2026 CVE Vulnerabilities
45,328 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8494 | MEDIUM | 6.4 | 0.2% | Jun 17, 2026 | The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admi... |
| CVE-2026-8383 | MEDIUM | 5.3 | 0.2% | Jun 17, 2026 | The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `e... |
| CVE-2026-7850 | MEDIUM | 5.9 | 0.1% | Jun 17, 2026 | The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting t... |
| CVE-2026-54196 | MEDIUM | 6.8 | 0.2% | Jun 17, 2026 | Subscriber Privilege Escalation in JetFormBuilder <= 3.6.1 versions. |
| CVE-2026-49072 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions. |
| CVE-2026-49071 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions. |
| CVE-2026-48783 | MEDIUM | 4.8 | 0.2% | Jun 17, 2026 | Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accept... |
| CVE-2026-48782 | MEDIUM | 6.8 | 0.3% | Jun 17, 2026 | Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 t... |
| CVE-2026-47340 | MEDIUM | 6.5 | 0.4% | Jun 17, 2026 | Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. ... |
| CVE-2026-47277 | MEDIUM | 6.5 | 0.4% | Jun 17, 2026 | Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos fro... |
| CVE-2026-45436 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions. |
| CVE-2026-44587 | MEDIUM | 6.1 | 0.2% | Jun 17, 2026 | CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_typ... |
| CVE-2026-42357 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do... |
| CVE-2026-41280 | MEDIUM | 4.9 | 0.4% | Jun 17, 2026 | Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthoriz... |
| CVE-2026-40724 | MEDIUM | 6.5 | 0.4% | Jun 17, 2026 | CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions. |
| CVE-2026-40723 | MEDIUM | 4.3 | 0.2% | Jun 17, 2026 | Subscriber Broken Access Control in Bricks Builder <= 2.1.4 versions. |
| CVE-2026-40722 | MEDIUM | 5.5 | 0.2% | Jun 17, 2026 | Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Contro... |
| CVE-2026-39595 | MEDIUM | 4.7 | 0.2% | Jun 17, 2026 | Author Broken Access Control in W3 Total Cache <= 2.9.1 versions. |
| CVE-2026-39578 | MEDIUM | 5.5 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Valiance <= 1.2 versions. |
| CVE-2026-39577 | MEDIUM | 5.5 | 0.2% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Playroom <= 1.4.1 versions. |
| CVE-2026-39433 | MEDIUM | 6.5 | 0.4% | Jun 17, 2026 | Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions. |
| CVE-2026-2604 | MEDIUM | 5.6 | 0.2% | Jun 17, 2026 | A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpa... |
| CVE-2026-28587 | MEDIUM | 5.5 | 0.1% | Jun 17, 2026 | In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing per... |
| CVE-2026-28576 | MEDIUM | 5.5 | 0.1% | Jun 17, 2026 | In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to l... |
| CVE-2026-28575 | MEDIUM | 5.5 | 0.1% | Jun 17, 2026 | In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now