2026 CVE Vulnerabilities

64,760 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-95523MEDIUM6.5Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
CVE-2026-95514MEDIUM5.3Unauthenticated Bypass Vulnerability in Netgsm <= 2.10.0 versions.
CVE-2026-94684MEDIUM6.5Contributor Cross Site Scripting (XSS) in Ocean Extra <= 2.6.1 versions.
CVE-2026-94682MEDIUM6.5Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine <= 1.5.6 versions.
CVE-2026-94680MEDIUM6.5Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.
CVE-2026-94679MEDIUM5.4Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.
CVE-2026-94671MEDIUM6.5Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.
CVE-2026-94500MEDIUM6.5Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions.
CVE-2026-94498MEDIUM6.5Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions.
CVE-2026-94461MEDIUM6.5Contributor Cross Site Scripting (XSS) in Ditty <= 3.1.69 versions.
CVE-2026-94457MEDIUM4.8Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions.
CVE-2026-94391MEDIUM6.5Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions.
CVE-2026-94168MEDIUM6.5Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions.
CVE-2026-94118MEDIUM6.5Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions.
CVE-2026-94080MEDIUM5.3Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions.
CVE-2026-94079MEDIUM5.3Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions.
CVE-2026-93772MEDIUM6.5Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions.
CVE-2026-93623MEDIUM5.3Unauthenticated Insecure Direct Object References (IDOR) in AI Engine <= 3.7.8 versions.
CVE-2026-93620MEDIUM6.5Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions.
CVE-2026-93618MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimp...
CVE-2026-93529MEDIUM6.5Contributor Broken Access Control in WSP MCP &#8211; AI Agents Connector <= 2.7.0 versions.
CVE-2026-93513MEDIUM4.3Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions.
CVE-2026-93421MEDIUM5.3Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /_...
CVE-2026-92700MEDIUM6.3Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/fil...
CVE-2026-92692MEDIUM6.9Sulu is an open-source PHP content management system based on the Symfony framework. Prior to 2.6.25 and 3.0.8, the affe...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now