2026 CVE Vulnerabilities

64,659 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8409HIGH8.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delet...
CVE-2026-8337MEDIUM5.3Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in s...
CVE-2026-8327MEDIUM4.3Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass...
CVE-2026-8245MEDIUM5.4Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection. Concrete\...
CVE-2026-8240MEDIUM5.3Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure across every page with a configur...
CVE-2026-8239MEDIUM5.3Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/get_rating' endpoint confirms exist...
CVE-2026-8238MEDIUM5.3Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/message_page' endpoint returns the ...
CVE-2026-8237MEDIUM5.3Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail` endpoint returns th...
CVE-2026-8236MEDIUM4.3Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate. The endpoint /ccm/system...
CVE-2026-8139MEDIUM5.4Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExte...
CVE-2026-7890MEDIUM6.4In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-s...
CVE-2026-7887MEDIUM6.4For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A user with uIsActive=0 ...
CVE-2026-7886MEDIUM4.3Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter which can lea...
CVE-2026-7882MEDIUM4.3Concrete CMS 9.5.0 and below is vulnerable to unauthorized file deletion due to an Inverted CSRF token check in the Del...
CVE-2026-7881MEDIUM4.3Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block via...
CVE-2026-7879MEDIUM5.3In Concrete CMS 9.5.0 and below,  the submit_password() method in concrete/controllers/single_page/download_file.php all...
CVE-2026-6960CRITICAL9.8The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in...
CVE-2026-5091MEDIUM5.1Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions us...
CVE-2026-4929MEDIUM5.4Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper output escaping of term...
CVE-2026-4093MEDIUM5.4In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter rendering pipeline. Ve...
CVE-2026-22678MEDIUM5.4Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the ...
CVE-2026-8428HIGH8.8Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but...
CVE-2026-8426HIGH8.8Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepa...
CVE-2026-8421HIGH8.8Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/singl...
CVE-2026-8417HIGH8.8Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/do_up...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now