2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6709MEDIUM4.3The Coinbase Commerce for Contact Form 7 plugin for WordPress is vulnerable to Missing Authorization in versions up to a...
CVE-2026-6708MEDIUM5.3The HEL Online Classroom: AI-powered Online Classrooms plugin for WordPress is vulnerable to Missing Authorization in al...
CVE-2026-6690HIGH7.2The LifePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'n' parameter of the lp_update_m...
CVE-2026-6663MEDIUM4.8The GWD Connect plugin for WordPress is vulnerable to missing authorization to limited code execution in all versions up...
CVE-2026-6402MEDIUM6.5webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving o...
CVE-2026-6256MEDIUM6.4The Credits Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the ...
CVE-2026-6247MEDIUM6.4The scratchblocks for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' attribute o...
CVE-2026-6237MEDIUM6.4The Quick Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' attribute of the 'qtbl...
CVE-2026-5715MEDIUM6.4The Voyage Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the 'post...
CVE-2026-5693MEDIUM5.3The Smart Appointment & Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
CVE-2026-5340MEDIUM6.4The Fancy Image Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `fancy-img-show`...
CVE-2026-5028MEDIUM6.5The Eight Day Week Print Workflow plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'title' p...
CVE-2026-4920MEDIUM6.4The Next Date plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribute in...
CVE-2026-4859MEDIUM6.4The SP Blog Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'design' attribute of the...
CVE-2026-4663——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-39608. Reason: This candidate is a ...
CVE-2026-4301MEDIUM4.3The Rate Star Review Vote - AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Missing Authorizatio...
CVE-2026-3604MEDIUM4.9The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `_kcseo_ativ...
CVE-2026-39432HIGH8.2Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Securi...
CVE-2026-2993HIGH7.5The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection in versions up to, and ...
CVE-2026-2300MEDIUM6.4The BJ Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `filter_images()` function in...
CVE-2026-35227HIGH8.2An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a...
CVE-2026-1681MEDIUM6.1Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursi...
CVE-2026-1185HIGH8.8A configuration file on the local file system had improper input validation which could allow code execution and potenti...
CVE-2026-0804HIGH7.3An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to pote...
CVE-2026-0802HIGH7.3An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now