2026 CVE Vulnerabilities

53,362 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-25198MEDIUM5.1web2py versions 2.27.1-stable+timestamp.2023.11.16.08.03.57 and prior contain an open redirect vulnerability. If this vu...
CVE-2026-1268MEDIUM6.4The Dynamic Widget Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget content fiel...
CVE-2026-1246MEDIUM4.9The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary File Read via path traversal in the 'load...
CVE-2026-0867MEDIUM6.4The Essential Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ew-author, ew-a...
CVE-2026-1898MEDIUM6.3A vulnerability was determined in WeKan up to 8.20. This affects an unknown part of the file packages/wekan-ldap/server/...
CVE-2026-1897MEDIUM5.3A vulnerability was found in WeKan up to 8.20. Affected by this issue is some unknown functionality of the file server/m...
CVE-2026-1896MEDIUM6.3A vulnerability has been found in WeKan up to 8.20. Affected by this vulnerability is the function ComprehensiveBoardMig...
CVE-2026-1895MEDIUM6.3A flaw has been found in WeKan up to 8.20. Affected is the function applyWipLimit of the file models/lists.js of the com...
CVE-2026-1894MEDIUM5.4A vulnerability was detected in WeKan up to 8.20. This impacts an unknown function of the file models/checklistItems.js ...
CVE-2026-25579MEDIUM6.5Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, authenticated users...
CVE-2026-25578MEDIUM6.1Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, a cross-site script...
CVE-2026-25543MEDIUM6.1HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. ...
CVE-2026-25540MEDIUM6.5Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.3.19, 4.4.13, 4.5.6, Mas...
CVE-2026-25523MEDIUM5.3Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin ur...
CVE-2026-25518MEDIUM5.9cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the proc...
CVE-2026-1892MEDIUM5A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file model...
CVE-2026-1884MEDIUM4.9A weakness has been identified in ZenTao up to 21.7.6-85642. The impacted element is the function fetchHook of the file ...
CVE-2026-25511MEDIUM4.9Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, a...
CVE-2026-1554MEDIUM4.2XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Priv...
CVE-2026-1553MEDIUM4.8Incorrect Authorization vulnerability in Drupal Drupal Canvas allows Forceful Browsing.This issue affects Drupal Canvas:...
CVE-2026-0948MEDIUM6.5Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Microsoft Entra ID SSO Login allows Pri...
CVE-2026-0947MEDIUM4.8Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet...
CVE-2026-0946MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet...
CVE-2026-0944MEDIUM5.3Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Group invite allows Forceful Browsing.This ...
CVE-2026-25475MEDIUM6.5OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allow...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now