2026 CVE Vulnerabilities

44,991 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-11570MEDIUM4.2The User Submitted Posts WordPress plugin before 20260608 does not escape a submitted value before outputting it in an ...
CVE-2026-11562MEDIUM4.3The WS Form LITE WordPress plugin before 1.11.8 does not have a capability check on one of its settings-update actions,...
CVE-2026-9107MEDIUM6.4The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2026-7828MEDIUM5.3UltraVNC repeater through 1.8.2.2 contains an integer overflow in the HTTP request logging path. In repeater/webgui/sett...
CVE-2026-58519MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun...
CVE-2026-58518MEDIUM6.3Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - RedirectManager Extension allows...
CVE-2026-44041MEDIUM6.5UltraVNC through 1.8.2.2 contains an out-of-bounds read in the wide-string to multibyte conversion helper. In rfb/dh.cpp...
CVE-2026-44040MEDIUM6.5UltraVNC through 1.8.2.2 uses a cryptographically weak pseudo-random number generator to produce VNC authentication chal...
CVE-2026-2387MEDIUM6.4The Event Organiser plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi...
CVE-2026-13443MEDIUM6.4The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2026-13246MEDIUM6.4The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2026-13015MEDIUM6.1The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' ...
CVE-2026-12904MEDIUM4.3The Kadence Blocks – Gutenberg Blocks for Page Builder Features plugin for WordPress is vulnerable to Insecure Direct Ob...
CVE-2026-12902MEDIUM4.3The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypas...
CVE-2026-12135MEDIUM6.4The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' ...
CVE-2026-12133MEDIUM4.3The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Missing Authori...
CVE-2026-12127MEDIUM5.3The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vu...
CVE-2026-12113MEDIUM4.3The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up...
CVE-2026-12110MEDIUM6.5The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to gene...
CVE-2026-12090MEDIUM6.5The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to gene...
CVE-2026-11988MEDIUM6.5The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure ...
CVE-2026-11981MEDIUM4.3The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.15.3 Thi...
CVE-2026-11380MEDIUM6.4The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and inc...
CVE-2026-20463MEDIUM6.7In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation o...
CVE-2026-20462MEDIUM6.7In Telephony, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation o...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now