2026 CVE Vulnerabilities

57,056 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-31982HIGH7.1An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of...
CVE-2026-31981MEDIUM4.8A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation ...
CVE-2026-15000HIGH7.2The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mailchimp...
CVE-2026-14343MEDIUM6.4The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after...
CVE-2026-14342MEDIUM4.9The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to...
CVE-2026-14245CRITICAL9.8The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass...
CVE-2026-13771MEDIUM6.4The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Short...
CVE-2026-13450MEDIUM5.3The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ...
CVE-2026-13334MEDIUM6.1The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stag' parameter in all v...
CVE-2026-13253MEDIUM6.4The Ultimate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'moreResultsText' block attr...
CVE-2026-13080MEDIUM6.6The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Lo...
CVE-2026-13011MEDIUM6.5The ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin for WordPress is vulner...
CVE-2026-12418MEDIUM5.3The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...
CVE-2026-12406MEDIUM5.3The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...
CVE-2026-12170MEDIUM6.4The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v...
CVE-2026-11359MEDIUM4.3The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerab...
CVE-2026-47840CRITICAL9.3A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate fro...
CVE-2026-47831HIGH7.7Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-...
CVE-2026-47830HIGH8.8Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege ...
CVE-2026-47829HIGH7.8Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-s...
CVE-2026-47828HIGH8.8During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new ...
CVE-2026-47826CRITICAL9.1The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfi...
CVE-2026-12517MEDIUM5.3The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performe...
CVE-2026-12516MEDIUM5.3The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performe...
CVE-2026-12270MEDIUM6.5The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belong...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now