2026 CVE Vulnerabilities

64,469 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-9015MEDIUM4.3The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl...
CVE-2026-8689MEDIUM4.3The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Missing Authorization in a...
CVE-2026-7526MEDIUM4.3The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi...
CVE-2026-7048MEDIUM6.5The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based blind SQL In...
CVE-2026-6937MEDIUM5.3The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Mis...
CVE-2026-6226HIGH8.8The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions ...
CVE-2026-4408CRITICAL9.8A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain con...
CVE-2026-4334MEDIUM6.4The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headline' parameter in th...
CVE-2026-9806MEDIUM6.3A stored cross-site scripting (XSS) vulnerability exists in the notification panel of CTI Transmute in versions prior to...
CVE-2026-9618MEDIUM4.3The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) plugin ...
CVE-2026-9227HIGH8.8The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and i...
CVE-2026-8682MEDIUM4.3The 3D Viewer – 3D Model Viewer – Augmented Reality – Virtual Try On plugin for WordPress is vulnerable to authorization...
CVE-2026-7862HIGH8.6The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not properly restrict access to its refund request...
CVE-2026-7797HIGH7.5The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to tim...
CVE-2026-7660MEDIUM6.1The Easy Updates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter ...
CVE-2026-7651MEDIUM5.3The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom U...
CVE-2026-7634HIGH7.2The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'User-Agent' header in ...
CVE-2026-7621MEDIUM4.3The SMTP2GO for WordPress – Email Made Easy plugin for WordPress is vulnerable to unauthorized access in all versions up...
CVE-2026-7552MEDIUM5.3The Geo Mashup plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.13.19....
CVE-2026-7052HIGH7.2The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scr...
CVE-2026-6455HIGH8.1The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary F...
CVE-2026-6427MEDIUM6.4The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,...
CVE-2026-44604HIGH7A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive ...
CVE-2026-9803MEDIUM5.3A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vuln...
CVE-2026-9802MEDIUM6.8A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now