Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks
AI SAST Scanner
LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB
6
Medium
CVE-2026-18403
Published date:
Aug 14, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
AI SAST Scanner
LimeSurvey Community Edition 7.0.5 - Reflected XSS in HTML editor popup
8.5
High
CVE-2026-63361
Published date:
Aug 14, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
Our pentesters
Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation
7.5
High
CVE-2026-10716
Published date:
Aug 5, 2026
Discovered by
Santiago Alvarez and Oscar Naveda
Our pentesters
ERPNext v16.25.0 - Improper authorization in Prospect opportunities API
7.1
High
CVE-2026-13227
Published date:
Aug 4, 2026
Discovered by
Eduardo Ferguson
AI SAST Scanner
Zammad 7.0.1 - Improper authorization in ticket article attachment cloning
7.1
High
CVE-2026-13229
Published date:
Aug 4, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Naveda
External pentesters
osTicket v1.18.3 - v1,17.7 - BOLA/IDOR in ticket field viewing allows cross-department data disclosure
7.1
High
CVE-2026-14871
Published date:
Jul 17, 2026
Discovered by
Juan Felipe Osorio Z
External pentesters
openSIS Classic 9.3 - Authenticated path traversal in SentMail attachment download
5.3
Medium
CVE-2026-11944
Published date:
Jul 9, 2026
Discovered by
Daniel Esteban Celis
Our pentesters
PayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlock access
5.3
Medium
CVE-2026-11779
Published date:
Jun 26, 2026
Discovered by
Oscar Naveda
Load more
AI SAST Scanner
LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB
6
Medium
CVE-2026-18403
Published date:
Aug 14, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
AI SAST Scanner
LimeSurvey Community Edition 7.0.5 - Reflected XSS in HTML editor popup
8.5
High
CVE-2026-63361
Published date:
Aug 14, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
Our pentesters
Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation
7.5
High
CVE-2026-10716
Published date:
Aug 5, 2026
Discovered by
Santiago Alvarez and Oscar Naveda
Our pentesters
ERPNext v16.25.0 - Improper authorization in Prospect opportunities API
7.1
High
CVE-2026-13227
Published date:
Aug 4, 2026
Discovered by
Eduardo Ferguson
AI SAST Scanner
Zammad 7.0.1 - Improper authorization in ticket article attachment cloning
7.1
High
CVE-2026-13229
Published date:
Aug 4, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Naveda
External pentesters
osTicket v1.18.3 - v1,17.7 - BOLA/IDOR in ticket field viewing allows cross-department data disclosure
7.1
High
CVE-2026-14871
Published date:
Jul 17, 2026
Discovered by
Juan Felipe Osorio Z
External pentesters
openSIS Classic 9.3 - Authenticated path traversal in SentMail attachment download
5.3
Medium
CVE-2026-11944
Published date:
Jul 9, 2026
Discovered by
Daniel Esteban Celis
Our pentesters
PayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlock access
5.3
Medium
CVE-2026-11779
Published date:
Jun 26, 2026
Discovered by
Oscar Naveda
Load more
AI SAST Scanner
LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB
6
Medium
CVE-2026-18403
Published date:
Aug 14, 2026
Discovered by
Miguel Gómez
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
AI SAST Scanner
LimeSurvey Community Edition 7.0.5 - Reflected XSS in HTML editor popup
8.5
High
CVE-2026-63361
Published date:
Aug 14, 2026
Discovered by
Miguel Gómez
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
Our pentesters
Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation
7.5
High
CVE-2026-10716
Published date:
Aug 5, 2026
Discovered by
Santiago Alvarez and Oscar Naveda
Our pentesters
ERPNext v16.25.0 - Improper authorization in Prospect opportunities API
7.1
High
CVE-2026-13227
Published date:
Aug 4, 2026
Discovered by
Eduardo Ferguson
AI SAST Scanner
Zammad 7.0.1 - Improper authorization in ticket article attachment cloning
7.1
High
CVE-2026-13229
Published date:
Aug 4, 2026
Discovered by
Oscar Naveda
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Naveda
External pentesters
osTicket v1.18.3 - v1,17.7 - BOLA/IDOR in ticket field viewing allows cross-department data disclosure
7.1
High
CVE-2026-14871
Published date:
Jul 17, 2026
Discovered by
Juan Felipe Osorio Z
External pentesters
openSIS Classic 9.3 - Authenticated path traversal in SentMail attachment download
5.3
Medium
CVE-2026-11944
Published date:
Jul 9, 2026
Discovered by
Daniel Esteban Celis
Our pentesters
PayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlock access
5.3
Medium
CVE-2026-11779
Published date:
Jun 26, 2026
Discovered by
Oscar Naveda
Load more


Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.


Start your 21-day free trial
Discover the benefits of the Fluid Attacks solution, which organizations of all sizes are already enjoying.


Start your 21-day free trial
Discover the benefits of the Fluid Attacks solution, which organizations of all sizes are already enjoying.


Start your 21-day free trial
Discover the benefits of the Fluid Attacks solution, which organizations of all sizes are already enjoying.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.
Products
Targets
Subscribe to our newsletter
Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.
Products
Targets
Subscribe to our newsletter
Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.
Products
Targets
Subscribe to our newsletter
Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.












