2026 CVE Vulnerabilities

43,896 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-57406MEDIUM6.5Missing Authorization vulnerability in Roxnor FundEngine wp-fundraising-donation allows Exploiting Incorrectly Configure...
CVE-2026-57404MEDIUM6.5Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocomme...
CVE-2026-57402MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdesk Flexible Re...
CVE-2026-57400MEDIUM6.5Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocomm...
CVE-2026-57395MEDIUM6.5Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control ...
CVE-2026-57393MEDIUM6.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF I...
CVE-2026-57392MEDIUM6.5Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control ...
CVE-2026-57391MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tangible Loops & L...
CVE-2026-57390MEDIUM6.5Missing Authorization vulnerability in EDGARROJAS Extra Product Options Builder for WooCommerce additional-product-field...
CVE-2026-57377MEDIUM6.5Missing Authorization vulnerability in WPXPO WowAddons product-addons allows Exploiting Incorrectly Configured Access Co...
CVE-2026-57375MEDIUM6.5Missing Authorization vulnerability in FluxBuilder MStore API mstore-api allows Exploiting Incorrectly Configured Access...
CVE-2026-57365MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hitesh Chandwani r...
CVE-2026-57364MEDIUM6.5Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment – Instant Payments, Donat...
CVE-2026-49876MEDIUM6.5Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpo...
CVE-2026-14846MEDIUM4.5In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by i...
CVE-2026-9708MEDIUM4.9Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming w...
CVE-2026-9597MEDIUM5.4Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before crea...
CVE-2026-9571MEDIUM6.5Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon...
CVE-2026-6850MEDIUM6.5Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of m...
CVE-2026-15547MEDIUM6.3A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048 of the component CI...
CVE-2026-15546MEDIUM6.3A security flaw has been discovered in Shibby Tomato up to 1.28.0000. Affected by this issue is the function sub_2D568 o...
CVE-2026-10106MEDIUM6.5Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced i...
CVE-2026-10103MEDIUM4.3Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared ...
CVE-2026-10085MEDIUM5.4Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained chann...
CVE-2026-57829MEDIUM6.1Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ul...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now