2026 CVE Vulnerabilities
45,091 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57629 | MEDIUM | 6.5 | 0.2% | Jun 26, 2026 | Contributor Cross Site Scripting (XSS) in StatCounter <= 2.1.1 versions. |
| CVE-2026-57627 | MEDIUM | 4.9 | — | Jun 26, 2026 | Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions. |
| CVE-2026-57622 | MEDIUM | 4.3 | — | Jun 26, 2026 | Subscriber Broken Access Control in WPCafe <= 3.0.14 versions. |
| CVE-2026-57618 | MEDIUM | 6.5 | — | Jun 26, 2026 | Contributor Cross Site Scripting (XSS) in Neve PRO <= 3.1.2 versions. |
| CVE-2026-57617 | MEDIUM | 6.5 | — | Jun 26, 2026 | Contributor Cross Site Scripting (XSS) in SeedProd Pro < 6.19.5 versions. |
| CVE-2026-57431 | MEDIUM | 6.5 | 0.2% | Jun 26, 2026 | Author Cross Site Scripting (XSS) in Featured Image <= 2.1 versions. |
| CVE-2026-57430 | MEDIUM | 4.3 | — | Jun 26, 2026 | Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions. |
| CVE-2026-57324 | MEDIUM | 6.5 | — | Jun 26, 2026 | Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions. |
| CVE-2026-57323 | MEDIUM | 5.8 | — | Jun 26, 2026 | Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions. |
| CVE-2026-57318 | MEDIUM | 6.5 | — | Jun 26, 2026 | Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions. |
| CVE-2026-57316 | MEDIUM | 6.5 | — | Jun 26, 2026 | Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions. |
| CVE-2026-57313 | MEDIUM | 6.5 | — | Jun 26, 2026 | Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions. |
| CVE-2026-56066 | MEDIUM | 5.8 | — | Jun 26, 2026 | Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions. |
| CVE-2026-56048 | MEDIUM | 6.5 | 0.2% | Jun 26, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= ... |
| CVE-2026-56046 | MEDIUM | 6.5 | — | Jun 26, 2026 | Subscriber Cross Site Scripting (XSS) in ListingPro <= 2.9.11 versions. |
| CVE-2026-56026 | MEDIUM | 6.4 | — | Jun 26, 2026 | Subscriber Server Side Request Forgery (SSRF) in utm.codes <= 1.9.0 versions. |
| CVE-2026-52701 | MEDIUM | 6.5 | — | Jun 26, 2026 | Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions. |
| CVE-2026-4339 | MEDIUM | 6.5 | 0.1% | Jun 26, 2026 | Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against int... |
| CVE-2026-45256 | MEDIUM | 5.5 | — | Jun 26, 2026 | When used to deliver a signal to a specific thread, thr_kill2(2) called p_cansignal() to determine whether the operation... |
| CVE-2026-30040 | MEDIUM | 6.5 | — | Jun 26, 2026 | A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary... |
| CVE-2026-24547 | MEDIUM | 5.3 | — | Jun 26, 2026 | Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions. |
| CVE-2026-57925 | MEDIUM | 5.3 | 0.2% | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags |
| CVE-2026-57924 | MEDIUM | 5.3 | 0.2% | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details |
| CVE-2026-57922 | MEDIUM | 5.3 | 0.1% | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible |
| CVE-2026-13426 | MEDIUM | 5.4 | — | Jun 26, 2026 | The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path paramet... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now