2025-10655

Published date:

Dec 9, 2025

Discovered by

Cristian Vargas

Our pentesters

Frappe CRM 1.53.1 — Multiple SQL Injections in Dashboard Controller

7.1

High

CVE-2025-11461

Published date:

Nov 26, 2025

Discovered by

Cristian Vargas

Our pentesters

OpenSearch 3.2.0 - Nested Boolean/Disjunction Asymmetric DoS

8.3

High

CVE-2025-9624

Published date:

Nov 25, 2025

Discovered by

Camilo Vera

Our pentesters

iStat Menus 7.10.4 - Local Privilege Escalation

9.3

Critical

CVE-2025-11921

Published date:

Nov 7, 2025

Discovered by

Oscar Uribe

Our pentesters

OpenSupports 4.11.0 — SSRF via test imap and smtp endpoints

6.9

Medium

CVE-2025-10695

Published date:

Oct 3, 2025

Discovered by

Cristian Vargas

Our pentesters

MacForge 1.2.0 Beta 1 - Local Privilege Escalation

9.3

Critical

CVE-2025-10751

Published date:

Oct 3, 2025

Discovered by

Oscar Uribe

Our pentesters

OpenSupports 4.11.0 — Insecure Direct Object Reference in supervised list

7.1

High

CVE-2025-10696

Published date:

Oct 3, 2025

Discovered by

Cristian Vargas

Load more

Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.

Start your 21-day free trial

Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.

Start your 21-day free trial

Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.

Start your 21-day free trial

Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.

Get an AI summary of Fluid Attacks

Subscribe to our newsletter

Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.

© 2025 Fluid Attacks. We hack your software.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.

Subscribe to our newsletter

Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.

Get an AI summary of Fluid Attacks

© 2025 Fluid Attacks. We hack your software.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.

Subscribe to our newsletter

Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.

Get an AI summary of Fluid Attacks

© 2025 Fluid Attacks. We hack your software.