2026 CVE Vulnerabilities

43,950 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-13262MEDIUM6.5The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to generi...
CVE-2026-12426MEDIUM5.3The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure ...
CVE-2026-10628MEDIUM4.3The Points and Rewards for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to,...
CVE-2026-11426MEDIUM6.5The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and inclu...
CVE-2026-15087MEDIUM5.9vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.
CVE-2026-15086MEDIUM5.9vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter...
CVE-2026-11915MEDIUM5.9vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions...
CVE-2026-11914MEDIUM5.9vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*.
CVE-2026-59155MEDIUM6.9Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to 2.2.5, the GET ...
CVE-2026-58591MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox al...
CVE-2026-58590MEDIUM5.4Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: f...
CVE-2026-58589MEDIUM5.4Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: f...
CVE-2026-58588MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canv...
CVE-2026-58587MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canv...
CVE-2026-58503MEDIUM6.9Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via...
CVE-2026-55808MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core...
CVE-2026-55806MEDIUM5.9URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This is...
CVE-2026-55804MEDIUM5.9Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow...
CVE-2026-55803MEDIUM5.9Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow...
CVE-2026-55187MEDIUM5.8Mailpit is an email testing tool and API for developers. Prior to 1.30.2, the remediation shipped for CVE-2026-27808 is ...
CVE-2026-52761MEDIUM5.3ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0....
CVE-2026-49844MEDIUM5.9Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces ...
CVE-2026-48127MEDIUM5.3Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach...
CVE-2026-47422MEDIUM5.3Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked approp...
CVE-2026-42219MEDIUM6.9Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, path traversal via download_backups was...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now