2026 CVE Vulnerabilities

50,911 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-61483HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: al...
CVE-2026-5651MEDIUM4.9The Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in multiple AJAX actions (a...
CVE-2026-5581CRITICAL9.1The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all ...
CVE-2026-5116MEDIUM4.4The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ver...
CVE-2026-5108MEDIUM4.4The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_setti...
CVE-2026-59675HIGH7.5When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a siz...
CVE-2026-55998MEDIUM5.3The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid ...
CVE-2026-55997HIGH8.8Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These token...
CVE-2026-55996MEDIUM4.3A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent com...
CVE-2026-55747MEDIUM6.8The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir...
CVE-2026-55739HIGH8.3Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability ch...
CVE-2026-54418HIGH8.1Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, ...
CVE-2026-54416HIGH7.2Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist i...
CVE-2026-4431CRITICAL9.1The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2026-18881HIGH7.5The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter...
CVE-2026-17532MEDIUM6.1The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_p...
CVE-2026-17505MEDIUM6.1The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v...
CVE-2026-15281MEDIUM6.5The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the w...
CVE-2026-12000HIGH7.5The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and...
CVE-2026-11977MEDIUM6.5The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to ...
CVE-2026-11969MEDIUM4.9The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Paramete...
CVE-2026-11920MEDIUM4.9The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL ...
CVE-2026-11454MEDIUM6.5The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object...
CVE-2026-71201MEDIUM5In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assign...
CVE-2026-70375HIGH8.8HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDe...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now