2026 CVE Vulnerabilities

59,993 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-9233MEDIUM4.3The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass...
CVE-2026-3462MEDIUM6.5The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks...
CVE-2026-13295MEDIUM6.4The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Paramet...
CVE-2026-12471MEDIUM4.3The Spexo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the activate_plu...
CVE-2026-12432MEDIUM5.3The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8....
CVE-2026-12399MEDIUM4.4The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-11987MEDIUM4.3The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPr...
CVE-2026-11783MEDIUM6.4The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPr...
CVE-2026-11773MEDIUM4.3The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypas...
CVE-2026-11597MEDIUM6.4The Surbma | Infusionsoft Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'infusions...
CVE-2026-11364MEDIUM4.3The Product Specifications for WooCommerce plugin for WordPress is vulnerable to unauthorized modification, creation, an...
CVE-2026-9677MEDIUM4.8The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl se...
CVE-2026-13245MEDIUM6.1The MaxButtons – Create buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view' para...
CVE-2026-12404MEDIUM5.3The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all ve...
CVE-2026-10820HIGH8.1The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl...
CVE-2026-12415CRITICAL9.8The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on th...
CVE-2026-13422MEDIUM4.3The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to ...
CVE-2026-13335MEDIUM6.4The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point...
CVE-2026-13333MEDIUM6.5The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection ...
CVE-2026-13331MEDIUM6.5The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection ...
CVE-2026-11356MEDIUM4.4The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'menu_t...
CVE-2026-56414HIGH8.6A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arb...
CVE-2026-55975HIGH8.6A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to t...
CVE-2026-33560HIGH8.8The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which a...
CVE-2026-31928CRITICAL9.8The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now