2026 CVE Vulnerabilities

53,074 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-65943HIGH7.5Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0
CVE-2026-65891MEDIUM6.5Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function ...
CVE-2026-65885HIGH8.8Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows au...
CVE-2026-65884CRITICAL9.8Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provide...
CVE-2026-50641HIGH7.1Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in...
CVE-2026-44944HIGH8.5An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control soc...
CVE-2026-44943MEDIUM6.9An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows rem...
CVE-2026-33385MEDIUM5.1A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a hig...
CVE-2026-14354HIGH8.7CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorize...
CVE-2026-12927HIGH8.4CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execut...
CVE-2026-0667CRITICAL9.3CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, d...
CVE-2026-14270HIGH8.8The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerabl...
CVE-2026-8791MEDIUM6.4The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` ...
CVE-2026-7436MEDIUM6.4The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text...
CVE-2026-6089MEDIUM4.9The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media' parameter in impor...
CVE-2026-65883CRITICAL9.8Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A fo...
CVE-2026-5060MEDIUM6.5The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure D...
CVE-2026-56390MEDIUM6.3GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifyi...
CVE-2026-56389HIGH8.6GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of gram...
CVE-2026-50642MEDIUM4.8diff‑so‑fancy does not properly sanitize non‑SGR terminal control sequences before outputting diff data. The application...
CVE-2026-4604MEDIUM5.3The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
CVE-2026-18220HIGH7.8An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. T...
CVE-2026-16655HIGH7.2The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne...
CVE-2026-16597HIGH7.2The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scr...
CVE-2026-14900CRITICAL9.8The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now