Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks

Buscar por termo

Search filters

Discovered by

All

Severity

All

Our pentesters

PayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlock access

5.3

Medium

CVE-2026-11779

Published date:

26 de jun. de 2026

Discovered by

Oscar Naveda

AI SAST Scanner

Frappe Framework 17.0.0-dev - Stored XSS in Tree View node label rendering

4.8

Medium

CVE-2026-50712

Published date:

24 de jun. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Frappe Framework 17.0.0-dev - Stored XSS in Number Card filter fields rendering

4.6

Medium

CVE-2026-50711

Published date:

24 de jun. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Frappe Framework 17.0.0-dev - Stored XSS via eval in Number Card filters_config

4.6

Medium

CVE-2026-50710

Published date:

24 de jun. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Frappe Framework 17.0.0-dev - Stored XSS in Notifications Events color rendering

4.8

Medium

CVE-2026-50709

Published date:

24 de jun. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Frappe Framework 17.0.0-dev - Stored XSS in Multi Select Dialog result rendering

4.8

Medium

CVE-2026-50708

Published date:

24 de jun. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Frappe Framework 17.0.0-dev - Stored XSS in Form Dashboard headline rendering

4.6

Medium

CVE-2026-50705

Published date:

24 de jun. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Frappe Framework 17.0.0-dev - Reflected/Stored XSS in File View breadcrumbs rendering

4.6

Medium

CVE-2026-50704

Published date:

24 de jun. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Carregar mais

Buscar por termo

Search filters

Discovered by

All

Severity

All

Our pentesters

PayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlock access

5.3

Medium

CVE-2026-11779

Published date:

26 de jun. de 2026

Discovered by

Oscar Naveda

AI SAST Scanner

Frappe Framework 17.0.0-dev - Stored XSS in Tree View node label rendering

4.8

Medium

CVE-2026-50712

Published date:

24 de jun. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Frappe Framework 17.0.0-dev - Stored XSS in Number Card filter fields rendering

4.6

Medium

CVE-2026-50711

Published date:

24 de jun. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Frappe Framework 17.0.0-dev - Stored XSS via eval in Number Card filters_config

4.6

Medium

CVE-2026-50710

Published date:

24 de jun. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Frappe Framework 17.0.0-dev - Stored XSS in Notifications Events color rendering

4.8

Medium

CVE-2026-50709

Published date:

24 de jun. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Frappe Framework 17.0.0-dev - Stored XSS in Multi Select Dialog result rendering

4.8

Medium

CVE-2026-50708

Published date:

24 de jun. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Frappe Framework 17.0.0-dev - Stored XSS in Form Dashboard headline rendering

4.6

Medium

CVE-2026-50705

Published date:

24 de jun. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Frappe Framework 17.0.0-dev - Reflected/Stored XSS in File View breadcrumbs rendering

4.6

Medium

CVE-2026-50704

Published date:

24 de jun. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Carregar mais

Buscar por termo

Search filters

Discovered by

All

Severity

All

Our pentesters

PayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlock access

5.3

Medium

CVE-2026-11779

Published date:

26 de jun. de 2026

Discovered by

Oscar Naveda

AI SAST Scanner

Frappe Framework 17.0.0-dev - Stored XSS in Tree View node label rendering

4.8

Medium

CVE-2026-50712

Published date:

24 de jun. de 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Frappe Framework 17.0.0-dev - Stored XSS in Number Card filter fields rendering

4.6

Medium

CVE-2026-50711

Published date:

24 de jun. de 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Frappe Framework 17.0.0-dev - Stored XSS via eval in Number Card filters_config

4.6

Medium

CVE-2026-50710

Published date:

24 de jun. de 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Frappe Framework 17.0.0-dev - Stored XSS in Notifications Events color rendering

4.8

Medium

CVE-2026-50709

Published date:

24 de jun. de 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Frappe Framework 17.0.0-dev - Stored XSS in Multi Select Dialog result rendering

4.8

Medium

CVE-2026-50708

Published date:

24 de jun. de 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Frappe Framework 17.0.0-dev - Stored XSS in Form Dashboard headline rendering

4.6

Medium

CVE-2026-50705

Published date:

24 de jun. de 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Frappe Framework 17.0.0-dev - Reflected/Stored XSS in File View breadcrumbs rendering

4.6

Medium

CVE-2026-50704

Published date:

24 de jun. de 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Carregar mais

Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.

Comece seu teste gratuito de 21 dias

Descubra os benefícios da solução Fluid Attacks, da qual empresas de todos os tamanhos já desfrutam.

Comece seu teste gratuito de 21 dias

Descubra os benefícios da solução Fluid Attacks, da qual empresas de todos os tamanhos já desfrutam.

Comece seu teste gratuito de 21 dias

Descubra os benefícios da solução Fluid Attacks, da qual empresas de todos os tamanhos já desfrutam.

As soluções da Fluid Attacks permitem que as organizações identifiquem, priorizem e corrijam vulnerabilidades em seus softwares ao longo do SDLC. Com o apoio de IA, ferramentas automatizadas e pentesters, a Fluid Attacks acelera a mitigação da exposição ao risco das empresas e fortalece sua postura de cibersegurança.

Consulta IA sobre Fluid Attacks

Assine nossa newsletter

Mantenha-se atualizado sobre nossos próximos eventos e os últimos posts do blog, advisories e outros recursos interessantes.

As soluções da Fluid Attacks permitem que as organizações identifiquem, priorizem e corrijam vulnerabilidades em seus softwares ao longo do SDLC. Com o apoio de IA, ferramentas automatizadas e pentesters, a Fluid Attacks acelera a mitigação da exposição ao risco das empresas e fortalece sua postura de cibersegurança.

Assine nossa newsletter

Mantenha-se atualizado sobre nossos próximos eventos e os últimos posts do blog, advisories e outros recursos interessantes.

Mantenha-se atualizado sobre nossos próximos eventos e os últimos posts do blog, advisories e outros recursos interessantes.

As soluções da Fluid Attacks permitem que as organizações identifiquem, priorizem e corrijam vulnerabilidades em seus softwares ao longo do SDLC. Com o apoio de IA, ferramentas automatizadas e pentesters, a Fluid Attacks acelera a mitigação da exposição ao risco das empresas e fortalece sua postura de cibersegurança.

Assine nossa newsletter

Mantenha-se atualizado sobre nossos próximos eventos e os últimos posts do blog, advisories e outros recursos interessantes.

Mantenha-se atualizado sobre nossos próximos eventos e os últimos posts do blog, advisories e outros recursos interessantes.