2026 CVE Vulnerabilities

44,067 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-8996MEDIUM6.5The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve...
CVE-2026-7558MEDIUM5.3The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access...
CVE-2026-6910MEDIUM6.4The Bookero.pl – system rezerwacji online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `boo...
CVE-2026-4653MEDIUM6.4The Block, Suspend, Report for BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lin...
CVE-2026-31983MEDIUM6.9A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attac...
CVE-2026-31981MEDIUM4.8A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation ...
CVE-2026-14343MEDIUM6.4The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after...
CVE-2026-14342MEDIUM4.9The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to...
CVE-2026-13771MEDIUM6.4The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Short...
CVE-2026-13450MEDIUM5.3The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ...
CVE-2026-13334MEDIUM6.1The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stag' parameter in all v...
CVE-2026-13253MEDIUM6.4The Ultimate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'moreResultsText' block attr...
CVE-2026-13080MEDIUM6.6The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Lo...
CVE-2026-13011MEDIUM6.5The ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin for WordPress is vulner...
CVE-2026-12418MEDIUM5.3The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...
CVE-2026-12406MEDIUM5.3The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...
CVE-2026-12170MEDIUM6.4The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v...
CVE-2026-11359MEDIUM4.3The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerab...
CVE-2026-12517MEDIUM5.3The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performe...
CVE-2026-12516MEDIUM5.3The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performe...
CVE-2026-12270MEDIUM6.5The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belong...
CVE-2026-11875MEDIUM5.3The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session co...
CVE-2026-11869MEDIUM5.3The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-proces...
CVE-2026-15138MEDIUM6.3A security vulnerability has been detected in tumf mcp-text-editor up to 1.0.2. This issue affects the function _validat...
CVE-2026-47646MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now