2026 CVE Vulnerabilities

57,035 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-21039MEDIUM6.9Improper access control in Settings prior to SMR Jul-2026 Release 1 allows local attackers to configure Theft protection...
CVE-2026-15332MEDIUM6.3A security flaw has been discovered in zhayujie CowAgent up to 2.1.0. The impacted element is an unknown function of the...
CVE-2026-15331MEDIUM5.4A vulnerability was identified in zhayujie CowAgent up to 2.1.0. The affected element is the function _add_url/_add_pack...
CVE-2026-15330HIGH7.3A vulnerability was determined in zhayujie CowAgent up to 2.1.1. Impacted is the function _build_image_content/_download...
CVE-2026-15302MEDIUM5.3The ARMember plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.0.27 via ...
CVE-2026-15301MEDIUM6.4The BuddyHolis TableSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ param...
CVE-2026-15300CRITICAL9.1The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in ve...
CVE-2026-15299MEDIUM6.4The Animation Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'weather_st...
CVE-2026-15298HIGH7.2The TelSender plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting in all versions up to, and including,...
CVE-2026-15297MEDIUM6.1The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerab...
CVE-2026-15296MEDIUM6.4The affiliate-toolkit – WP Affiliate Plugin with Amazon plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2026-15293HIGH8The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all versions up to, and ...
CVE-2026-15292MEDIUM6.4The Sudoku Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background' parameter in...
CVE-2026-15291HIGH7.5The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in all ...
CVE-2026-15290HIGH7.5The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2026-15289MEDIUM5.9The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to time-based SQL Injection via the ...
CVE-2026-15288HIGH7.5The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation...
CVE-2026-15287MEDIUM6.5The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based SQL Injection via the...
CVE-2026-15286MEDIUM4.3The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to unauthorized po...
CVE-2026-15285MEDIUM6.4The Plus Addons for Elementor plugin for WordPress was vulnerable to Authenticated (Contributor+) Stored Cross-Site Scri...
CVE-2026-15284MEDIUM6.4The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_page_id' p...
CVE-2026-15283MEDIUM4.4The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in al...
CVE-2026-15282CRITICAL9.8The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation...
CVE-2026-5069MEDIUM5.4The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in ve...
CVE-2026-54423HIGH8.2In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now