Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks
AI SAST Scanner
ERPNext 16.16.0 - Stored XSS in POS cart item rendering
4.8
Medium
CVE-2026-42839
Published date:
Jun 3, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Naveda
AI SAST Scanner
ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literals
5.1
Medium
CVE-2026-42840
Published date:
Jun 3, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Naveda
AI SAST Scanner
GLPI 11.0.0 - Stored XSS in knowledge base
8.4
High
CVE-2026-5385
Published date:
Jun 2, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
AI SAST Scanner
mailcow-dockerized 2026-03b - Stored XSS in Queue Manager
7.4
High
CVE-2026-7460
Published date:
May 18, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Naveda
AI SAST Scanner
Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping
6
Medium
CVE-2026-6093
Published date:
May 11, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
AI SAST Scanner
Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering
4.8
Medium
CVE-2026-40230
Published date:
Apr 29, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
AI SAST Scanner
Helpy 2.8.0 - Stored XSS in post author display via PostsHelper
5.1
Medium
CVE-2026-40229
Published date:
Apr 29, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
AI SAST Scanner
Pimcore Platform v12.3.3 - Stored XSS in Document Editable Embed rendering
4.8
Medium
CVE-2026-5362
Published date:
Apr 27, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Naveda
Load more
AI SAST Scanner
ERPNext 16.16.0 - Stored XSS in POS cart item rendering
4.8
Medium
CVE-2026-42839
Published date:
Jun 3, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Naveda
AI SAST Scanner
ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literals
5.1
Medium
CVE-2026-42840
Published date:
Jun 3, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Naveda
AI SAST Scanner
GLPI 11.0.0 - Stored XSS in knowledge base
8.4
High
CVE-2026-5385
Published date:
Jun 2, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
AI SAST Scanner
mailcow-dockerized 2026-03b - Stored XSS in Queue Manager
7.4
High
CVE-2026-7460
Published date:
May 18, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Naveda
AI SAST Scanner
Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping
6
Medium
CVE-2026-6093
Published date:
May 11, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
AI SAST Scanner
Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering
4.8
Medium
CVE-2026-40230
Published date:
Apr 29, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
AI SAST Scanner
Helpy 2.8.0 - Stored XSS in post author display via PostsHelper
5.1
Medium
CVE-2026-40229
Published date:
Apr 29, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
AI SAST Scanner
Pimcore Platform v12.3.3 - Stored XSS in Document Editable Embed rendering
4.8
Medium
CVE-2026-5362
Published date:
Apr 27, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Naveda
Load more
AI SAST Scanner
ERPNext 16.16.0 - Stored XSS in POS cart item rendering
4.8
Medium
CVE-2026-42839
Published date:
Jun 3, 2026
Discovered by
Oscar Naveda
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Naveda
AI SAST Scanner
ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literals
5.1
Medium
CVE-2026-42840
Published date:
Jun 3, 2026
Discovered by
Oscar Naveda
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Naveda
AI SAST Scanner
GLPI 11.0.0 - Stored XSS in knowledge base
8.4
High
CVE-2026-5385
Published date:
Jun 2, 2026
Discovered by
Oscar Uribe
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
AI SAST Scanner
mailcow-dockerized 2026-03b - Stored XSS in Queue Manager
7.4
High
CVE-2026-7460
Published date:
May 18, 2026
Discovered by
Oscar Naveda
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Naveda
AI SAST Scanner
Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping
6
Medium
CVE-2026-6093
Published date:
May 11, 2026
Discovered by
Oscar Uribe
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
AI SAST Scanner
Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering
4.8
Medium
CVE-2026-40230
Published date:
Apr 29, 2026
Discovered by
Oscar Uribe
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
AI SAST Scanner
Helpy 2.8.0 - Stored XSS in post author display via PostsHelper
5.1
Medium
CVE-2026-40229
Published date:
Apr 29, 2026
Discovered by
Oscar Uribe
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
AI SAST Scanner
Pimcore Platform v12.3.3 - Stored XSS in Document Editable Embed rendering
4.8
Medium
CVE-2026-5362
Published date:
Apr 27, 2026
Discovered by
Oscar Naveda
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Naveda
Load more


Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.


Start your 21-day free trial
Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.


Start your 21-day free trial
Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.


Start your 21-day free trial
Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.


Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.
Products
Targets
Subscribe to our newsletter
Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.
© 2026 Fluid Attacks. We hack your software.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.
Products
Targets
Subscribe to our newsletter
Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.
© 2026 Fluid Attacks. We hack your software.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.
Products
Targets
Subscribe to our newsletter
Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.
© 2026 Fluid Attacks. We hack your software.












