2026 CVE Vulnerabilities
65,619 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3243 | HIGH | 8.8 | 0.8% | Apr 8, 2026 | The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path... |
| CVE-2026-2481 | MEDIUM | 6.4 | 0.3% | Apr 8, 2026 | The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site ... |
| CVE-2026-28264 | MEDIUM | 5.5 | 0.1% | Apr 8, 2026 | Dell PowerProtect Agent Service, version(s) prior to 20.1, contain(s) an Incorrect Permission Assignment for Critical Re... |
| CVE-2026-1865 | MEDIUM | 6.5 | 0.3% | Apr 8, 2026 | The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom U... |
| CVE-2026-1673 | MEDIUM | 4.3 | 0.1% | Apr 8, 2026 | The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnera... |
| CVE-2026-1672 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnera... |
| CVE-2026-4303 | MEDIUM | 6.4 | 0.3% | Apr 8, 2026 | The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ... |
| CVE-2026-4300 | MEDIUM | 6.4 | 0.4% | Apr 8, 2026 | The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Loading Label' setting in al... |
| CVE-2026-4073 | MEDIUM | 6.4 | 0.3% | Apr 8, 2026 | The pdfl.io plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pdflio' shortcode in all versions... |
| CVE-2026-4025 | MEDIUM | 6.4 | 0.3% | Apr 8, 2026 | The PrivateContent Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' shortcode attr... |
| CVE-2026-39716 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in CKThemes Flipmart flipmart allows Exploiting Incorrectly Configured Access Contro... |
| CVE-2026-39715 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in AnyTrack AnyTrack Affiliate Link Manager anytrack-affiliate-link-manager allows E... |
| CVE-2026-39714 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in G5Theme G5Plus April g5plus-april allows Exploiting Incorrectly Configured Access... |
| CVE-2026-39713 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in mailercloud Mailercloud – Integrate webforms and synchronize website contacts mai... |
| CVE-2026-39712 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in tagDiv tagDiv Composer td... |
| CVE-2026-39711 | MEDIUM | 5.3 | 0.3% | Apr 8, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allow... |
| CVE-2026-39710 | MEDIUM | 5.4 | 0.1% | Apr 8, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Cross Site Req... |
| CVE-2026-39709 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in thetechtribe The Tribal the-tech-tribe allows Retriev... |
| CVE-2026-39708 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UiCore UiCore Elem... |
| CVE-2026-39707 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in ZealousWeb Accept PayPal Payments using Contact Form 7 contact-form-7-paypal-exte... |
| CVE-2026-39706 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in Netro Systems Make My Trivia trivialy allows Exploiting Incorrectly Configured Ac... |
| CVE-2026-39705 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in Mulika Team MIPL WC Multisite Sync mipl-wc-multisite-sync allows Exploiting Incor... |
| CVE-2026-39704 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in nfusionsolutions Precious Metals Automated Product Pricing – Pro precious-metals-... |
| CVE-2026-39703 | MEDIUM | 6.5 | 0.1% | Apr 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpbits WPBITS Addo... |
| CVE-2026-39702 | MEDIUM | 6.5 | 0.1% | Apr 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wealcoder Animatio... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now