Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks

Buscar por término

Search filters

Discovered by

All

Severity

All

External pentesters

openSIS Classic 9.3 - Insecure Direct Object Reference in Sent Mail

7.1

High

CVE-2026-8406

Published date:

11 jun 2026

Discovered by

Daniel Esteban Celis

Our pentesters

X-VPN macOS website versions 77.0–77.5 - Local Privilege Escalation

7.3

High

CVE-2026-2638

Published date:

7 jun 2026

Discovered by

Oscar Uribe

AI SAST Scanner

ERPNext 16.16.0 - Stored XSS in POS cart item rendering

4.8

Medium

CVE-2026-42839

Published date:

3 jun 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literals

5.1

Medium

CVE-2026-42840

Published date:

3 jun 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

GLPI 11.0.0 - Stored XSS in knowledge base

8.4

High

CVE-2026-5385

Published date:

2 jun 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

mailcow-dockerized 2026-03b - Stored XSS in Queue Manager

7.4

High

CVE-2026-7460

Published date:

18 may 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping

6

Medium

CVE-2026-6093

Published date:

11 may 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering

4.8

Medium

CVE-2026-40230

Published date:

29 abr 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Cargar más

Buscar por término

Search filters

Discovered by

All

Severity

All

External pentesters

openSIS Classic 9.3 - Insecure Direct Object Reference in Sent Mail

7.1

High

CVE-2026-8406

Published date:

11 jun 2026

Discovered by

Daniel Esteban Celis

Our pentesters

X-VPN macOS website versions 77.0–77.5 - Local Privilege Escalation

7.3

High

CVE-2026-2638

Published date:

7 jun 2026

Discovered by

Oscar Uribe

AI SAST Scanner

ERPNext 16.16.0 - Stored XSS in POS cart item rendering

4.8

Medium

CVE-2026-42839

Published date:

3 jun 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literals

5.1

Medium

CVE-2026-42840

Published date:

3 jun 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

GLPI 11.0.0 - Stored XSS in knowledge base

8.4

High

CVE-2026-5385

Published date:

2 jun 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

mailcow-dockerized 2026-03b - Stored XSS in Queue Manager

7.4

High

CVE-2026-7460

Published date:

18 may 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping

6

Medium

CVE-2026-6093

Published date:

11 may 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering

4.8

Medium

CVE-2026-40230

Published date:

29 abr 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Cargar más

Buscar por término

Search filters

Discovered by

All

Severity

All

External pentesters

openSIS Classic 9.3 - Insecure Direct Object Reference in Sent Mail

7.1

High

CVE-2026-8406

Published date:

11 jun 2026

Discovered by

Daniel Esteban Celis

Our pentesters

X-VPN macOS website versions 77.0–77.5 - Local Privilege Escalation

7.3

High

CVE-2026-2638

Published date:

7 jun 2026

Discovered by

Oscar Uribe

AI SAST Scanner

ERPNext 16.16.0 - Stored XSS in POS cart item rendering

4.8

Medium

CVE-2026-42839

Published date:

3 jun 2026

Discovered by

Oscar Naveda

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literals

5.1

Medium

CVE-2026-42840

Published date:

3 jun 2026

Discovered by

Oscar Naveda

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

GLPI 11.0.0 - Stored XSS in knowledge base

8.4

High

CVE-2026-5385

Published date:

2 jun 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

mailcow-dockerized 2026-03b - Stored XSS in Queue Manager

7.4

High

CVE-2026-7460

Published date:

18 may 2026

Discovered by

Oscar Naveda

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping

6

Medium

CVE-2026-6093

Published date:

11 may 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering

4.8

Medium

CVE-2026-40230

Published date:

29 abr 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Cargar más

Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.

Inicia tu prueba gratuita de 21 días

Descubre los beneficios de nuestra solución Hacking Continuo, de la que ya disfrutan empresas de todos los tamaños.

Inicia tu prueba gratuita de 21 días

Descubre los beneficios de nuestra solución Hacking Continuo, de la que ya disfrutan empresas de todos los tamaños.

Inicia tu prueba gratuita de 21 días

Descubre los beneficios de nuestra solución Hacking Continuo, de la que ya disfrutan empresas de todos los tamaños.

Las soluciones de Fluid Attacks permiten a las organizaciones identificar, priorizar y remediar vulnerabilidades en su software a lo largo del SDLC. Con el apoyo de la IA, herramientas automatizadas y pentesters, Fluid Attacks acelera la mitigación de la exposición al riesgo de las empresas y fortalece su postura de ciberseguridad.

Lee un resumen de Fluid Attacks

Suscríbete a nuestro boletín

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

Las soluciones de Fluid Attacks permiten a las organizaciones identificar, priorizar y remediar vulnerabilidades en su software a lo largo del SDLC. Con el apoyo de la IA, herramientas automatizadas y pentesters, Fluid Attacks acelera la mitigación de la exposición al riesgo de las empresas y fortalece su postura de ciberseguridad.

Suscríbete a nuestro boletín

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

Las soluciones de Fluid Attacks permiten a las organizaciones identificar, priorizar y remediar vulnerabilidades en su software a lo largo del SDLC. Con el apoyo de la IA, herramientas automatizadas y pentesters, Fluid Attacks acelera la mitigación de la exposición al riesgo de las empresas y fortalece su postura de ciberseguridad.

Suscríbete a nuestro boletín

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.