2026 CVE Vulnerabilities
60,340 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8039 | MEDIUM | 6.4 | 0.2% | Jun 18, 2026 | The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attr... |
| CVE-2026-50643 | MEDIUM | 5.1 | 0.1% | Jun 18, 2026 | 8cc is vulnerable to an Out‑of‑Bounds Read due to improper handling of #line directives and GNU linemarkers. The compile... |
| CVE-2026-2021 | MEDIUM | 6.4 | 0.2% | Jun 18, 2026 | The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortc... |
| CVE-2026-9815 | MEDIUM | 6.5 | 0.2% | Jun 18, 2026 | The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenti... |
| CVE-2026-55746 | HIGH | 7.6 | 0.2% | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage... |
| CVE-2026-55745 | MEDIUM | 5.4 | 0.1% | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage ... |
| CVE-2026-55744 | HIGH | 8.6 | 0.2% | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage ... |
| CVE-2026-55742 | CRITICAL | 9.6 | 0.2% | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights ... |
| CVE-2026-55741 | HIGH | 8.8 | 0.2% | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configu... |
| CVE-2026-28573 | MEDIUM | 5.5 | 0.1% | Jun 18, 2026 | In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could l... |
| CVE-2026-12137 | MEDIUM | 6.1 | 0.2% | Jun 18, 2026 | The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is... |
| CVE-2026-12136 | MEDIUM | 6.4 | 0.2% | Jun 18, 2026 | The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysb... |
| CVE-2026-12111 | MEDIUM | 4.3 | 0.3% | Jun 18, 2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to,... |
| CVE-2026-12102 | LOW | 2.7 | 0.3% | Jun 18, 2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre... |
| CVE-2026-12098 | MEDIUM | 6.4 | 0.2% | Jun 18, 2026 | The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed... |
| CVE-2026-11395 | HIGH | 7.2 | 0.2% | Jun 18, 2026 | The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin... |
| CVE-2026-9860 | HIGH | 8.8 | 0.6% | Jun 18, 2026 | The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all ver... |
| CVE-2026-9199 | MEDIUM | 4.3 | 0.2% | Jun 18, 2026 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl... |
| CVE-2026-55740 | CRITICAL | 9.8 | 0.4% | Jun 18, 2026 | Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthe... |
| CVE-2026-12120 | MEDIUM | 5.3 | 0.3% | Jun 18, 2026 | The FireBox Popups – Increase Sales and Grow Your Email List plugin for WordPress is vulnerable to Sensitive Information... |
| CVE-2026-12093 | MEDIUM | 5.3 | 0.4% | Jun 18, 2026 | The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4... |
| CVE-2026-11784 | MEDIUM | 4.3 | 0.2% | Jun 18, 2026 | The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vuln... |
| CVE-2026-11777 | MEDIUM | 4.9 | 0.4% | Jun 18, 2026 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic... |
| CVE-2026-11776 | MEDIUM | 4.9 | 0.4% | Jun 18, 2026 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic... |
| CVE-2026-11402 | MEDIUM | 6.4 | 0.2% | Jun 18, 2026 | The Services Section Block – Showcase Service Details in Grid or Columns plugin for WordPress is vulnerable to Stored Cr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now