2026 CVE Vulnerabilities
48,299 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8203 | MEDIUM | 5.4 | 0.1% | May 21, 2026 | Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $heigh... |
| CVE-2026-8197 | MEDIUM | 4.8 | 0.2% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration name. The OAuth authorize template render... |
| CVE-2026-8140 | MEDIUM | 6.5 | 0.1% | May 21, 2026 | Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/install/down... |
| CVE-2026-6826 | MEDIUM | 5.3 | 0.3% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to unauthenticated file usage disclosure via missing permission check in the... |
| CVE-2026-4843 | MEDIUM | 4.3 | 0.2% | May 21, 2026 | The GSheet For Woo Importer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability ... |
| CVE-2026-48245 | MEDIUM | 6.9 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in tables.php that is committed to the public sou... |
| CVE-2026-48244 | MEDIUM | 6.9 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in settings.inc.php that is committed to the publ... |
| CVE-2026-48243 | MEDIUM | 6.9 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 embeds a hardcoded WhitePages reverse-phone API key in wp1.php that is committed to the ... |
| CVE-2026-48230 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ticketsmdb_import.php that al... |
| CVE-2026-48229 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_i.php that allows auth... |
| CVE-2026-48228 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_w.php that allows aut... |
| CVE-2026-48227 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient.php that allows authe... |
| CVE-2026-48226 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in os_watch.php that allows auth... |
| CVE-2026-48225 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in landb.php that allows authent... |
| CVE-2026-48224 | MEDIUM | 5.4 | 0.3% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics214.php that allows authen... |
| CVE-2026-48223 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213rr.php that allows auth... |
| CVE-2026-48222 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213.php that allows authen... |
| CVE-2026-48221 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205a.php that allows authe... |
| CVE-2026-48220 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205.php that allows authen... |
| CVE-2026-48219 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics202.php that allows authen... |
| CVE-2026-48218 | MEDIUM | 5.4 | 0.3% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in icons/buttons/landb.php that ... |
| CVE-2026-48217 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in delete_module.php that allows... |
| CVE-2026-48216 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in db_loader.php that allows aut... |
| CVE-2026-48215 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in circle.php that allows authen... |
| CVE-2026-48214 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_nm.php that allows authen... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now