2026 CVE Vulnerabilities

60,340 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8039MEDIUM6.4The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attr...
CVE-2026-50643MEDIUM5.18cc is vulnerable to an Out‑of‑Bounds Read due to improper handling of #line directives and GNU linemarkers. The compile...
CVE-2026-2021MEDIUM6.4The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortc...
CVE-2026-9815MEDIUM6.5The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenti...
CVE-2026-55746HIGH7.6Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage...
CVE-2026-55745MEDIUM5.4Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage ...
CVE-2026-55744HIGH8.6Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage ...
CVE-2026-55742CRITICAL9.6Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights ...
CVE-2026-55741HIGH8.8Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configu...
CVE-2026-28573MEDIUM5.5In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could l...
CVE-2026-12137MEDIUM6.1The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is...
CVE-2026-12136MEDIUM6.4The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysb...
CVE-2026-12111MEDIUM4.3The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to,...
CVE-2026-12102LOW2.7The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre...
CVE-2026-12098MEDIUM6.4The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed...
CVE-2026-11395HIGH7.2The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin...
CVE-2026-9860HIGH8.8The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all ver...
CVE-2026-9199MEDIUM4.3The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl...
CVE-2026-55740CRITICAL9.8Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthe...
CVE-2026-12120MEDIUM5.3The FireBox Popups – Increase Sales and Grow Your Email List plugin for WordPress is vulnerable to Sensitive Information...
CVE-2026-12093MEDIUM5.3The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4...
CVE-2026-11784MEDIUM4.3The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vuln...
CVE-2026-11777MEDIUM4.9The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic...
CVE-2026-11776MEDIUM4.9The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic...
CVE-2026-11402MEDIUM6.4The Services Section Block – Showcase Service Details in Grid or Columns plugin for WordPress is vulnerable to Stored Cr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now