2026 CVE Vulnerabilities

64,997 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-84899MEDIUM6.8The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it ...
CVE-2026-84898MEDIUM6.6The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include ...
CVE-2026-84896MEDIUM6.8The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before out...
CVE-2026-84221MEDIUM6.8The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allo...
CVE-2026-84022MEDIUM6.8The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before out...
CVE-2026-84021MEDIUM6.8The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTM...
CVE-2026-83544MEDIUM6.8The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute before outputting it...
CVE-2026-83543MEDIUM4.1The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, all...
CVE-2026-82846MEDIUM6.8The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting the...
CVE-2026-81424MEDIUM5.3The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is c...
CVE-2026-81423MEDIUM4.3The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redi...
CVE-2026-78149MEDIUM5.3The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its c...
CVE-2026-4361MEDIUM5The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. ...
CVE-2026-3853MEDIUM6.4The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the...
CVE-2026-19861MEDIUM4.7The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a...
CVE-2026-18843MEDIUM6.1The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no...
CVE-2026-15247MEDIUM5.4The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a se...
CVE-2026-14975MEDIUM6.5The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3...
CVE-2026-8625MEDIUM6.4The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-...
CVE-2026-8623MEDIUM6.4The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-...
CVE-2026-83628MEDIUM4.3The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 ...
CVE-2026-18404MEDIUM6.4The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consen...
CVE-2026-86137MEDIUM6.1In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro i...
CVE-2026-86100MEDIUM6.4Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload fro...
CVE-2026-52774MEDIUM6.1YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki's Bazar widget handler reflects the id GET para...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now