2026 CVE Vulnerabilities

44,967 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-57690MEDIUM4.3Unauthenticated Cross Site Request Forgery (CSRF) in Werkstatt <= 4.7.2 versions.
CVE-2026-57689MEDIUM4.3Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions.
CVE-2026-57685MEDIUM4.3Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 versions.
CVE-2026-57684MEDIUM6.5Contributor Cross Site Scripting (XSS) in TheFox <= 3.9.70 versions.
CVE-2026-57681MEDIUM6.4Subscriber Server Side Request Forgery (SSRF) in GeoDirectory <= 2.8.161 versions.
CVE-2026-57680MEDIUM6.5Unauthenticated Insecure Direct Object References (IDOR) in Kirki <= 6.0.11 versions.
CVE-2026-57669MEDIUM6.5Subscriber Broken Access Control in Advanced Contact form 7 DB <= 2.0.9 versions.
CVE-2026-57355MEDIUM6.5Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.
CVE-2026-57354MEDIUM6.5Subscriber Cross Site Scripting (XSS) in JetReviews <= 3.0.0.1 versions.
CVE-2026-57353MEDIUM6.5Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions.
CVE-2026-57352MEDIUM4.8Unauthenticated Broken Authentication in ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0 vers...
CVE-2026-57347MEDIUM6.5Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.
CVE-2026-57342MEDIUM6.5Subscriber Cross Site Scripting (XSS) in ShortPixel Adaptive Images <= 3.11.3 versions.
CVE-2026-49779MEDIUM6.5Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal. This issue affect...
CVE-2026-27433MEDIUM6.5Unauthenticated Broken Access Control in Motors <= 5.6.80 versions.
CVE-2026-14449MEDIUM6.4u5CMS through v12.8.8 is vulnerable to reflected XSS via the ‘thanks’ parameter in multiple form components
CVE-2026-54431MEDIUM5.1In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header conta...
CVE-2026-54430MEDIUM5.1liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() function. The AWS ALB verif...
CVE-2026-9188MEDIUM5.3The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Dire...
CVE-2026-9145MEDIUM6.5The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via ...
CVE-2026-8482MEDIUM4.3A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , ...
CVE-2026-14029MEDIUM6.5The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection ...
CVE-2026-13459MEDIUM5.3The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versi...
CVE-2026-13252MEDIUM6.4The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is...
CVE-2026-12657MEDIUM5.3The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direc...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now