2026 CVE Vulnerabilities

57,138 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-57343HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Real Estate 7 <= 3.5.9 versions.
CVE-2026-57342MEDIUM6.5Subscriber Cross Site Scripting (XSS) in ShortPixel Adaptive Images <= 3.11.3 versions.
CVE-2026-56037HIGH8.8Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Th...
CVE-2026-49779MEDIUM6.5Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal. This issue affect...
CVE-2026-42382HIGH8.1Unauthenticated Local File Inclusion in Audrey <= 1.5 versions.
CVE-2026-39448HIGH7.5Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.
CVE-2026-27436CRITICAL9.1Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
CVE-2026-27433MEDIUM6.5Unauthenticated Broken Access Control in Motors <= 5.6.80 versions.
CVE-2026-27430HIGH7.1Unauthenticated Cross Site Scripting (XSS) in TheFox <= 3.9.76 versions.
CVE-2026-27426HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Automotive Car Dealership Business <= 13.3.3 versions.
CVE-2026-27425HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Automotive Listings <= 18.6 versions.
CVE-2026-27419CRITICAL9.9Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.
CVE-2026-27414HIGH8.8Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.
CVE-2026-27412HIGH8.1Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions.
CVE-2026-27408HIGH7.1Unauthenticated Cross Site Scripting (XSS) in NativeChurch <= 4.8.8.2 versions.
CVE-2026-27404HIGH7.1Unauthenticated Cross Site Scripting (XSS) in LMS <= 9.7 versions.
CVE-2026-27402HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPress <= 5.2 versions.
CVE-2026-27060HIGH8.8Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember Premium allows Object Injection. This is...
CVE-2026-14449MEDIUM6.4u5CMS through v12.8.8 is vulnerable to reflected XSS via the ‘thanks’ parameter in multiple form components
CVE-2026-11946HIGH7.5An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The en...
CVE-2026-54431MEDIUM5.1In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header conta...
CVE-2026-54430MEDIUM5.1liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() function. The AWS ALB verif...
CVE-2026-9834HIGH7.2The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to OS Com...
CVE-2026-9188MEDIUM5.3The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Dire...
CVE-2026-9145MEDIUM6.5The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now