Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks
Our pentesters
LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via invalid attribute column name
7.4
High
CVE-2026-92730
Published date:
Sep 23, 2026
Discovered by
Miguel Gómez
Our pentesters
LimeSurvey Community Edition 7.0.14 - Reflected XSS through unescaped LSS survey-import warnings
7.4
High
CVE-2026-91775
Published date:
Sep 23, 2026
Discovered by
Miguel Gómez
External pentesters
NASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCID
8.7
High
CVE-2026-79954
Published date:
Sep 17, 2026
Discovered by
Romel Marín
Our pentesters
Gallery - Private Photo Vault 1.0.41 - Unauthenticated local-network HTTP file exposure
7.1
High
CVE-2026-77884
Published date:
Sep 14, 2026
Discovered by
Andrés Ramos
Our pentesters
Ekia File Manager 1.2.7 - Exported ContentProvider allows unauthorized file access
8.5
High
CVE-2026-81301
Published date:
Sep 14, 2026
Discovered by
Andrés Ramos
Our pentesters
Hide Photos - Secure vault 4.1.0 - Insecure storage of vault media and wallet records in shared external storage
6.8
Medium
CVE-2026-77875
Published date:
Sep 9, 2026
Discovered by
Andrés Ramos
AI SAST Scanner
Baserow 2.3.3 - SQL injection in formula index() JSONB array extraction
8.6
High
Published date:
Sep 1, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
Our pentesters
LimeSurvey Community Edition 7.0.5 - Improper authorization in survey menu entry creation endpoint
5.1
Medium
CVE-2026-65931
Published date:
Aug 26, 2026
Discovered by
Miguel Gómez
Load more
Our pentesters
LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via invalid attribute column name
7.4
High
CVE-2026-92730
Published date:
Sep 23, 2026
Discovered by
Miguel Gómez
Our pentesters
LimeSurvey Community Edition 7.0.14 - Reflected XSS through unescaped LSS survey-import warnings
7.4
High
CVE-2026-91775
Published date:
Sep 23, 2026
Discovered by
Miguel Gómez
External pentesters
NASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCID
8.7
High
CVE-2026-79954
Published date:
Sep 17, 2026
Discovered by
Romel Marín
Our pentesters
Gallery - Private Photo Vault 1.0.41 - Unauthenticated local-network HTTP file exposure
7.1
High
CVE-2026-77884
Published date:
Sep 14, 2026
Discovered by
Andrés Ramos
Our pentesters
Ekia File Manager 1.2.7 - Exported ContentProvider allows unauthorized file access
8.5
High
CVE-2026-81301
Published date:
Sep 14, 2026
Discovered by
Andrés Ramos
Our pentesters
Hide Photos - Secure vault 4.1.0 - Insecure storage of vault media and wallet records in shared external storage
6.8
Medium
CVE-2026-77875
Published date:
Sep 9, 2026
Discovered by
Andrés Ramos
AI SAST Scanner
Baserow 2.3.3 - SQL injection in formula index() JSONB array extraction
8.6
High
Published date:
Sep 1, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
Our pentesters
LimeSurvey Community Edition 7.0.5 - Improper authorization in survey menu entry creation endpoint
5.1
Medium
CVE-2026-65931
Published date:
Aug 26, 2026
Discovered by
Miguel Gómez
Load more
Our pentesters
LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via invalid attribute column name
7.4
High
CVE-2026-92730
Published date:
Sep 23, 2026
Discovered by
Miguel Gómez
Our pentesters
LimeSurvey Community Edition 7.0.14 - Reflected XSS through unescaped LSS survey-import warnings
7.4
High
CVE-2026-91775
Published date:
Sep 23, 2026
Discovered by
Miguel Gómez
External pentesters
NASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCID
8.7
High
CVE-2026-79954
Published date:
Sep 17, 2026
Discovered by
Romel Marín
Our pentesters
Gallery - Private Photo Vault 1.0.41 - Unauthenticated local-network HTTP file exposure
7.1
High
CVE-2026-77884
Published date:
Sep 14, 2026
Discovered by
Andrés Ramos
Our pentesters
Ekia File Manager 1.2.7 - Exported ContentProvider allows unauthorized file access
8.5
High
CVE-2026-81301
Published date:
Sep 14, 2026
Discovered by
Andrés Ramos
Our pentesters
Hide Photos - Secure vault 4.1.0 - Insecure storage of vault media and wallet records in shared external storage
6.8
Medium
CVE-2026-77875
Published date:
Sep 9, 2026
Discovered by
Andrés Ramos
AI SAST Scanner
Baserow 2.3.3 - SQL injection in formula index() JSONB array extraction
8.6
High
Published date:
Sep 1, 2026
Discovered by
Miguel Gómez
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
Our pentesters
LimeSurvey Community Edition 7.0.5 - Improper authorization in survey menu entry creation endpoint
5.1
Medium
CVE-2026-65931
Published date:
Aug 26, 2026
Discovered by
Miguel Gómez
Load more


Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.

Reduce risk without slowing delivery
Reduce risk without slowing delivery
All in one continuous security program powered by AI, scanners, and pentesters.
All in one continuous security program powered by AI, scanners, and pentesters.
PreventPrevent
PreventPrevent
PreventPrevent
DetectDetect
DetectDetect
DetectDetect
ManageManage
ManageManage
ManageManage
RemediateRemediate
RemediateRemediate
RemediateRemediate
Solutions
Resources
Solutions
Resources
Solutions
Resources














