2026 CVE Vulnerabilities
43,896 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57406 | MEDIUM | 6.5 | 0.3% | Jul 13, 2026 | Missing Authorization vulnerability in Roxnor FundEngine wp-fundraising-donation allows Exploiting Incorrectly Configure... |
| CVE-2026-57404 | MEDIUM | 6.5 | 0.3% | Jul 13, 2026 | Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocomme... |
| CVE-2026-57402 | MEDIUM | 6.5 | 0.2% | Jul 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdesk Flexible Re... |
| CVE-2026-57400 | MEDIUM | 6.5 | 0.3% | Jul 13, 2026 | Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocomm... |
| CVE-2026-57395 | MEDIUM | 6.5 | 0.3% | Jul 13, 2026 | Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2026-57393 | MEDIUM | 6.5 | 0.3% | Jul 13, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF I... |
| CVE-2026-57392 | MEDIUM | 6.5 | 0.3% | Jul 13, 2026 | Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2026-57391 | MEDIUM | 6.5 | 0.2% | Jul 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tangible Loops & L... |
| CVE-2026-57390 | MEDIUM | 6.5 | 0.3% | Jul 13, 2026 | Missing Authorization vulnerability in EDGARROJAS Extra Product Options Builder for WooCommerce additional-product-field... |
| CVE-2026-57377 | MEDIUM | 6.5 | 0.3% | Jul 13, 2026 | Missing Authorization vulnerability in WPXPO WowAddons product-addons allows Exploiting Incorrectly Configured Access Co... |
| CVE-2026-57375 | MEDIUM | 6.5 | 0.3% | Jul 13, 2026 | Missing Authorization vulnerability in FluxBuilder MStore API mstore-api allows Exploiting Incorrectly Configured Access... |
| CVE-2026-57365 | MEDIUM | 6.5 | 0.2% | Jul 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hitesh Chandwani r... |
| CVE-2026-57364 | MEDIUM | 6.5 | 0.4% | Jul 13, 2026 | Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment – Instant Payments, Donat... |
| CVE-2026-49876 | MEDIUM | 6.5 | 0.2% | Jul 13, 2026 | Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpo... |
| CVE-2026-14846 | MEDIUM | 4.5 | 0.3% | Jul 13, 2026 | In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by i... |
| CVE-2026-9708 | MEDIUM | 4.9 | 0.2% | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming w... |
| CVE-2026-9597 | MEDIUM | 5.4 | 0.1% | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before crea... |
| CVE-2026-9571 | MEDIUM | 6.5 | 0.2% | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon... |
| CVE-2026-6850 | MEDIUM | 6.5 | 0.2% | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of m... |
| CVE-2026-15547 | MEDIUM | 6.3 | 1.1% | Jul 13, 2026 | A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048 of the component CI... |
| CVE-2026-15546 | MEDIUM | 6.3 | 1.1% | Jul 13, 2026 | A security flaw has been discovered in Shibby Tomato up to 1.28.0000. Affected by this issue is the function sub_2D568 o... |
| CVE-2026-10106 | MEDIUM | 6.5 | 0.2% | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced i... |
| CVE-2026-10103 | MEDIUM | 4.3 | 0.1% | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared ... |
| CVE-2026-10085 | MEDIUM | 5.4 | 0.2% | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained chann... |
| CVE-2026-57829 | MEDIUM | 6.1 | 0.1% | Jul 13, 2026 | Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ul... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now