2026 CVE Vulnerabilities

64,617 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8866MEDIUM6.4The jQuery googleslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'googleslides' shortco...
CVE-2026-8847MEDIUM6.4The Dideo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dideo' shortcode in versio...
CVE-2026-8846MEDIUM6.4The Tuxquote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'TUXQUOTE' shortcode in versions ...
CVE-2026-8845MEDIUM6.4The Islamic Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'islamicDB-roqya' shortco...
CVE-2026-8844MEDIUM6.4The Responsive Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rspcheck' shortcode in v...
CVE-2026-8842MEDIUM6.4The Google+ Link Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gplusnamelink' shortcod...
CVE-2026-8837MEDIUM6.4The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'adi...
CVE-2026-8787HIGH8.8The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions up to,...
CVE-2026-8760CRITICAL9.8The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6...
CVE-2026-8708MEDIUM4.3The Genzel breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2026-8707MEDIUM6.1The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF in all versi...
CVE-2026-8703MEDIUM6.4The Endless Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all ver...
CVE-2026-8702MEDIUM6.4The GBI To Print plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the 'div' attribut...
CVE-2026-8701MEDIUM6.4The GNTT Post Title Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the `tit...
CVE-2026-8698MEDIUM6.4The Cryptocurrency Prijsvergelijking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version...
CVE-2026-8048MEDIUM6.4The My Email Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subject' shortcode att...
CVE-2026-8040MEDIUM6.4The faq shortocde plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute ...
CVE-2026-7614MEDIUM4.3The Old Posts Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2026-6268HIGH7.1The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customizer_n...
CVE-2026-9236MEDIUM4.3The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress is vulnerable to Cros...
CVE-2026-8450CRITICAL9.1HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string arg...
CVE-2026-6287MEDIUM5.4The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2026-49000HIGH7An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequa...
CVE-2026-9022MEDIUM6.4The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in...
CVE-2026-48999MEDIUM5.7Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now