Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks

Search by term

Search filters

Discovered by

All

Severity

All

AI SAST Scanner

LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB

6

Medium

CVE-2026-18403

Published date:

Aug 14, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

AI SAST Scanner

LimeSurvey Community Edition 7.0.5 - Reflected XSS in HTML editor popup

8.5

High

CVE-2026-63361

Published date:

Aug 14, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

Our pentesters

Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation

7.5

High

CVE-2026-10716

Published date:

Aug 5, 2026

Discovered by

Santiago Alvarez and Oscar Naveda

Our pentesters

ERPNext v16.25.0 - Improper authorization in Prospect opportunities API

7.1

High

CVE-2026-13227

Published date:

Aug 4, 2026

Discovered by

Eduardo Ferguson

AI SAST Scanner

Zammad 7.0.1 - Improper authorization in ticket article attachment cloning

7.1

High

CVE-2026-13229

Published date:

Aug 4, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

External pentesters

osTicket v1.18.3 - v1,17.7 - BOLA/IDOR in ticket field viewing allows cross-department data disclosure

7.1

High

CVE-2026-14871

Published date:

Jul 17, 2026

Discovered by

Juan Felipe Osorio Z

External pentesters

openSIS Classic 9.3 - Authenticated path traversal in SentMail attachment download

5.3

Medium

CVE-2026-11944

Published date:

Jul 9, 2026

Discovered by

Daniel Esteban Celis

Our pentesters

PayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlock access

5.3

Medium

CVE-2026-11779

Published date:

Jun 26, 2026

Discovered by

Oscar Naveda

Load more

Search by term

Search filters

Discovered by

All

Severity

All

AI SAST Scanner

LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB

6

Medium

CVE-2026-18403

Published date:

Aug 14, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

AI SAST Scanner

LimeSurvey Community Edition 7.0.5 - Reflected XSS in HTML editor popup

8.5

High

CVE-2026-63361

Published date:

Aug 14, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

Our pentesters

Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation

7.5

High

CVE-2026-10716

Published date:

Aug 5, 2026

Discovered by

Santiago Alvarez and Oscar Naveda

Our pentesters

ERPNext v16.25.0 - Improper authorization in Prospect opportunities API

7.1

High

CVE-2026-13227

Published date:

Aug 4, 2026

Discovered by

Eduardo Ferguson

AI SAST Scanner

Zammad 7.0.1 - Improper authorization in ticket article attachment cloning

7.1

High

CVE-2026-13229

Published date:

Aug 4, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

External pentesters

osTicket v1.18.3 - v1,17.7 - BOLA/IDOR in ticket field viewing allows cross-department data disclosure

7.1

High

CVE-2026-14871

Published date:

Jul 17, 2026

Discovered by

Juan Felipe Osorio Z

External pentesters

openSIS Classic 9.3 - Authenticated path traversal in SentMail attachment download

5.3

Medium

CVE-2026-11944

Published date:

Jul 9, 2026

Discovered by

Daniel Esteban Celis

Our pentesters

PayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlock access

5.3

Medium

CVE-2026-11779

Published date:

Jun 26, 2026

Discovered by

Oscar Naveda

Load more

Search by term

Search filters

Discovered by

All

Severity

All

AI SAST Scanner

LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB

6

Medium

CVE-2026-18403

Published date:

Aug 14, 2026

Discovered by

Miguel Gómez

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

AI SAST Scanner

LimeSurvey Community Edition 7.0.5 - Reflected XSS in HTML editor popup

8.5

High

CVE-2026-63361

Published date:

Aug 14, 2026

Discovered by

Miguel Gómez

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

Our pentesters

Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation

7.5

High

CVE-2026-10716

Published date:

Aug 5, 2026

Discovered by

Santiago Alvarez and Oscar Naveda

Our pentesters

ERPNext v16.25.0 - Improper authorization in Prospect opportunities API

7.1

High

CVE-2026-13227

Published date:

Aug 4, 2026

Discovered by

Eduardo Ferguson

AI SAST Scanner

Zammad 7.0.1 - Improper authorization in ticket article attachment cloning

7.1

High

CVE-2026-13229

Published date:

Aug 4, 2026

Discovered by

Oscar Naveda

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

External pentesters

osTicket v1.18.3 - v1,17.7 - BOLA/IDOR in ticket field viewing allows cross-department data disclosure

7.1

High

CVE-2026-14871

Published date:

Jul 17, 2026

Discovered by

Juan Felipe Osorio Z

External pentesters

openSIS Classic 9.3 - Authenticated path traversal in SentMail attachment download

5.3

Medium

CVE-2026-11944

Published date:

Jul 9, 2026

Discovered by

Daniel Esteban Celis

Our pentesters

PayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlock access

5.3

Medium

CVE-2026-11779

Published date:

Jun 26, 2026

Discovered by

Oscar Naveda

Load more

Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.

Start your 21-day free trial

Discover the benefits of the Fluid Attacks solution, which organizations of all sizes are already enjoying.

Start your 21-day free trial

Discover the benefits of the Fluid Attacks solution, which organizations of all sizes are already enjoying.

Start your 21-day free trial

Discover the benefits of the Fluid Attacks solution, which organizations of all sizes are already enjoying.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.

Get an AI summary of Fluid Attacks

Subscribe to our newsletter

Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.

Subscribe to our newsletter

Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.

Get an AI summary of Fluid Attacks

Subscribe to our newsletter

Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.

Get an AI summary of Fluid Attacks