2026 CVE Vulnerabilities

65,328 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-93000MEDIUM6.8The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its ...
CVE-2026-92996MEDIUM5.3The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a payment was actu...
CVE-2026-89411MEDIUM5.3The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the ...
CVE-2026-89303MEDIUM6.4The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in...
CVE-2026-89300MEDIUM5.3The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowi...
CVE-2026-88828MEDIUM5.4The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every a...
CVE-2026-86838MEDIUM5.3The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before c...
CVE-2026-84744MEDIUM6.5The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values...
CVE-2026-101009HIGH8.4A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function panelTask.bt_task._un...
CVE-2026-101008CRITICAL9.1A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the function merge_split_file of the file /www/serv...
CVE-2026-101007HIGH8.4A vulnerability has been found in aaPanel BaoTa up to 11.8.0. This issue affects the function InputSql of the file class...
CVE-2026-101006MEDIUM4.3A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_r...
CVE-2026-101005HIGH7.3A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file...
CVE-2026-100751HIGH7.5Joomla Extension - regularlabs.com - Privileged stored XSS via data-rlta-url attributes in Tabs & Accordions (Pro) 2.3.0...
CVE-2026-100750HIGH8.5Joomla Extension - regularlabs.com - LFI / SSRF in Modules Anywhere 1.5.0 - 9.0.5 for Joomla - Modules Anywhere Pro lets...
CVE-2026-101004MEDIUM5.3A security vulnerability has been detected in notionnext-org NotionNext up to 4.10.10. Affected by this issue is the fun...
CVE-2026-101003MEDIUM5.3A weakness has been identified in Cesanta Mongoose up to 7.21. Affected by this vulnerability is the function fn of the ...
CVE-2026-101002CRITICAL9.9A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function system of the file /...
CVE-2026-87723MEDIUM5.4In Google fuse-archive versions prior to 1.24, an attacker who can prepend a directory to PATH or write a malicious bina...
CVE-2026-101001CRITICAL10A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cg...
CVE-2026-101000CRITICAL10A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /u...
CVE-2026-100909HIGH7.3A vulnerability was found in OctoberCMS up to 4.1.19/4.2.25/4.3.4. The impacted element is the function getSourcePathFor...
CVE-2026-100908HIGH7.5A vulnerability has been found in Eyeplus 57.0.0.0308. This affects an unknown function of the component p2pcam HTTP Par...
CVE-2026-100907MEDIUM5.3A flaw has been found in Eyeplus 57.0.0.0308. The impacted element is an unknown function of the file /snapshot of the c...
CVE-2026-100906MEDIUM5.3A vulnerability was detected in Eyeplus 57.0.0.0308. The affected element is the function GetUsers of the file /onvif/De...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now