2026 CVE Vulnerabilities
53,433 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27403 | MEDIUM | 6.5 | — | Jul 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub L... |
| CVE-2026-27399 | MEDIUM | 5.3 | — | Jul 23, 2026 | Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions. |
| CVE-2026-27392 | MEDIUM | 4.3 | — | Jul 23, 2026 | Contributor Broken Access Control in uListing <= 2.2.0 versions. |
| CVE-2026-27391 | MEDIUM | 5.4 | — | Jul 23, 2026 | Subscriber Broken Access Control in uListing <= 2.2.0 versions. |
| CVE-2026-27377 | MEDIUM | 6.7 | — | Jul 23, 2026 | Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions. |
| CVE-2026-27372 | MEDIUM | 6.5 | — | Jul 23, 2026 | Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions. |
| CVE-2026-27355 | MEDIUM | 5.3 | — | Jul 23, 2026 | Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions. |
| CVE-2026-27064 | CRITICAL | 9.1 | — | Jul 23, 2026 | Editor Arbitrary File Upload in Mailster <= 4.1.17 versions. |
| CVE-2026-25466 | MEDIUM | 5.3 | — | Jul 23, 2026 | Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions. |
| CVE-2026-25427 | MEDIUM | 5.4 | — | Jul 23, 2026 | Subscriber Broken Access Control in eRoom <= 1.7.1 versions. |
| CVE-2026-25424 | MEDIUM | 4.3 | — | Jul 23, 2026 | Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions. |
| CVE-2026-25405 | HIGH | 8.5 | — | Jul 23, 2026 | Contributor SQL Injection in eRoom <= 1.7.1 versions. |
| CVE-2026-24639 | MEDIUM | 4.4 | — | Jul 23, 2026 | Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions. |
| CVE-2026-24628 | MEDIUM | 5.9 | — | Jul 23, 2026 | Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions. |
| CVE-2026-24552 | HIGH | 8.5 | 0.2% | Jul 23, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'All... |
| CVE-2026-24537 | MEDIUM | 4.3 | — | Jul 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions. |
| CVE-2026-64611 | HIGH | 7.5 | 0.3% | Jul 23, 2026 | A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing ... |
| CVE-2026-16745 | HIGH | 8.8 | 0.4% | Jul 23, 2026 | A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network b... |
| CVE-2026-65758 | HIGH | 8.2 | — | Jul 23, 2026 | Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submission... |
| CVE-2026-65757 | HIGH | 8.1 | 0.1% | Jul 23, 2026 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - T... |
| CVE-2026-65756 | MEDIUM | 6.1 | 0.2% | Jul 23, 2026 | Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitr... |
| CVE-2026-65755 | HIGH | 7.5 | 0.1% | Jul 23, 2026 | Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extensio... |
| CVE-2026-65754 | HIGH | 7.5 | 0.2% | Jul 23, 2026 | Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths c... |
| CVE-2026-65713 | MEDIUM | 6.5 | 0.2% | Jul 23, 2026 | Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumera... |
| CVE-2026-65712 | MEDIUM | 6.2 | 0.2% | Jul 23, 2026 | Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now