2026 CVE Vulnerabilities

60,195 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-9612MEDIUM5.3The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure i...
CVE-2026-9184MEDIUM4.3The 24liveblog - live blog tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
CVE-2026-9183MEDIUM4.3The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up t...
CVE-2026-9179HIGH7.5The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/...
CVE-2026-9178HIGH7.5The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, ...
CVE-2026-9175MEDIUM5.3The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorizati...
CVE-2026-9172MEDIUM5.3The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modifi...
CVE-2026-8905MEDIUM6.1The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2026-8896MEDIUM6.4The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribut...
CVE-2026-8865MEDIUM6.4The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '...
CVE-2026-8705HIGH7.5The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of th...
CVE-2026-8690MEDIUM5.3The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions...
CVE-2026-8688MEDIUM4.3The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu...
CVE-2026-8628MEDIUM6.1The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all ver...
CVE-2026-8622MEDIUM6.1The Image Sizes on Demand plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Server Varia...
CVE-2026-8617MEDIUM5.3The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, a...
CVE-2026-8614MEDIUM4.3The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check a...
CVE-2026-7617MEDIUM5.3The Secufor_OAuth plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.7....
CVE-2026-6292MEDIUM4.3The MP Customize Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up t...
CVE-2026-4297HIGH8.8The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and...
CVE-2026-13006HIGH7ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.3...
CVE-2026-12417CRITICAL9.8The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leadi...
CVE-2026-12416CRITICAL9.8The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, a...
CVE-2026-12100HIGH7.2The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ...
CVE-2026-12095HIGH7.2The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now