Publicly disclosed vulnerabilities discovered by Fluid Attacks' research team
A Capture Contact Form (and tab) - Insecure deserialization
1.7
Low
CVE-2025-31287
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Click-to-Call for Twilio - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31288
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
AIO Cache and Performance - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31289
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Church Admin - Insecure deserialization
1.7
Low
CVE-2025-31290
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Batch Validator - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31291
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Content.ad - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31292
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Best Rating and Pageviews - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31293
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Bulk Watermark - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31294
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Load more
A Capture Contact Form (and tab) - Insecure deserialization
1.7
Low
CVE-2025-31287
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Click-to-Call for Twilio - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31288
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
AIO Cache and Performance - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31289
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Church Admin - Insecure deserialization
1.7
Low
CVE-2025-31290
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Batch Validator - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31291
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Content.ad - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31292
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Best Rating and Pageviews - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31293
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Bulk Watermark - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31294
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Load more
A Capture Contact Form (and tab) - Insecure deserialization
1.7
Low
CVE-2025-31287
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Click-to-Call for Twilio - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31288
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
AIO Cache and Performance - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31289
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Church Admin - Insecure deserialization
1.7
Low
CVE-2025-31290
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Batch Validator - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31291
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Content.ad - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31292
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Best Rating and Pageviews - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31293
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Bulk Watermark - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31294
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Load more
A Capture Contact Form (and tab) - Insecure deserialization
1.7
Low
CVE-2025-31287
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Click-to-Call for Twilio - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31288
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
AIO Cache and Performance - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31289
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Church Admin - Insecure deserialization
1.7
Low
CVE-2025-31290
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Batch Validator - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31291
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Content.ad - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31292
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Best Rating and Pageviews - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31293
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Bulk Watermark - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31294
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Load more
A Capture Contact Form (and tab) - Insecure deserialization
1.7
Low
CVE-2025-31287
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Click-to-Call for Twilio - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31288
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
AIO Cache and Performance - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31289
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Church Admin - Insecure deserialization
1.7
Low
CVE-2025-31290
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Batch Validator - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31291
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Content.ad - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31292
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Best Rating and Pageviews - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31293
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Bulk Watermark - Reflected cross-site scripting (XSS)
4.8
Medium
CVE-2025-31294
Published date:
Mar 14, 2025
Detected by
Fluid Attacks SAST Scanner,
disclosed by
Andres Roldan
Load more


Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.


Start your 21-day free trial
Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.


Start your 21-day free trial
Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.


Start your 21-day free trial
Discover the benefits of our Continuous Hacking solution, which organizations of all sizes are already enjoying.


Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.
Targets
Resources


SOC 2 Type II
SOC 3
Subscribe to our newsletter
Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.
© 2025 Fluid Attacks. We hack your software.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.
Targets
Resources


SOC 2 Type II
SOC 3
Subscribe to our newsletter
Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.
© 2025 Fluid Attacks. We hack your software.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.
Targets
Resources


SOC 2 Type II
SOC 3
Subscribe to our newsletter
Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.
© 2025 Fluid Attacks. We hack your software.

Fluid Attacks' solutions enable organizations to identify, prioritize, and remediate vulnerabilities in their software throughout the SDLC. Supported by AI, automated tools, and pentesters, Fluid Attacks accelerates companies' risk exposure mitigation and strengthens their cybersecurity posture.
Targets
Resources


SOC 2 Type II
SOC 3
Subscribe to our newsletter
Stay updated on our upcoming events and latest blog posts, advisories and other engaging resources.
© 2025 Fluid Attacks. We hack your software.