Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks

Buscar por término

Search filters

Discovered by

All

Severity

All

Our scanner

Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering

4.8

Medium

CVE-2026-40230

Published date:

29 abr 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Our scanner

Helpy 2.8.0 - Stored XSS in post author display via PostsHelper

5.1

Medium

CVE-2026-40229

Published date:

29 abr 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Our scanner

Pimcore Platform v12.3.3 - Stored XSS in Document Editable Embed rendering

4.8

Medium

CVE-2026-5362

Published date:

27 abr 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

Our scanner

Pimcore Platform v12.3.3 - SQL Injection in DataObject composite index handling

7

High

CVE-2026-5394

Published date:

27 abr 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

Our scanner

Frappe Framework v16.10.0 - Stored DOM XSS in Multiple Field Formatters

4.6

Medium

CVE-2026-3837

Published date:

21 abr 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Our scanner

Frappe Framework 16.10.0 - Stored DOM XSS in Tag Pill Renderer

4.6

Medium

CVE-2026-3673

Published date:

21 abr 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Our pentesters

DOMPurify mXSS via Re-Contextualization

5.3

Medium

CVE-2026-0540

Published date:

24 mar 2026

Discovered by

Camilo Vera, Cristian Vargas and Scott Moore

External pentesters

Actual Sync Server 26.2.1 - Authenticated Path Traversal

5.3

Medium

CVE-2026-3089

Published date:

9 mar 2026

Discovered by

Juan Patarroyo

Cargar más

Buscar por término

Search filters

Discovered by

All

Severity

All

Our scanner

Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering

4.8

Medium

CVE-2026-40230

Published date:

29 abr 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Our scanner

Helpy 2.8.0 - Stored XSS in post author display via PostsHelper

5.1

Medium

CVE-2026-40229

Published date:

29 abr 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Our scanner

Pimcore Platform v12.3.3 - Stored XSS in Document Editable Embed rendering

4.8

Medium

CVE-2026-5362

Published date:

27 abr 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

Our scanner

Pimcore Platform v12.3.3 - SQL Injection in DataObject composite index handling

7

High

CVE-2026-5394

Published date:

27 abr 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

Our scanner

Frappe Framework v16.10.0 - Stored DOM XSS in Multiple Field Formatters

4.6

Medium

CVE-2026-3837

Published date:

21 abr 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Our scanner

Frappe Framework 16.10.0 - Stored DOM XSS in Tag Pill Renderer

4.6

Medium

CVE-2026-3673

Published date:

21 abr 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Our pentesters

DOMPurify mXSS via Re-Contextualization

5.3

Medium

CVE-2026-0540

Published date:

24 mar 2026

Discovered by

Camilo Vera, Cristian Vargas and Scott Moore

External pentesters

Actual Sync Server 26.2.1 - Authenticated Path Traversal

5.3

Medium

CVE-2026-3089

Published date:

9 mar 2026

Discovered by

Juan Patarroyo

Cargar más

Buscar por término

Search filters

Discovered by

All

Severity

All

Our scanner

Helpy 2.8.0 - Stored XSS in knowledgebase Doc body rendering

4.8

Medium

CVE-2026-40230

Published date:

29 abr 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Our scanner

Helpy 2.8.0 - Stored XSS in post author display via PostsHelper

5.1

Medium

CVE-2026-40229

Published date:

29 abr 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Our scanner

Pimcore Platform v12.3.3 - Stored XSS in Document Editable Embed rendering

4.8

Medium

CVE-2026-5362

Published date:

27 abr 2026

Discovered by

Oscar Naveda

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

Our scanner

Pimcore Platform v12.3.3 - SQL Injection in DataObject composite index handling

7

High

CVE-2026-5394

Published date:

27 abr 2026

Discovered by

Oscar Naveda

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Naveda

Our scanner

Frappe Framework v16.10.0 - Stored DOM XSS in Multiple Field Formatters

4.6

Medium

CVE-2026-3837

Published date:

21 abr 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Our scanner

Frappe Framework 16.10.0 - Stored DOM XSS in Tag Pill Renderer

4.6

Medium

CVE-2026-3673

Published date:

21 abr 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Our pentesters

DOMPurify mXSS via Re-Contextualization

5.3

Medium

CVE-2026-0540

Published date:

24 mar 2026

Discovered by

Camilo Vera, Cristian Vargas and Scott Moore

External pentesters

Actual Sync Server 26.2.1 - Authenticated Path Traversal

5.3

Medium

CVE-2026-3089

Published date:

9 mar 2026

Discovered by

Juan Patarroyo

Cargar más

Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.

Inicia tu prueba gratuita de 21 días

Descubre los beneficios de nuestra solución Hacking Continuo, de la que ya disfrutan empresas de todos los tamaños.

Inicia tu prueba gratuita de 21 días

Descubre los beneficios de nuestra solución Hacking Continuo, de la que ya disfrutan empresas de todos los tamaños.

Inicia tu prueba gratuita de 21 días

Descubre los beneficios de nuestra solución Hacking Continuo, de la que ya disfrutan empresas de todos los tamaños.

Las soluciones de Fluid Attacks permiten a las organizaciones identificar, priorizar y remediar vulnerabilidades en su software a lo largo del SDLC. Con el apoyo de la IA, herramientas automatizadas y pentesters, Fluid Attacks acelera la mitigación de la exposición al riesgo de las empresas y fortalece su postura de ciberseguridad.

Lee un resumen de Fluid Attacks

Suscríbete a nuestro boletín

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

SOC 2 Type II

SOC 3

Las soluciones de Fluid Attacks permiten a las organizaciones identificar, priorizar y remediar vulnerabilidades en su software a lo largo del SDLC. Con el apoyo de la IA, herramientas automatizadas y pentesters, Fluid Attacks acelera la mitigación de la exposición al riesgo de las empresas y fortalece su postura de ciberseguridad.

Suscríbete a nuestro boletín

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

SOC 2 Type II

SOC 3

Las soluciones de Fluid Attacks permiten a las organizaciones identificar, priorizar y remediar vulnerabilidades en su software a lo largo del SDLC. Con el apoyo de la IA, herramientas automatizadas y pentesters, Fluid Attacks acelera la mitigación de la exposición al riesgo de las empresas y fortalece su postura de ciberseguridad.

Suscríbete a nuestro boletín

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

Mantente al día sobre nuestros próximos eventos y los últimos blog posts, advisories y otros recursos interesantes.

SOC 2 Type II

SOC 3