2026 CVE Vulnerabilities

61,772 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-9730MEDIUM4.3The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to...
CVE-2026-9723MEDIUM4.3The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2026-9722MEDIUM4.3The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1....
CVE-2026-9599MEDIUM4.3The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2026-9234MEDIUM4.3The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and inc...
CVE-2026-8885MEDIUM6.4The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'callo...
CVE-2026-8422MEDIUM4.3The Remove meta boxes per user role plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up ...
CVE-2026-4081MEDIUM6.4The ZeM STL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [zemstl] shortcode in all versions...
CVE-2026-4080MEDIUM6.4The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_to_cart' shortcode in all v...
CVE-2026-4071MEDIUM4.3The BirdSeed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2....
CVE-2026-3620MEDIUM4.4The Word Replacer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'replacement' parameter in a...
CVE-2026-3514HIGH7.5In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the improper handling of UR...
CVE-2026-2425MEDIUM6.1The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_domain' par...
CVE-2026-2382MEDIUM6.4The FPW Category Thumbnails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of ...
CVE-2026-1784HIGH8.8The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found...
CVE-2026-1451MEDIUM6.1The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'a' parameter in versions up to...
CVE-2026-1450MEDIUM6.1The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in versions up...
CVE-2026-8293HIGH7.5The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its ...
CVE-2026-8206CRITICAL9.8The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalati...
CVE-2026-3198MEDIUM6.5MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API 'l...
CVE-2026-10583MEDIUM4.7A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. Affected by this issue is the functi...
CVE-2026-10581MEDIUM6.3A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decode of the file /plus/...
CVE-2026-3871MEDIUM6.5A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through ...
CVE-2026-3870MEDIUM6.5A buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.1...
CVE-2026-3722MEDIUM6.4The Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) plugin for WordPress...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now