Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks

Search by term

Search filters

Discovered by

All

Severity

All

External pentesters

openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR)

9.3

Critical

CVE-2026-91107

Published date:

Oct 5, 2026

Discovered by

Daniel Esteban Celis

AI SAST Scanner

LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_min question attribute

7.2

High

CVE-2026-102626

Published date:

Oct 1, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

Our pentesters

LimeSurvey Community Edition 7.3.0 - Cross-survey object authorization bypass in REST survey patch operations

7.1

High

CVE-2026-97685

Published date:

Sep 28, 2026

Discovered by

Miguel Gómez

AI SAST Scanner

Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping

6

Medium

CVE-2026-6093

Published date:

Sep 25, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Our pentesters

Root Browser Classic 3.3.0 - OS command injection through crafted SQLite filenames

8.5

High

CVE-2026-85082

Published date:

Sep 24, 2026

Discovered by

Andrés Ramos

Our pentesters

Secure Folder 1.2 - Plaintext vault files in shared storage bypass the PIN gate

6.8

Medium

CVE-2026-84283

Published date:

Sep 24, 2026

Discovered by

Andrés Ramos

Our pentesters

LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via invalid attribute column name

7.4

High

CVE-2026-92730

Published date:

Sep 23, 2026

Discovered by

Miguel Gómez

Our pentesters

LimeSurvey Community Edition 7.0.14 - Reflected XSS through unescaped LSS survey-import warnings

7.4

High

CVE-2026-91775

Published date:

Sep 23, 2026

Discovered by

Miguel Gómez

Load more

Search by term

Search filters

Discovered by

All

Severity

All

External pentesters

openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR)

9.3

Critical

CVE-2026-91107

Published date:

Oct 5, 2026

Discovered by

Daniel Esteban Celis

AI SAST Scanner

LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_min question attribute

7.2

High

CVE-2026-102626

Published date:

Oct 1, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

Our pentesters

LimeSurvey Community Edition 7.3.0 - Cross-survey object authorization bypass in REST survey patch operations

7.1

High

CVE-2026-97685

Published date:

Sep 28, 2026

Discovered by

Miguel Gómez

AI SAST Scanner

Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping

6

Medium

CVE-2026-6093

Published date:

Sep 25, 2026

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Our pentesters

Root Browser Classic 3.3.0 - OS command injection through crafted SQLite filenames

8.5

High

CVE-2026-85082

Published date:

Sep 24, 2026

Discovered by

Andrés Ramos

Our pentesters

Secure Folder 1.2 - Plaintext vault files in shared storage bypass the PIN gate

6.8

Medium

CVE-2026-84283

Published date:

Sep 24, 2026

Discovered by

Andrés Ramos

Our pentesters

LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via invalid attribute column name

7.4

High

CVE-2026-92730

Published date:

Sep 23, 2026

Discovered by

Miguel Gómez

Our pentesters

LimeSurvey Community Edition 7.0.14 - Reflected XSS through unescaped LSS survey-import warnings

7.4

High

CVE-2026-91775

Published date:

Sep 23, 2026

Discovered by

Miguel Gómez

Load more

Search by term

Search filters

Discovered by

All

Severity

All

External pentesters

openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR)

9.3

Critical

CVE-2026-91107

Published date:

Oct 5, 2026

Discovered by

Daniel Esteban Celis

AI SAST Scanner

LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_min question attribute

7.2

High

CVE-2026-102626

Published date:

Oct 1, 2026

Discovered by

Miguel Gómez

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Miguel Gómez

Our pentesters

LimeSurvey Community Edition 7.3.0 - Cross-survey object authorization bypass in REST survey patch operations

7.1

High

CVE-2026-97685

Published date:

Sep 28, 2026

Discovered by

Miguel Gómez

AI SAST Scanner

Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping

6

Medium

CVE-2026-6093

Published date:

Sep 25, 2026

Discovered by

Oscar Uribe

Detected by

Fluid Attacks AI SAST Scanner,

disclosed by

Oscar Uribe

Our pentesters

Root Browser Classic 3.3.0 - OS command injection through crafted SQLite filenames

8.5

High

CVE-2026-85082

Published date:

Sep 24, 2026

Discovered by

Andrés Ramos

Our pentesters

Secure Folder 1.2 - Plaintext vault files in shared storage bypass the PIN gate

6.8

Medium

CVE-2026-84283

Published date:

Sep 24, 2026

Discovered by

Andrés Ramos

Our pentesters

LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via invalid attribute column name

7.4

High

CVE-2026-92730

Published date:

Sep 23, 2026

Discovered by

Miguel Gómez

Our pentesters

LimeSurvey Community Edition 7.0.14 - Reflected XSS through unescaped LSS survey-import warnings

7.4

High

CVE-2026-91775

Published date:

Sep 23, 2026

Discovered by

Miguel Gómez

Load more

Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.

Reduce risk without slowing delivery

Reduce risk without slowing delivery

Fast and accurate results from one continuous security program powered by AI, scanners, and pentesters.

Fast and accurate results from one continuous security program powered by AI, scanners, and pentesters.

Prevent

Prevent

Prevent

Detect

Detect

Detect

Manage

Manage

Manage

Remediate

Remediate

Remediate