2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8468HIGH8.2Allocation of Resources Without Limits or Throttling vulnerability in plug_project plug allows denial of service via unb...
CVE-2026-8295MEDIUM6.9An integer overflow vulnerability in the simdjson document-builder API allows incorrect buffer size calculations in "str...
CVE-2026-2347CRITICAL9.8Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Comme...
CVE-2026-6514HIGH7.5The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2...
CVE-2026-6512CRITICAL9.1The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1....
CVE-2026-6504MEDIUM6.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titl...
CVE-2026-6206MEDIUM5.3The MW WP Form plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.1.2 vi...
CVE-2026-6174MEDIUM6.4The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'more' parameter in all ver...
CVE-2026-6145MEDIUM5.3The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, an...
CVE-2026-6670MEDIUM6.5The Media Sync plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.9 via the ...
CVE-2026-6510CRITICAL9.8The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions ...
CVE-2026-6506HIGH8.8The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1....
CVE-2026-6271CRITICAL9.8The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7...
CVE-2026-6252MEDIUM6.4The Meta Field Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tagName' block attribute...
CVE-2026-6225MEDIUM6.5The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to time...
CVE-2026-5395HIGH8.2The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne...
CVE-2026-5365MEDIUM4.3The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 5.3.2...
CVE-2026-5193MEDIUM6.5The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privile...
CVE-2026-3892HIGH8.1The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion i...
CVE-2026-3718HIGH7.2The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'MWP-Key-Name' HTTP reques...
CVE-2026-3694MEDIUM6.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the ...
CVE-2026-8280MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.9.7, 18.10 before 18.10.6, and ...
CVE-2026-8181CRITICAL9.8The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulne...
CVE-2026-8144MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and...
CVE-2026-7481MEDIUM5.4GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.9.7, 18.10 before 18.10.6, and 18...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now