2026 CVE Vulnerabilities
60,195 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9612 | MEDIUM | 5.3 | 0.3% | Jun 24, 2026 | The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure i... |
| CVE-2026-9184 | MEDIUM | 4.3 | 0.2% | Jun 24, 2026 | The 24liveblog - live blog tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing... |
| CVE-2026-9183 | MEDIUM | 4.3 | 0.2% | Jun 24, 2026 | The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up t... |
| CVE-2026-9179 | HIGH | 7.5 | 0.4% | Jun 24, 2026 | The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/... |
| CVE-2026-9178 | HIGH | 7.5 | 0.3% | Jun 24, 2026 | The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, ... |
| CVE-2026-9175 | MEDIUM | 5.3 | 0.3% | Jun 24, 2026 | The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorizati... |
| CVE-2026-9172 | MEDIUM | 5.3 | 0.2% | Jun 24, 2026 | The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modifi... |
| CVE-2026-8905 | MEDIUM | 6.1 | 0.1% | Jun 24, 2026 | The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2026-8896 | MEDIUM | 6.4 | 0.2% | Jun 24, 2026 | The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribut... |
| CVE-2026-8865 | MEDIUM | 6.4 | 0.2% | Jun 24, 2026 | The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '... |
| CVE-2026-8705 | HIGH | 7.5 | 0.5% | Jun 24, 2026 | The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of th... |
| CVE-2026-8690 | MEDIUM | 5.3 | 0.3% | Jun 24, 2026 | The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions... |
| CVE-2026-8688 | MEDIUM | 4.3 | 0.2% | Jun 24, 2026 | The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu... |
| CVE-2026-8628 | MEDIUM | 6.1 | 0.2% | Jun 24, 2026 | The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all ver... |
| CVE-2026-8622 | MEDIUM | 6.1 | 0.2% | Jun 24, 2026 | The Image Sizes on Demand plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Server Varia... |
| CVE-2026-8617 | MEDIUM | 5.3 | 0.2% | Jun 24, 2026 | The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, a... |
| CVE-2026-8614 | MEDIUM | 4.3 | 0.2% | Jun 24, 2026 | The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check a... |
| CVE-2026-7617 | MEDIUM | 5.3 | 0.3% | Jun 24, 2026 | The Secufor_OAuth plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.7.... |
| CVE-2026-6292 | MEDIUM | 4.3 | 0.2% | Jun 24, 2026 | The MP Customize Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up t... |
| CVE-2026-4297 | HIGH | 8.8 | 0.5% | Jun 24, 2026 | The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and... |
| CVE-2026-13006 | HIGH | 7 | 0.1% | Jun 24, 2026 | ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.3... |
| CVE-2026-12417 | CRITICAL | 9.8 | 0.5% | Jun 24, 2026 | The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leadi... |
| CVE-2026-12416 | CRITICAL | 9.8 | 0.4% | Jun 24, 2026 | The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, a... |
| CVE-2026-12100 | HIGH | 7.2 | 0.3% | Jun 24, 2026 | The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ... |
| CVE-2026-12095 | HIGH | 7.2 | 0.3% | Jun 24, 2026 | The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now