2026 CVE Vulnerabilities

61,555 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-49741HIGH8.7Backend users with write access to the form_definition database table were able to directly create, update, or delete fo...
CVE-2026-49740MEDIUM6.3TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without in...
CVE-2026-49738LOW2.1The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requir...
CVE-2026-47352MEDIUM5.3Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission...
CVE-2026-47351MEDIUM5.3Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission ch...
CVE-2026-47350MEDIUM5.3Backend users were able to move records to a different page without having edit permissions on the source page. This iss...
CVE-2026-47349MEDIUM5.3Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they w...
CVE-2026-47348MEDIUM5.1Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in...
CVE-2026-47347MEDIUM5.3Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks ...
CVE-2026-47346HIGH7.6Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .F...
CVE-2026-47343HIGH7.2Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on fold...
CVE-2026-11607HIGH7.6Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, whi...
CVE-2026-52902MEDIUM4.7A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize ...
CVE-2026-4058MEDIUM4.3The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...
CVE-2026-46749CRITICAL9.8A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a pas...
CVE-2026-46748HIGH7.8A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a bina...
CVE-2026-46747MEDIUM5.3A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not p...
CVE-2026-46746HIGH8.8A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly s...
CVE-2026-41031CRITICAL9.3A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) allows an ...
CVE-2026-24349HIGH8.2A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Run...
CVE-2026-10731CRITICAL9.3SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/u...
CVE-2026-8677MEDIUM6.4The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored...
CVE-2026-8599MEDIUM6.4The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable ...
CVE-2026-8365HIGH8.8The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_...
CVE-2026-7542MEDIUM6.5The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions 7.0 to 7.0.10. ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now