57,566 vulnerabilities published in 2026
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that
The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on seve
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer reco
The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before o
The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, al
Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP
A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to injec
A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta allows a low-privileged authenticated user (Autho
A stored cross-site scripting (XSS) vulnerability in fastschema through v0.15.1 allows a low-privileged authenticated us
ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated custome
Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previo
HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and out
SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashb
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7
A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write
A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows any registered member to inject persisten
A stored cross-site scripting vulnerability in HortusFox 5.9 allows authenticated workspace members to inject persistent
Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulne
is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass.
TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a worksp
Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authentica
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized
Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request
TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a u
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction w
tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows
The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts i
The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it
The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTM
Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-pri
Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm
Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriv
Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload th
Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team'
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js
Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearc
A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authentic
VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly spec
The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentica
The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or non
GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keywor
basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager
Email Management API Bypasses ManageCredentials Feature Restrictions
Gitea LFS Deploy-Key Privilege Escalation
phpList before 3.7.0-RC5 fail to enforce CSRF token validation on the bounce rule deletion endpoint (bouncerules.php / b
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-o
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Access
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a deni
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started