2026 CVE Vulnerabilities

48,299 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-8203MEDIUM5.4Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $heigh...
CVE-2026-8197MEDIUM4.8Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration name. The OAuth authorize template render...
CVE-2026-8140MEDIUM6.5Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/install/down...
CVE-2026-6826MEDIUM5.3Concrete CMS 9.5.0 and below  is vulnerable to unauthenticated file usage disclosure via missing permission check in the...
CVE-2026-4843MEDIUM4.3The GSheet For Woo Importer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability ...
CVE-2026-48245MEDIUM6.9Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in tables.php that is committed to the public sou...
CVE-2026-48244MEDIUM6.9Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in settings.inc.php that is committed to the publ...
CVE-2026-48243MEDIUM6.9Open ISES Tickets before 3.44.2 embeds a hardcoded WhitePages reverse-phone API key in wp1.php that is committed to the ...
CVE-2026-48230MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ticketsmdb_import.php that al...
CVE-2026-48229MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_i.php that allows auth...
CVE-2026-48228MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_w.php that allows aut...
CVE-2026-48227MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient.php that allows authe...
CVE-2026-48226MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in os_watch.php that allows auth...
CVE-2026-48225MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in landb.php that allows authent...
CVE-2026-48224MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics214.php that allows authen...
CVE-2026-48223MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213rr.php that allows auth...
CVE-2026-48222MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213.php that allows authen...
CVE-2026-48221MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205a.php that allows authe...
CVE-2026-48220MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205.php that allows authen...
CVE-2026-48219MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics202.php that allows authen...
CVE-2026-48218MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in icons/buttons/landb.php that ...
CVE-2026-48217MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in delete_module.php that allows...
CVE-2026-48216MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in db_loader.php that allows aut...
CVE-2026-48215MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in circle.php that allows authen...
CVE-2026-48214MEDIUM5.4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_nm.php that allows authen...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now