2026 CVE Vulnerabilities

59,305 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-27435MEDIUM5.3Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Securit...
CVE-2026-13454MEDIUM6.5The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in a...
CVE-2026-12754MEDIUM6.1The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '...
CVE-2026-56016MEDIUM5.9CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The gene...
CVE-2026-50043HIGH8.6Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge MB-...
CVE-2026-13733MEDIUM6.4The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attri...
CVE-2026-12732MEDIUM6.4The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_wrapper_form' shortcode ...
CVE-2026-12577HIGH8.7DVP80ES3 with Improperly Implemented Security Check for Standard vulnerability.
CVE-2026-12576HIGH7.5DVP80ES3 with Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability.
CVE-2026-12575HIGH7.5DVP80ES3 with  Improper Resource Shutdown or Release vulnerability.
CVE-2026-12435MEDIUM4.3The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to authorization bypass in a...
CVE-2026-12408MEDIUM4.3The Slim SEO – A Fast & Automated SEO Plugin For WordPress plugin for WordPress is vulnerable to Unauthorized Private Co...
CVE-2026-12224HIGH8.8The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all ve...
CVE-2026-12158HIGH8.8The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery ...
CVE-2026-11387CRITICAL9.8The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera...
CVE-2026-10540MEDIUM5.6The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offl...
CVE-2026-10539CRITICAL9.5A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain con...
CVE-2026-10538HIGH8.9Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowe...
CVE-2026-10096MEDIUM4.3The Qi Blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includin...
CVE-2026-1239HIGH7.5The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access...
CVE-2026-14193HIGH7.5DVP80ES300T with Improper Validation of Array Index Vulnerability
CVE-2026-12579HIGH7.4AS228T with Authentication Bypass Vulnerability
CVE-2026-11887MEDIUM4.3The Salon Booking System WordPress plugin before 10.30.20 does not have proper authorisation checks on one of its AJAX ...
CVE-2026-11883HIGH7.2The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-factor authent...
CVE-2026-11880LOW3.1The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription canc...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now