2026 CVE Vulnerabilities

61,555 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8981LOW3.5The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability acros...
CVE-2026-5067CRITICAL9.8A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sendi...
CVE-2026-4986MEDIUM5.3The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before ...
CVE-2026-41539MEDIUM6.1A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remot...
CVE-2026-11572HIGH8.8Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to impro...
CVE-2026-9662HIGH8.1The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and in...
CVE-2026-9185HIGH7.5The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versi...
CVE-2026-8977MEDIUM6.4The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_ac...
CVE-2026-8940MEDIUM4.3The WP Meta Sort Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2026-8910MEDIUM6.1The WP Emoticon Rating plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2026-8909MEDIUM4.3The WpMobi plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.3....
CVE-2026-8907MEDIUM6.1The WP-Ultimate-Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1...
CVE-2026-8904MEDIUM4.3The FastPicker, an order picker and order management system (oms) for WooCommerce on steroids plugin for WordPress is vu...
CVE-2026-8902MEDIUM4.3The AJAX Report Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2026-8895MEDIUM6.4The kk blog card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blog-card' shortcod...
CVE-2026-8883MEDIUM6.4The Global Body Mass Index Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gbmical...
CVE-2026-8882MEDIUM6.4The WP ApplicantStack Jobs Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attri...
CVE-2026-8880MEDIUM6.4The RomanCart Ecommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blclass' attribute (a...
CVE-2026-8841MEDIUM6.4The Extra Settings for RocketChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rocketchat'...
CVE-2026-8499MEDIUM5.3The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in ver...
CVE-2026-7662MEDIUM6.4The ePaperFlip Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'publicationid' attri...
CVE-2026-41980MEDIUM5.5Permission control vulnerability in the file preview module. Impact: Successful exploitation of this vulnerability may a...
CVE-2026-41979MEDIUM5.5Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect i...
CVE-2026-41978MEDIUM4.4Permission control vulnerability in the clone module. Impact: Successful exploitation of this vulnerability may affect s...
CVE-2026-41975MEDIUM6.3Permission management vulnerability in the network management module. Impact: Successful exploitation of this vulnerabil...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now