2026 CVE Vulnerabilities

66,307 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-96039HIGH7.2The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_name Parameter in all...
CVE-2026-94376MEDIUM6.4The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Stor...
CVE-2026-93899MEDIUM6.5The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to gene...
CVE-2026-93897MEDIUM6.4The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ...
CVE-2026-93477MEDIUM5.9Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a...
CVE-2026-93399CRITICAL9.1The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2...
CVE-2026-93303HIGH7.2The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cros...
CVE-2026-92829MEDIUM4.3The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass in all ve...
CVE-2026-92799MEDIUM5.3The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorization Bypass...
CVE-2026-92746MEDIUM6.4The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-92212MEDIUM6.1The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi...
CVE-2026-89055CRITICAL9.1The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, a...
CVE-2026-84281HIGH7.2The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'productTitle' in '_fpd...
CVE-2026-84279HIGH7.2The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'output_format' par...
CVE-2026-83591HIGH7.2The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment ...
CVE-2026-78397MEDIUM4The Link Library WordPress plugin before 7.9.6 does not validate the destination of a user-supplied URL before falling b...
CVE-2026-78394MEDIUM4.1The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a gen...
CVE-2026-78393MEDIUM6.1The Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the ad...
CVE-2026-75553LOW2.4Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an att...
CVE-2026-62062HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This is...
CVE-2026-19775MEDIUM4.3The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is vulnerable to authorizat...
CVE-2026-14281CRITICAL9.8The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulne...
CVE-2026-97721LOW2.7A weakness has been identified in Sanluan PublicCMS up to 6.202506.e. This vulnerability affects the function CmsContent...
CVE-2026-97818HIGH8.6phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.
CVE-2026-97764LOW3.7django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now