Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks

Buscar por termo

Search filters

Discovered by

All

Severity

All

Our pentesters

X-VPN macOS website versions 77.0–77.5 - Local Privilege Escalation

7.3

High

CVE-2026-2638

Published date:

7 de jun. de 2026

Discovered by

Oscar Uribe

AI SAST Scanner

ERPNext 16.16.0 - Stored XSS in POS cart item rendering

4.8

Medium

CVE-2026-42839

Published date:

3 de jun. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literals

5.1

Medium

CVE-2026-42840

Published date:

3 de jun. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

GLPI 11.0.0 - Stored XSS in knowledge base

8.4

High

CVE-2026-5385

Published date:

2 de jun. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

mailcow-dockerized 2026-03b - Stored XSS in Queue Manager

7.4

High

CVE-2026-7460

Published date:

18 de mai. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping

6

Medium

CVE-2026-6093

Published date:

11 de mai. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering

4.8

Medium

CVE-2026-40230

Published date:

29 de abr. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Helpy 2.8.0 - Stored XSS in post author display via PostsHelper

5.1

Medium

CVE-2026-40229

Published date:

29 de abr. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Carregar mais

Buscar por termo

Search filters

Discovered by

All

Severity

All

Our pentesters

X-VPN macOS website versions 77.0–77.5 - Local Privilege Escalation

7.3

High

CVE-2026-2638

Published date:

7 de jun. de 2026

Discovered by

Oscar Uribe

AI SAST Scanner

ERPNext 16.16.0 - Stored XSS in POS cart item rendering

4.8

Medium

CVE-2026-42839

Published date:

3 de jun. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literals

5.1

Medium

CVE-2026-42840

Published date:

3 de jun. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

GLPI 11.0.0 - Stored XSS in knowledge base

8.4

High

CVE-2026-5385

Published date:

2 de jun. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

mailcow-dockerized 2026-03b - Stored XSS in Queue Manager

7.4

High

CVE-2026-7460

Published date:

18 de mai. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping

6

Medium

CVE-2026-6093

Published date:

11 de mai. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering

4.8

Medium

CVE-2026-40230

Published date:

29 de abr. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Helpy 2.8.0 - Stored XSS in post author display via PostsHelper

5.1

Medium

CVE-2026-40229

Published date:

29 de abr. de 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Carregar mais

Buscar por termo

Search filters

Discovered by

All

Severity

All

Our pentesters

X-VPN macOS website versions 77.0–77.5 - Local Privilege Escalation

7.3

High

CVE-2026-2638

Published date:

7 de jun. de 2026

Discovered by

Oscar Uribe

AI SAST Scanner

ERPNext 16.16.0 - Stored XSS in POS cart item rendering

4.8

Medium

CVE-2026-42839

Published date:

3 de jun. de 2026

Discovered by

Oscar Naveda

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

ERPNext 16.16.0 - Stored XSS in POS customer section via unescaped template literals

5.1

Medium

CVE-2026-42840

Published date:

3 de jun. de 2026

Discovered by

Oscar Naveda

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

GLPI 11.0.0 - Stored XSS in knowledge base

8.4

High

CVE-2026-5385

Published date:

2 de jun. de 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

mailcow-dockerized 2026-03b - Stored XSS in Queue Manager

7.4

High

CVE-2026-7460

Published date:

18 de mai. de 2026

Discovered by

Oscar Naveda

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

AI SAST Scanner

Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping

6

Medium

CVE-2026-6093

Published date:

11 de mai. de 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering

4.8

Medium

CVE-2026-40230

Published date:

29 de abr. de 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

AI SAST Scanner

Helpy 2.8.0 - Stored XSS in post author display via PostsHelper

5.1

Medium

CVE-2026-40229

Published date:

29 de abr. de 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Carregar mais

Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.

Comece seu teste gratuito de 21 dias

Descubra os benefícios de nossa solução de Hacking Contínuo, da qual empresas de todos os tamanhos já desfrutam.

Comece seu teste gratuito de 21 dias

Descubra os benefícios de nossa solução de Hacking Contínuo, da qual empresas de todos os tamanhos já desfrutam.

Comece seu teste gratuito de 21 dias

Descubra os benefícios de nossa solução de Hacking Contínuo, da qual empresas de todos os tamanhos já desfrutam.

As soluções da Fluid Attacks permitem que as organizações identifiquem, priorizem e corrijam vulnerabilidades em seus softwares ao longo do SDLC. Com o apoio de IA, ferramentas automatizadas e pentesters, a Fluid Attacks acelera a mitigação da exposição ao risco das empresas e fortalece sua postura de cibersegurança.

Consulta IA sobre Fluid Attacks

Assine nossa newsletter

Mantenha-se atualizado sobre nossos próximos eventos e os últimos posts do blog, advisories e outros recursos interessantes.

As soluções da Fluid Attacks permitem que as organizações identifiquem, priorizem e corrijam vulnerabilidades em seus softwares ao longo do SDLC. Com o apoio de IA, ferramentas automatizadas e pentesters, a Fluid Attacks acelera a mitigação da exposição ao risco das empresas e fortalece sua postura de cibersegurança.

Assine nossa newsletter

Mantenha-se atualizado sobre nossos próximos eventos e os últimos posts do blog, advisories e outros recursos interessantes.

Mantenha-se atualizado sobre nossos próximos eventos e os últimos posts do blog, advisories e outros recursos interessantes.

As soluções da Fluid Attacks permitem que as organizações identifiquem, priorizem e corrijam vulnerabilidades em seus softwares ao longo do SDLC. Com o apoio de IA, ferramentas automatizadas e pentesters, a Fluid Attacks acelera a mitigação da exposição ao risco das empresas e fortalece sua postura de cibersegurança.

Assine nossa newsletter

Mantenha-se atualizado sobre nossos próximos eventos e os últimos posts do blog, advisories e outros recursos interessantes.

Mantenha-se atualizado sobre nossos próximos eventos e os últimos posts do blog, advisories e outros recursos interessantes.