Publicly disclosed vulnerabilities discovered by Fluid Attacks' research team

Search by term

Search filters

Discover by

All

Severity

All

A Capture Contact Form (and tab) - Insecure deserialization

1.7

Low

CVE-2025-31287

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Click-to-Call for Twilio - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31288

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

AIO Cache and Performance - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31289

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Church Admin - Insecure deserialization

1.7

Low

CVE-2025-31290

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Batch Validator - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31291

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Content.ad - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31292

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Best Rating and Pageviews - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31293

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Bulk Watermark - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31294

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Load more

Search by term

Search filters

Discover by

All

Severity

All

A Capture Contact Form (and tab) - Insecure deserialization

1.7

Low

CVE-2025-31287

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Click-to-Call for Twilio - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31288

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

AIO Cache and Performance - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31289

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Church Admin - Insecure deserialization

1.7

Low

CVE-2025-31290

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Batch Validator - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31291

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Content.ad - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31292

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Best Rating and Pageviews - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31293

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Bulk Watermark - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31294

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Load more

Search by term

Search filters

Discover by

All

Severity

All

A Capture Contact Form (and tab) - Insecure deserialization

1.7

Low

CVE-2025-31287

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Click-to-Call for Twilio - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31288

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

AIO Cache and Performance - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31289

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Church Admin - Insecure deserialization

1.7

Low

CVE-2025-31290

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Batch Validator - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31291

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Content.ad - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31292

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Best Rating and Pageviews - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31293

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Bulk Watermark - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31294

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Load more

Search by term

Search filters

Author

All

Severity

All

A Capture Contact Form (and tab) - Insecure deserialization

1.7

Low

CVE-2025-31287

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Click-to-Call for Twilio - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31288

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

AIO Cache and Performance - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31289

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Church Admin - Insecure deserialization

1.7

Low

CVE-2025-31290

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Batch Validator - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31291

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Content.ad - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31292

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Best Rating and Pageviews - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31293

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Bulk Watermark - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31294

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Load more

Search by term

Search filters

Author

All

Severity

All

A Capture Contact Form (and tab) - Insecure deserialization

1.7

Low

CVE-2025-31287

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Click-to-Call for Twilio - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31288

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

AIO Cache and Performance - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31289

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Church Admin - Insecure deserialization

1.7

Low

CVE-2025-31290

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Batch Validator - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31291

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Content.ad - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31292

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Best Rating and Pageviews - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31293

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Bulk Watermark - Reflected cross-site scripting (XSS)

4.8

Medium

CVE-2025-31294

Published date:

Mar 14, 2025

Detected by

Fluid Attacks SAST Scanner,

disclosed by

Andres Roldan

Load more

Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.

Start your 21-day free trial

Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.

Start your 21-day free trial

Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.

Start your 21-day free trial

Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.

SOC 2 Type II

SOC 3

Subscribe to our newsletter

Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.

© 2025 Fluid Attacks. We hack your software.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.

SOC 2 Type II

SOC 3

Subscribe to our newsletter

Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.

© 2025 Fluid Attacks. We hack your software.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.

SOC 2 Type II

SOC 3

Subscribe to our newsletter

Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.

© 2025 Fluid Attacks. We hack your software.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.

SOC 2 Type II

SOC 3

Subscribe to our newsletter

Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.

© 2025 Fluid Attacks. We hack your software.