Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks
Our pentesters
ExifTool for photo and video 5.0.1 - Local OS command injection through filenames during CSV export
8.4
High
CVE-2026-101947
Published date:
9 oct 2026
Discovered by
Andrés Ramos
External pentesters
openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR)
9.3
Critical
CVE-2026-91107
Published date:
5 oct 2026
Discovered by
Daniel Esteban Celis
AI SAST Scanner
LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_min question attribute
7.2
High
CVE-2026-102626
Published date:
1 oct 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
Our pentesters
LimeSurvey Community Edition 7.3.0 - Cross-survey object authorization bypass in REST survey patch operations
7.1
High
CVE-2026-97685
Published date:
28 sept 2026
Discovered by
Miguel Gómez
AI SAST Scanner
Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping
6
Medium
CVE-2026-6093
Published date:
25 sept 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
Our pentesters
Root Browser Classic 3.3.0 - OS command injection through crafted SQLite filenames
8.5
High
CVE-2026-85082
Published date:
24 sept 2026
Discovered by
Andrés Ramos
Our pentesters
Secure Folder 1.2 - Plaintext vault files in shared storage bypass the PIN gate
6.8
Medium
CVE-2026-84283
Published date:
24 sept 2026
Discovered by
Andrés Ramos
Our pentesters
LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via invalid attribute column name
7.4
High
CVE-2026-92730
Published date:
23 sept 2026
Discovered by
Miguel Gómez
Cargar más
Our pentesters
ExifTool for photo and video 5.0.1 - Local OS command injection through filenames during CSV export
8.4
High
CVE-2026-101947
Published date:
9 oct 2026
Discovered by
Andrés Ramos
External pentesters
openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR)
9.3
Critical
CVE-2026-91107
Published date:
5 oct 2026
Discovered by
Daniel Esteban Celis
AI SAST Scanner
LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_min question attribute
7.2
High
CVE-2026-102626
Published date:
1 oct 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
Our pentesters
LimeSurvey Community Edition 7.3.0 - Cross-survey object authorization bypass in REST survey patch operations
7.1
High
CVE-2026-97685
Published date:
28 sept 2026
Discovered by
Miguel Gómez
AI SAST Scanner
Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping
6
Medium
CVE-2026-6093
Published date:
25 sept 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
Our pentesters
Root Browser Classic 3.3.0 - OS command injection through crafted SQLite filenames
8.5
High
CVE-2026-85082
Published date:
24 sept 2026
Discovered by
Andrés Ramos
Our pentesters
Secure Folder 1.2 - Plaintext vault files in shared storage bypass the PIN gate
6.8
Medium
CVE-2026-84283
Published date:
24 sept 2026
Discovered by
Andrés Ramos
Our pentesters
LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via invalid attribute column name
7.4
High
CVE-2026-92730
Published date:
23 sept 2026
Discovered by
Miguel Gómez
Cargar más
Our pentesters
ExifTool for photo and video 5.0.1 - Local OS command injection through filenames during CSV export
8.4
High
CVE-2026-101947
Published date:
9 oct 2026
Discovered by
Andrés Ramos
External pentesters
openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR)
9.3
Critical
CVE-2026-91107
Published date:
5 oct 2026
Discovered by
Daniel Esteban Celis
AI SAST Scanner
LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_min question attribute
7.2
High
CVE-2026-102626
Published date:
1 oct 2026
Discovered by
Miguel Gómez
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
Our pentesters
LimeSurvey Community Edition 7.3.0 - Cross-survey object authorization bypass in REST survey patch operations
7.1
High
CVE-2026-97685
Published date:
28 sept 2026
Discovered by
Miguel Gómez
AI SAST Scanner
Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping
6
Medium
CVE-2026-6093
Published date:
25 sept 2026
Discovered by
Oscar Uribe
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
Our pentesters
Root Browser Classic 3.3.0 - OS command injection through crafted SQLite filenames
8.5
High
CVE-2026-85082
Published date:
24 sept 2026
Discovered by
Andrés Ramos
Our pentesters
Secure Folder 1.2 - Plaintext vault files in shared storage bypass the PIN gate
6.8
Medium
CVE-2026-84283
Published date:
24 sept 2026
Discovered by
Andrés Ramos
Our pentesters
LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via invalid attribute column name
7.4
High
CVE-2026-92730
Published date:
23 sept 2026
Discovered by
Miguel Gómez
Cargar más


Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.

Reduce el riesgo sin retrasar tus entregas
Reduce el riesgo sin retrasar tus entregas
Resultados rápidos y exactos desde un único programa de seguridad continuo impulsado por IA, escáneres y pentesters.
Resultados rápidos y exactos desde un único programa de seguridad continuo impulsado por IA, escáneres y pentesters.
PrevénPrevén
PrevénPrevén
PrevénPrevén
DetectaDetecta
DetectaDetecta
DetectaDetecta
GestionaGestiona
GestionaGestiona
GestionaGestiona
RemediaRemedia
RemediaRemedia
RemediaRemedia
Soluciones
Productos
Soluciones
Productos
Soluciones
Productos














