Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks
Our pentesters
NoSleep 1.5.1 - Unauthorized disclosure of root-owned files through privileged XPC helper
6.9
Medium
CVE-2026-19755
Published date:
20 ago 2026
Discovered by
Oscar Uribe
External pentesters
Akaunting 3.1.21 - Improper authorization in BulkActions handle dispatch
8.7
High
CVE-2026-19198
Published date:
19 ago 2026
Discovered by
Jaime Ramírez
AI SAST Scanner
HumHub Community Edition 1.18.4-pl1 - Reflected XSS in Space membership request button rendering
7.2
High
CVE-2026-18756
Published date:
19 ago 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
AI SAST Scanner
HumHub 1.18.4 - Stored XSS in comment-deletion notifications through unescaped administrator reason
7.2
High
CVE-2026-18430
Published date:
19 ago 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
AI SAST Scanner
HumHub 1.18.4 / 1.18.4-pl1 – Stored Cross-Site Scripting in oEmbed confirmation
7.4
High
CVE-2026-18526
Published date:
19 ago 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
AI SAST Scanner
LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB
6
Medium
CVE-2026-18403
Published date:
14 ago 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
AI SAST Scanner
LimeSurvey Community Edition 7.0.5 - Reflected XSS in HTML editor popup Copy
8.5
High
CVE-2026-63361
Published date:
14 ago 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
Our pentesters
Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation
7.5
High
CVE-2026-10716
Published date:
5 ago 2026
Discovered by
Santiago Alvarez and Oscar Naveda
Cargar más
Our pentesters
NoSleep 1.5.1 - Unauthorized disclosure of root-owned files through privileged XPC helper
6.9
Medium
CVE-2026-19755
Published date:
20 ago 2026
Discovered by
Oscar Uribe
External pentesters
Akaunting 3.1.21 - Improper authorization in BulkActions handle dispatch
8.7
High
CVE-2026-19198
Published date:
19 ago 2026
Discovered by
Jaime Ramírez
AI SAST Scanner
HumHub Community Edition 1.18.4-pl1 - Reflected XSS in Space membership request button rendering
7.2
High
CVE-2026-18756
Published date:
19 ago 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
AI SAST Scanner
HumHub 1.18.4 - Stored XSS in comment-deletion notifications through unescaped administrator reason
7.2
High
CVE-2026-18430
Published date:
19 ago 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
AI SAST Scanner
HumHub 1.18.4 / 1.18.4-pl1 – Stored Cross-Site Scripting in oEmbed confirmation
7.4
High
CVE-2026-18526
Published date:
19 ago 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
AI SAST Scanner
LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB
6
Medium
CVE-2026-18403
Published date:
14 ago 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
AI SAST Scanner
LimeSurvey Community Edition 7.0.5 - Reflected XSS in HTML editor popup Copy
8.5
High
CVE-2026-63361
Published date:
14 ago 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
Our pentesters
Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation
7.5
High
CVE-2026-10716
Published date:
5 ago 2026
Discovered by
Santiago Alvarez and Oscar Naveda
Cargar más
Our pentesters
NoSleep 1.5.1 - Unauthorized disclosure of root-owned files through privileged XPC helper
6.9
Medium
CVE-2026-19755
Published date:
20 ago 2026
Discovered by
Oscar Uribe
External pentesters
Akaunting 3.1.21 - Improper authorization in BulkActions handle dispatch
8.7
High
CVE-2026-19198
Published date:
19 ago 2026
Discovered by
Jaime Ramírez
AI SAST Scanner
HumHub Community Edition 1.18.4-pl1 - Reflected XSS in Space membership request button rendering
7.2
High
CVE-2026-18756
Published date:
19 ago 2026
Discovered by
Miguel Gómez
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
AI SAST Scanner
HumHub 1.18.4 - Stored XSS in comment-deletion notifications through unescaped administrator reason
7.2
High
CVE-2026-18430
Published date:
19 ago 2026
Discovered by
Miguel Gómez
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
AI SAST Scanner
HumHub 1.18.4 / 1.18.4-pl1 – Stored Cross-Site Scripting in oEmbed confirmation
7.4
High
CVE-2026-18526
Published date:
19 ago 2026
Discovered by
Miguel Gómez
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
AI SAST Scanner
LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB
6
Medium
CVE-2026-18403
Published date:
14 ago 2026
Discovered by
Miguel Gómez
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
AI SAST Scanner
LimeSurvey Community Edition 7.0.5 - Reflected XSS in HTML editor popup Copy
8.5
High
CVE-2026-63361
Published date:
14 ago 2026
Discovered by
Miguel Gómez
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
Our pentesters
Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation
7.5
High
CVE-2026-10716
Published date:
5 ago 2026
Discovered by
Santiago Alvarez and Oscar Naveda
Cargar más


Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.


Inicia tu prueba gratuita de 21 días
Descubre los beneficios de la solución Fluid Attacks, de la que ya disfrutan empresas de todos los tamaños.


Inicia tu prueba gratuita de 21 días
Descubre los beneficios de la solución Fluid Attacks, de la que ya disfrutan empresas de todos los tamaños.


Inicia tu prueba gratuita de 21 días
Descubre los beneficios de la solución Fluid Attacks, de la que ya disfrutan empresas de todos los tamaños.


Las soluciones de Fluid Attacks permiten a las organizaciones identificar, priorizar y remediar vulnerabilidades en su software a lo largo del SDLC. Con el apoyo de la IA, herramientas automatizadas y pentesters, Fluid Attacks acelera la mitigación de la exposición al riesgo de las empresas y fortalece su postura de ciberseguridad.
Productos
Objetivos
Suscríbete a nuestro boletín
Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.
© 2026 Fluid Attacks.

Las soluciones de Fluid Attacks permiten a las organizaciones identificar, priorizar y remediar vulnerabilidades en su software a lo largo del SDLC. Con el apoyo de la IA, herramientas automatizadas y pentesters, Fluid Attacks acelera la mitigación de la exposición al riesgo de las empresas y fortalece su postura de ciberseguridad.
Productos
Objetivos
Compañía
Suscríbete a nuestro boletín
Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.
Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.
© 2026 Fluid Attacks.

Las soluciones de Fluid Attacks permiten a las organizaciones identificar, priorizar y remediar vulnerabilidades en su software a lo largo del SDLC. Con el apoyo de la IA, herramientas automatizadas y pentesters, Fluid Attacks acelera la mitigación de la exposición al riesgo de las empresas y fortalece su postura de ciberseguridad.
Productos
Objetivos
Compañía
Suscríbete a nuestro boletín
Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.
Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.
© 2026 Fluid Attacks.













