2026 CVE Vulnerabilities

48,529 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-6008MEDIUM6.8Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Pu...
CVE-2026-5790MEDIUM5.1Stored Cross-Site Scripting (XSS) in Stel Order v3.25.1 and earlier, located at the ‘/app/FrontController’ endpoint via ...
CVE-2026-43644MEDIUM6.1podinfo through 6.11.2 contains a reflected cross-site scripting vulnerability in the /echo and /api/echo endpoints wher...
CVE-2026-45205MEDIUM5.3Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Config...
CVE-2026-8295MEDIUM6.9An integer overflow vulnerability in the simdjson document-builder API allows incorrect buffer size calculations in "str...
CVE-2026-6504MEDIUM6.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titl...
CVE-2026-6206MEDIUM5.3The MW WP Form plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.1.2 vi...
CVE-2026-6174MEDIUM6.4The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'more' parameter in all ver...
CVE-2026-6145MEDIUM5.3The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, an...
CVE-2026-6670MEDIUM6.5The Media Sync plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.9 via the ...
CVE-2026-6252MEDIUM6.4The Meta Field Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tagName' block attribute...
CVE-2026-6225MEDIUM6.5The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to time...
CVE-2026-5365MEDIUM4.3The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 5.3.2...
CVE-2026-5193MEDIUM6.5The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privile...
CVE-2026-3694MEDIUM6.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the ...
CVE-2026-8280MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.9.7, 18.10 before 18.10.6, and ...
CVE-2026-8144MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and...
CVE-2026-7481MEDIUM5.4GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.9.7, 18.10 before 18.10.6, and 18...
CVE-2026-7377MEDIUM5.4GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18...
CVE-2026-6883MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18...
CVE-2026-6417MEDIUM6.1The GLS Shipping for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'failed_or...
CVE-2026-6335MEDIUM5.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.3 that under certain condi...
CVE-2026-6073MEDIUM5.4GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18...
CVE-2026-6063MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, and 1...
CVE-2026-5243MEDIUM6.4The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for Wor...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now