2026 CVE Vulnerabilities

43,347 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-57769HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.
CVE-2026-57767HIGH7.1Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.
CVE-2026-57735HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions.
CVE-2026-57704HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.
CVE-2026-57701HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.
CVE-2026-57699HIGH7.1Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.
CVE-2026-57696HIGH7.1Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.
CVE-2026-57626HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailP...
CVE-2026-57428HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.
CVE-2026-57427HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.
CVE-2026-57397HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions.
CVE-2026-57374HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions.
CVE-2026-57370HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.
CVE-2026-57367HIGH7.1Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
CVE-2026-25405HIGH8.5Contributor SQL Injection in eRoom <= 1.7.1 versions.
CVE-2026-24552HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'All...
CVE-2026-64611HIGH7.5A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing ...
CVE-2026-16745HIGH8.8A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network b...
CVE-2026-65758HIGH8.2Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submission...
CVE-2026-65757HIGH8.1Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - T...
CVE-2026-65755HIGH7.5Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extensio...
CVE-2026-65754HIGH7.5Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths c...
CVE-2026-65430HIGH7.5Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in...
CVE-2026-64876HIGH8.8Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-up...
CVE-2026-64799HIGH7.5Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now