2026 CVE Vulnerabilities

67,245 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-93836HIGH7.2The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' ...
CVE-2026-93778HIGH7.2The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (import...
CVE-2026-92969HIGH8.1The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Local File Inclusion in a...
CVE-2026-92235HIGH8.1The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, an...
CVE-2026-91092MEDIUM4.3The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5....
CVE-2026-87082HIGH7.5Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in...
CVE-2026-87081HIGH7.5Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label...
CVE-2026-87080CRITICAL9.1Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never...
CVE-2026-87079HIGH7.5Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long...
CVE-2026-87078CRITICAL9.1Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_pu...
CVE-2026-7622MEDIUM4.3The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.1. This is ...
CVE-2026-74766HIGH8.4Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that r...
CVE-2026-74765MEDIUM6.5Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumula...
CVE-2026-6922HIGH7.1The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Authorization in all ve...
CVE-2026-4123MEDIUM4.3The RW Elephant Rental Inventory plugin for WordPress is vulnerable to Missing Authorization in all versions up to and i...
CVE-2026-1645MEDIUM4.4The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_currency' parameter and the...
CVE-2026-18439MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere...
CVE-2026-18345MEDIUM4.3The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2026-16778MEDIUM6.4The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
CVE-2026-12995MEDIUM4.3The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, ...
CVE-2026-94504HIGH7.2Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy su...
CVE-2026-92438HIGH8.8The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submis...
CVE-2026-91827HIGH7.5The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when a...
CVE-2026-89412HIGH7.2The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross...
CVE-2026-93655MEDIUM6.1The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill' param...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now