Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks
AI SAST Scanner
Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering
4.8
Medium
CVE-2026-40230
Published date:
Apr 29, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
AI SAST Scanner
Helpy 2.8.0 - Stored XSS in post author display via PostsHelper
5.1
Medium
CVE-2026-40229
Published date:
Apr 29, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
AI SAST Scanner
Pimcore Platform v12.3.3 - Stored XSS in Document Editable Embed rendering
4.8
Medium
CVE-2026-5362
Published date:
Apr 27, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Naveda
AI SAST Scanner
Pimcore Platform v12.3.3 - SQL Injection in DataObject composite index handling
7
High
CVE-2026-5394
Published date:
Apr 27, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Naveda
AI SAST Scanner
Frappe Framework v16.10.0 - Stored DOM XSS in Multiple Field Formatters
4.6
Medium
CVE-2026-3837
Published date:
Apr 21, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
AI SAST Scanner
Frappe Framework 16.10.0 - Stored DOM XSS in Tag Pill Renderer
4.6
Medium
CVE-2026-3673
Published date:
Apr 21, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
Our pentesters
DOMPurify mXSS via Re-Contextualization
5.3
Medium
CVE-2026-0540
Published date:
Mar 24, 2026
Discovered by
Camilo Vera, Cristian Vargas and Scott Moore
External pentesters
Actual Sync Server 26.2.1 - Authenticated Path Traversal
5.3
Medium
CVE-2026-3089
Published date:
Mar 9, 2026
Discovered by
Juan Patarroyo
Load more
AI SAST Scanner
Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering
4.8
Medium
CVE-2026-40230
Published date:
Apr 29, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
AI SAST Scanner
Helpy 2.8.0 - Stored XSS in post author display via PostsHelper
5.1
Medium
CVE-2026-40229
Published date:
Apr 29, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
AI SAST Scanner
Pimcore Platform v12.3.3 - Stored XSS in Document Editable Embed rendering
4.8
Medium
CVE-2026-5362
Published date:
Apr 27, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Naveda
AI SAST Scanner
Pimcore Platform v12.3.3 - SQL Injection in DataObject composite index handling
7
High
CVE-2026-5394
Published date:
Apr 27, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Naveda
AI SAST Scanner
Frappe Framework v16.10.0 - Stored DOM XSS in Multiple Field Formatters
4.6
Medium
CVE-2026-3837
Published date:
Apr 21, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
AI SAST Scanner
Frappe Framework 16.10.0 - Stored DOM XSS in Tag Pill Renderer
4.6
Medium
CVE-2026-3673
Published date:
Apr 21, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
Our pentesters
DOMPurify mXSS via Re-Contextualization
5.3
Medium
CVE-2026-0540
Published date:
Mar 24, 2026
Discovered by
Camilo Vera, Cristian Vargas and Scott Moore
External pentesters
Actual Sync Server 26.2.1 - Authenticated Path Traversal
5.3
Medium
CVE-2026-3089
Published date:
Mar 9, 2026
Discovered by
Juan Patarroyo
Load more
AI SAST Scanner
Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering
4.8
Medium
CVE-2026-40230
Published date:
Apr 29, 2026
Discovered by
Oscar Uribe
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
AI SAST Scanner
Helpy 2.8.0 - Stored XSS in post author display via PostsHelper
5.1
Medium
CVE-2026-40229
Published date:
Apr 29, 2026
Discovered by
Oscar Uribe
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
AI SAST Scanner
Pimcore Platform v12.3.3 - Stored XSS in Document Editable Embed rendering
4.8
Medium
CVE-2026-5362
Published date:
Apr 27, 2026
Discovered by
Oscar Naveda
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Naveda
AI SAST Scanner
Pimcore Platform v12.3.3 - SQL Injection in DataObject composite index handling
7
High
CVE-2026-5394
Published date:
Apr 27, 2026
Discovered by
Oscar Naveda
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Naveda
AI SAST Scanner
Frappe Framework v16.10.0 - Stored DOM XSS in Multiple Field Formatters
4.6
Medium
CVE-2026-3837
Published date:
Apr 21, 2026
Discovered by
Oscar Uribe
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
AI SAST Scanner
Frappe Framework 16.10.0 - Stored DOM XSS in Tag Pill Renderer
4.6
Medium
CVE-2026-3673
Published date:
Apr 21, 2026
Discovered by
Oscar Uribe
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
Our pentesters
DOMPurify mXSS via Re-Contextualization
5.3
Medium
CVE-2026-0540
Published date:
Mar 24, 2026
Discovered by
Camilo Vera, Cristian Vargas and Scott Moore
External pentesters
Actual Sync Server 26.2.1 - Authenticated Path Traversal
5.3
Medium
CVE-2026-3089
Published date:
Mar 9, 2026
Discovered by
Juan Patarroyo
Load more


Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.


Start your 21-day free trial
Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.


Start your 21-day free trial
Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.


Start your 21-day free trial
Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.


Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.
Products
Targets
Subscribe to our newsletter
Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.
© 2026 Fluid Attacks. We hack your software.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.
Products
Targets
Subscribe to our newsletter
Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.
© 2026 Fluid Attacks. We hack your software.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.
Products
Targets
Subscribe to our newsletter
Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.
© 2026 Fluid Attacks. We hack your software.





