Publicly disclosed vulnerabilities discovered by or reported to Fluid Attacks
External pentesters
openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR)
9.3
Critical
CVE-2026-91107
Published date:
Oct 5, 2026
Discovered by
Daniel Esteban Celis
AI SAST Scanner
LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_min question attribute
7.2
High
CVE-2026-102626
Published date:
Oct 1, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
Our pentesters
LimeSurvey Community Edition 7.3.0 - Cross-survey object authorization bypass in REST survey patch operations
7.1
High
CVE-2026-97685
Published date:
Sep 28, 2026
Discovered by
Miguel Gómez
AI SAST Scanner
Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping
6
Medium
CVE-2026-6093
Published date:
Sep 25, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
Our pentesters
Root Browser Classic 3.3.0 - OS command injection through crafted SQLite filenames
8.5
High
CVE-2026-85082
Published date:
Sep 24, 2026
Discovered by
Andrés Ramos
Our pentesters
Secure Folder 1.2 - Plaintext vault files in shared storage bypass the PIN gate
6.8
Medium
CVE-2026-84283
Published date:
Sep 24, 2026
Discovered by
Andrés Ramos
Our pentesters
LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via invalid attribute column name
7.4
High
CVE-2026-92730
Published date:
Sep 23, 2026
Discovered by
Miguel Gómez
Our pentesters
LimeSurvey Community Edition 7.0.14 - Reflected XSS through unescaped LSS survey-import warnings
7.4
High
CVE-2026-91775
Published date:
Sep 23, 2026
Discovered by
Miguel Gómez
Load more
External pentesters
openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR)
9.3
Critical
CVE-2026-91107
Published date:
Oct 5, 2026
Discovered by
Daniel Esteban Celis
AI SAST Scanner
LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_min question attribute
7.2
High
CVE-2026-102626
Published date:
Oct 1, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
Our pentesters
LimeSurvey Community Edition 7.3.0 - Cross-survey object authorization bypass in REST survey patch operations
7.1
High
CVE-2026-97685
Published date:
Sep 28, 2026
Discovered by
Miguel Gómez
AI SAST Scanner
Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping
6
Medium
CVE-2026-6093
Published date:
Sep 25, 2026
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
Our pentesters
Root Browser Classic 3.3.0 - OS command injection through crafted SQLite filenames
8.5
High
CVE-2026-85082
Published date:
Sep 24, 2026
Discovered by
Andrés Ramos
Our pentesters
Secure Folder 1.2 - Plaintext vault files in shared storage bypass the PIN gate
6.8
Medium
CVE-2026-84283
Published date:
Sep 24, 2026
Discovered by
Andrés Ramos
Our pentesters
LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via invalid attribute column name
7.4
High
CVE-2026-92730
Published date:
Sep 23, 2026
Discovered by
Miguel Gómez
Our pentesters
LimeSurvey Community Edition 7.0.14 - Reflected XSS through unescaped LSS survey-import warnings
7.4
High
CVE-2026-91775
Published date:
Sep 23, 2026
Discovered by
Miguel Gómez
Load more
External pentesters
openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR)
9.3
Critical
CVE-2026-91107
Published date:
Oct 5, 2026
Discovered by
Daniel Esteban Celis
AI SAST Scanner
LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_min question attribute
7.2
High
CVE-2026-102626
Published date:
Oct 1, 2026
Discovered by
Miguel Gómez
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Miguel Gómez
Our pentesters
LimeSurvey Community Edition 7.3.0 - Cross-survey object authorization bypass in REST survey patch operations
7.1
High
CVE-2026-97685
Published date:
Sep 28, 2026
Discovered by
Miguel Gómez
AI SAST Scanner
Corteza 2024.9.8 - SQL Injection in MSSQL JSON-path meta filter via incorrect T-SQL string escaping
6
Medium
CVE-2026-6093
Published date:
Sep 25, 2026
Discovered by
Oscar Uribe
Detected by
Fluid Attacks AI SAST Scanner,
disclosed by
Oscar Uribe
Our pentesters
Root Browser Classic 3.3.0 - OS command injection through crafted SQLite filenames
8.5
High
CVE-2026-85082
Published date:
Sep 24, 2026
Discovered by
Andrés Ramos
Our pentesters
Secure Folder 1.2 - Plaintext vault files in shared storage bypass the PIN gate
6.8
Medium
CVE-2026-84283
Published date:
Sep 24, 2026
Discovered by
Andrés Ramos
Our pentesters
LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via invalid attribute column name
7.4
High
CVE-2026-92730
Published date:
Sep 23, 2026
Discovered by
Miguel Gómez
Our pentesters
LimeSurvey Community Edition 7.0.14 - Reflected XSS through unescaped LSS survey-import warnings
7.4
High
CVE-2026-91775
Published date:
Sep 23, 2026
Discovered by
Miguel Gómez
Load more


Learn about our policy for disclosing advisories of vulnerabilities in third-party, open-source products.

Reduce risk without slowing delivery
Reduce risk without slowing delivery
Fast and accurate results from one continuous security program powered by AI, scanners, and pentesters.
Fast and accurate results from one continuous security program powered by AI, scanners, and pentesters.
PreventPrevent
PreventPrevent
PreventPrevent
DetectDetect
DetectDetect
DetectDetect
ManageManage
ManageManage
ManageManage
RemediateRemediate
RemediateRemediate
RemediateRemediate
Solutions
Resources
Solutions
Resources
Solutions
Resources














