Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks

Buscar por término

Search filters

Discovered by

All

Severity

All

Our pentesters

NoSleep 1.5.1 - Unauthorized disclosure of root-owned files through privileged XPC helper

6.9

Medium

CVE-2026-19755

Published date:

20 ago 2026

Discovered by

Oscar Uribe

External pentesters

Akaunting 3.1.21 - Improper authorization in BulkActions handle dispatch

8.7

High

CVE-2026-19198

Published date:

19 ago 2026

Discovered by

Jaime Ramírez

AI SAST Scanner

HumHub Community Edition 1.18.4-pl1 - Reflected XSS in Space membership request button rendering

7.2

High

CVE-2026-18756

Published date:

19 ago 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

AI SAST Scanner

HumHub 1.18.4 - Stored XSS in comment-deletion notifications through unescaped administrator reason

7.2

High

CVE-2026-18430

Published date:

19 ago 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

AI SAST Scanner

HumHub 1.18.4 / 1.18.4-pl1 – Stored Cross-Site Scripting in oEmbed confirmation

7.4

High

CVE-2026-18526

Published date:

19 ago 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

AI SAST Scanner

LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB

6

Medium

CVE-2026-18403

Published date:

14 ago 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

AI SAST Scanner

LimeSurvey Community Edition 7.0.5 - Reflected XSS in HTML editor popup Copy

8.5

High

CVE-2026-63361

Published date:

14 ago 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

Our pentesters

Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation

7.5

High

CVE-2026-10716

Published date:

5 ago 2026

Discovered by

Santiago Alvarez and Oscar Naveda

Cargar más

Buscar por término

Search filters

Discovered by

All

Severity

All

Our pentesters

NoSleep 1.5.1 - Unauthorized disclosure of root-owned files through privileged XPC helper

6.9

Medium

CVE-2026-19755

Published date:

20 ago 2026

Discovered by

Oscar Uribe

External pentesters

Akaunting 3.1.21 - Improper authorization in BulkActions handle dispatch

8.7

High

CVE-2026-19198

Published date:

19 ago 2026

Discovered by

Jaime Ramírez

AI SAST Scanner

HumHub Community Edition 1.18.4-pl1 - Reflected XSS in Space membership request button rendering

7.2

High

CVE-2026-18756

Published date:

19 ago 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

AI SAST Scanner

HumHub 1.18.4 - Stored XSS in comment-deletion notifications through unescaped administrator reason

7.2

High

CVE-2026-18430

Published date:

19 ago 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

AI SAST Scanner

HumHub 1.18.4 / 1.18.4-pl1 – Stored Cross-Site Scripting in oEmbed confirmation

7.4

High

CVE-2026-18526

Published date:

19 ago 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

AI SAST Scanner

LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB

6

Medium

CVE-2026-18403

Published date:

14 ago 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

AI SAST Scanner

LimeSurvey Community Edition 7.0.5 - Reflected XSS in HTML editor popup Copy

8.5

High

CVE-2026-63361

Published date:

14 ago 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

Our pentesters

Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation

7.5

High

CVE-2026-10716

Published date:

5 ago 2026

Discovered by

Santiago Alvarez and Oscar Naveda

Cargar más

Buscar por término

Search filters

Discovered by

All

Severity

All

Our pentesters

NoSleep 1.5.1 - Unauthorized disclosure of root-owned files through privileged XPC helper

6.9

Medium

CVE-2026-19755

Published date:

20 ago 2026

Discovered by

Oscar Uribe

External pentesters

Akaunting 3.1.21 - Improper authorization in BulkActions handle dispatch

8.7

High

CVE-2026-19198

Published date:

19 ago 2026

Discovered by

Jaime Ramírez

AI SAST Scanner

HumHub Community Edition 1.18.4-pl1 - Reflected XSS in Space membership request button rendering

7.2

High

CVE-2026-18756

Published date:

19 ago 2026

Discovered by

Miguel Gómez

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

AI SAST Scanner

HumHub 1.18.4 - Stored XSS in comment-deletion notifications through unescaped administrator reason

7.2

High

CVE-2026-18430

Published date:

19 ago 2026

Discovered by

Miguel Gómez

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

AI SAST Scanner

HumHub 1.18.4 / 1.18.4-pl1 – Stored Cross-Site Scripting in oEmbed confirmation

7.4

High

CVE-2026-18526

Published date:

19 ago 2026

Discovered by

Miguel Gómez

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

AI SAST Scanner

LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB

6

Medium

CVE-2026-18403

Published date:

14 ago 2026

Discovered by

Miguel Gómez

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

AI SAST Scanner

LimeSurvey Community Edition 7.0.5 - Reflected XSS in HTML editor popup Copy

8.5

High

CVE-2026-63361

Published date:

14 ago 2026

Discovered by

Miguel Gómez

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

Our pentesters

Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation

7.5

High

CVE-2026-10716

Published date:

5 ago 2026

Discovered by

Santiago Alvarez and Oscar Naveda

Cargar más

Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.

Inicia tu prueba gratuita de 21 días

Descubre los beneficios de la solución Fluid Attacks, de la que ya disfrutan empresas de todos los tamaños.

Inicia tu prueba gratuita de 21 días

Descubre los beneficios de la solución Fluid Attacks, de la que ya disfrutan empresas de todos los tamaños.

Inicia tu prueba gratuita de 21 días

Descubre los beneficios de la solución Fluid Attacks, de la que ya disfrutan empresas de todos los tamaños.

logo-fluidattacks-white-png

Las soluciones de Fluid Attacks permiten a las organizaciones identificar, priorizar y remediar vulnerabilidades en su software a lo largo del SDLC. Con el apoyo de la IA, herramientas automatizadas y pentesters, Fluid Attacks acelera la mitigación de la exposición al riesgo de las empresas y fortalece su postura de ciberseguridad.

Lee un resumen de Fluid Attacks

Suscríbete a nuestro boletín

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

logo-fluidattacks-white-png

Las soluciones de Fluid Attacks permiten a las organizaciones identificar, priorizar y remediar vulnerabilidades en su software a lo largo del SDLC. Con el apoyo de la IA, herramientas automatizadas y pentesters, Fluid Attacks acelera la mitigación de la exposición al riesgo de las empresas y fortalece su postura de ciberseguridad.

Suscríbete a nuestro boletín

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

logo-fluidattacks-white-png

Las soluciones de Fluid Attacks permiten a las organizaciones identificar, priorizar y remediar vulnerabilidades en su software a lo largo del SDLC. Con el apoyo de la IA, herramientas automatizadas y pentesters, Fluid Attacks acelera la mitigación de la exposición al riesgo de las empresas y fortalece su postura de ciberseguridad.

Suscríbete a nuestro boletín

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.