2026 CVE Vulnerabilities

45,207 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-61861HIGH7.5ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory alloca...
CVE-2026-61857HIGH7.5ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP p...
CVE-2026-61454HIGH8.7The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFI...
CVE-2026-61442HIGH7.1PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for ...
CVE-2026-61439HIGH8.7PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults ...
CVE-2026-61429HIGH8.5PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend th...
CVE-2026-61428HIGH7.3PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attacke...
CVE-2026-61426HIGH8.8PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requireme...
CVE-2026-56303HIGH8.7Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function m...
CVE-2026-57828HIGH8.8Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downlo...
CVE-2026-1359HIGH8.8The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due t...
CVE-2026-9282HIGH7.5The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4...
CVE-2026-6939HIGH7.2The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'app...
CVE-2026-4661HIGH7.5The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQ...
CVE-2026-15155HIGH8.8The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authent...
CVE-2026-7655HIGH8.1The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and incl...
CVE-2026-13378HIGH7.2The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contac...
CVE-2026-3576HIGH7.2The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local ...
CVE-2026-2354HIGH8.8The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validatio...
CVE-2026-15335HIGH7.5The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in ...
CVE-2026-14262HIGH8.8The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Byp...
CVE-2026-15338HIGH7.5The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to...
CVE-2026-13353HIGH8.8The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remo...
CVE-2026-13114HIGH7.2The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2026-13756HIGH8.8The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now