2026 CVE Vulnerabilities

57,119 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-57350HIGH7.1Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions.
CVE-2026-57349HIGH7.1Unauthenticated Cross Site Scripting (XSS) in WPeMatico RSS Feed Fetcher <= 2.8.17 versions.
CVE-2026-57348HIGH7.2Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions.
CVE-2026-57347MEDIUM6.5Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.
CVE-2026-57345HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 versions.
CVE-2026-57344HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions.
CVE-2026-57343HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Real Estate 7 <= 3.5.9 versions.
CVE-2026-57342MEDIUM6.5Subscriber Cross Site Scripting (XSS) in ShortPixel Adaptive Images <= 3.11.3 versions.
CVE-2026-56037HIGH8.8Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Th...
CVE-2026-49779MEDIUM6.5Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal. This issue affect...
CVE-2026-42382HIGH8.1Unauthenticated Local File Inclusion in Audrey <= 1.5 versions.
CVE-2026-39448HIGH7.5Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.
CVE-2026-27436CRITICAL9.1Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
CVE-2026-27433MEDIUM6.5Unauthenticated Broken Access Control in Motors <= 5.6.80 versions.
CVE-2026-27430HIGH7.1Unauthenticated Cross Site Scripting (XSS) in TheFox <= 3.9.76 versions.
CVE-2026-27426HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Automotive Car Dealership Business <= 13.3.3 versions.
CVE-2026-27425HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Automotive Listings <= 18.6 versions.
CVE-2026-27419CRITICAL9.9Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.
CVE-2026-27414HIGH8.8Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.
CVE-2026-27412HIGH8.1Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions.
CVE-2026-27408HIGH7.1Unauthenticated Cross Site Scripting (XSS) in NativeChurch <= 4.8.8.2 versions.
CVE-2026-27404HIGH7.1Unauthenticated Cross Site Scripting (XSS) in LMS <= 9.7 versions.
CVE-2026-27402HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPress <= 5.2 versions.
CVE-2026-27060HIGH8.8Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember Premium allows Object Injection. This is...
CVE-2026-14449MEDIUM6.4u5CMS through v12.8.8 is vulnerable to reflected XSS via the ‘thanks’ parameter in multiple form components

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now