2026 CVE Vulnerabilities

53,433 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-65431CRITICAL9.8Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extr...
CVE-2026-65430HIGH7.5Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in...
CVE-2026-64876HIGH8.8Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-up...
CVE-2026-64875MEDIUM6.5Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forw...
CVE-2026-64874CRITICAL9.8Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed i...
CVE-2026-64873CRITICAL9.8Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or re...
CVE-2026-64872MEDIUM6.5Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could es...
CVE-2026-64871MEDIUM5.4Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Admi...
CVE-2026-64799HIGH7.5Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions ...
CVE-2026-16078MEDIUM6.5The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all ...
CVE-2026-15906MEDIUM6.5The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via th...
CVE-2026-15827MEDIUM5.3The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check ...
CVE-2026-15794MEDIUM6.4The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shor...
CVE-2026-15786MEDIUM4.4The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is v...
CVE-2026-15761MEDIUM6.5The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event...
CVE-2026-15647MEDIUM4.4The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term...
CVE-2026-15646MEDIUM6.4The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attri...
CVE-2026-15448MEDIUM6.5The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order...
CVE-2026-15404MEDIUM6.4The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and inc...
CVE-2026-15394MEDIUM6.4The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross...
CVE-2026-15348MEDIUM6.3The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all...
CVE-2026-15017HIGH8.8The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin...
CVE-2026-15015CRITICAL9.8The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions u...
CVE-2026-15011CRITICAL9.8The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parame...
CVE-2026-14481MEDIUM6.4The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now