2026 CVE Vulnerabilities

65,063 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-84780MEDIUM5.3Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions.
CVE-2026-84775MEDIUM5.3Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions.
CVE-2026-84772MEDIUM5.5Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions.
CVE-2026-84771MEDIUM5.3Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions.
CVE-2026-84760MEDIUM5.3Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.
CVE-2026-84217MEDIUM5.4Missing Authorization vulnerability in Mamunur Rashid Classified Listing classified-listing allows Accessing Functionali...
CVE-2026-83562MEDIUM6.5Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions.
CVE-2026-82223MEDIUM6.5Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions.
CVE-2026-66652MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forgery. This issue ...
CVE-2026-32773MEDIUM6.1There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generat...
CVE-2026-84175MEDIUM5.3In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (Web of Things) ThingModels over HTTP from URLs...
CVE-2026-53683MEDIUM4.3reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location...
CVE-2026-3850MEDIUM6.4The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of the `et_pb...
CVE-2026-82182MEDIUM4.1The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied list of iden...
CVE-2026-81583MEDIUM5.4The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site sig...
CVE-2026-81432MEDIUM4.3The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does not have CSRF protection on some of its AJAX action...
CVE-2026-81428MEDIUM6.5The WC Vendors WordPress plugin before 2.7.2.1 does not verify ownership or the object type of user-supplied IDs when s...
CVE-2026-81427MEDIUM4.3The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order shipment st...
CVE-2026-81426MEDIUM4.3The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its front-end order shipment st...
CVE-2026-81199MEDIUM5.3The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before retu...
CVE-2026-81197MEDIUM5.3The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not restrict access to a REST route that lists...
CVE-2026-81195MEDIUM5.3The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before retu...
CVE-2026-81194MEDIUM4.3The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization when retriev...
CVE-2026-79621MEDIUM4.3The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user can store b...
CVE-2026-78151MEDIUM5.3The FormLayer WordPress plugin before 1.0.9 does not perform any authorization check before returning a form's full stor...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now