2026 CVE Vulnerabilities
44,067 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8996 | MEDIUM | 6.5 | 0.3% | Jul 9, 2026 | The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve... |
| CVE-2026-7558 | MEDIUM | 5.3 | 0.3% | Jul 9, 2026 | The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access... |
| CVE-2026-6910 | MEDIUM | 6.4 | 0.2% | Jul 9, 2026 | The Bookero.pl – system rezerwacji online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `boo... |
| CVE-2026-4653 | MEDIUM | 6.4 | 0.2% | Jul 9, 2026 | The Block, Suspend, Report for BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lin... |
| CVE-2026-31983 | MEDIUM | 6.9 | 0.2% | Jul 9, 2026 | A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attac... |
| CVE-2026-31981 | MEDIUM | 4.8 | 0.1% | Jul 9, 2026 | A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation ... |
| CVE-2026-14343 | MEDIUM | 6.4 | 0.2% | Jul 9, 2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after... |
| CVE-2026-14342 | MEDIUM | 4.9 | 0.3% | Jul 9, 2026 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to... |
| CVE-2026-13771 | MEDIUM | 6.4 | 0.2% | Jul 9, 2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Short... |
| CVE-2026-13450 | MEDIUM | 5.3 | 0.4% | Jul 9, 2026 | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ... |
| CVE-2026-13334 | MEDIUM | 6.1 | 0.2% | Jul 9, 2026 | The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stag' parameter in all v... |
| CVE-2026-13253 | MEDIUM | 6.4 | 0.2% | Jul 9, 2026 | The Ultimate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'moreResultsText' block attr... |
| CVE-2026-13080 | MEDIUM | 6.6 | 0.7% | Jul 9, 2026 | The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Lo... |
| CVE-2026-13011 | MEDIUM | 6.5 | 0.3% | Jul 9, 2026 | The ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin for WordPress is vulner... |
| CVE-2026-12418 | MEDIUM | 5.3 | 0.2% | Jul 9, 2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP... |
| CVE-2026-12406 | MEDIUM | 5.3 | 0.3% | Jul 9, 2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP... |
| CVE-2026-12170 | MEDIUM | 6.4 | 0.3% | Jul 9, 2026 | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v... |
| CVE-2026-11359 | MEDIUM | 4.3 | 0.2% | Jul 9, 2026 | The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerab... |
| CVE-2026-12517 | MEDIUM | 5.3 | 0.1% | Jul 9, 2026 | The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performe... |
| CVE-2026-12516 | MEDIUM | 5.3 | 0.1% | Jul 9, 2026 | The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performe... |
| CVE-2026-12270 | MEDIUM | 6.5 | 0.1% | Jul 9, 2026 | The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belong... |
| CVE-2026-11875 | MEDIUM | 5.3 | 0.1% | Jul 9, 2026 | The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session co... |
| CVE-2026-11869 | MEDIUM | 5.3 | 0.1% | Jul 9, 2026 | The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-proces... |
| CVE-2026-15138 | MEDIUM | 6.3 | 0.3% | Jul 9, 2026 | A security vulnerability has been detected in tumf mcp-text-editor up to 1.0.2. This issue affects the function _validat... |
| CVE-2026-47646 | MEDIUM | 6.1 | 0.5% | Jul 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now