2026 CVE Vulnerabilities

53,433 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-27403MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub L...
CVE-2026-27399MEDIUM5.3Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.
CVE-2026-27392MEDIUM4.3Contributor Broken Access Control in uListing <= 2.2.0 versions.
CVE-2026-27391MEDIUM5.4Subscriber Broken Access Control in uListing <= 2.2.0 versions.
CVE-2026-27377MEDIUM6.7Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.
CVE-2026-27372MEDIUM6.5Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVE-2026-27355MEDIUM5.3Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.
CVE-2026-27064CRITICAL9.1Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
CVE-2026-25466MEDIUM5.3Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.
CVE-2026-25427MEDIUM5.4Subscriber Broken Access Control in eRoom <= 1.7.1 versions.
CVE-2026-25424MEDIUM4.3Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.
CVE-2026-25405HIGH8.5Contributor SQL Injection in eRoom <= 1.7.1 versions.
CVE-2026-24639MEDIUM4.4Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.
CVE-2026-24628MEDIUM5.9Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.
CVE-2026-24552HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'All...
CVE-2026-24537MEDIUM4.3Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.
CVE-2026-64611HIGH7.5A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing ...
CVE-2026-16745HIGH8.8A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network b...
CVE-2026-65758HIGH8.2Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submission...
CVE-2026-65757HIGH8.1Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - T...
CVE-2026-65756MEDIUM6.1Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitr...
CVE-2026-65755HIGH7.5Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extensio...
CVE-2026-65754HIGH7.5Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths c...
CVE-2026-65713MEDIUM6.5Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumera...
CVE-2026-65712MEDIUM6.2Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now