2026 CVE Vulnerabilities

65,619 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-39649MEDIUM5.3Missing Authorization vulnerability in themebeez Royale News royale-news allows Exploiting Incorrectly Configured Access...
CVE-2026-39648MEDIUM5.3Missing Authorization vulnerability in themebeez Cream Blog cream-blog allows Exploiting Incorrectly Configured Access C...
CVE-2026-39647MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-mus...
CVE-2026-39646MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bozdoz Leaflet Map...
CVE-2026-39645MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in Global Payments GlobalPayments WooCommerce global-payments-woocommer...
CVE-2026-39644MEDIUM5.3Missing Authorization vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows Exploiting Incorrectly Config...
CVE-2026-39643MEDIUM5.3Missing Authorization vulnerability in Payment Plugins Payment Plugins for PayPal WooCommerce pymntpl-paypal-woocommerce...
CVE-2026-39641MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in Skywarrior Blackfyre blackfyre allows Cross Site Request Forgery.This...
CVE-2026-39640CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This iss...
CVE-2026-39639MEDIUM6.5Missing Authorization vulnerability in redpixelstudios RPS Include Content rps-include-content allows Exploiting Incorre...
CVE-2026-39638MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely qub...
CVE-2026-39637MEDIUM5.3Missing Authorization vulnerability in SpabRice Mogi mogi allows Exploiting Incorrectly Configured Access Control Securi...
CVE-2026-39636MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh ...
CVE-2026-39635MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Magazine grandmagazine allows Cross Site Request For...
CVE-2026-39634MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Portfolio grandportfolio allows Cross Site Request F...
CVE-2026-39633MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Car Rental grandcarrental allows Cross Site Request ...
CVE-2026-39632MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Blog grandblog allows Cross Site Request Forgery.Thi...
CVE-2026-39631MEDIUM4.9Missing Authorization vulnerability in Ronik@UnlimitedWP WPSchoolPress wpschoolpress allows Exploiting Incorrectly Confi...
CVE-2026-39630MEDIUM6.4Server-Side Request Forgery (SSRF) vulnerability in Getty Images Getty Images getty-images allows Server Side Request Fo...
CVE-2026-39629MEDIUM5.3Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes Uminex uminex ...
CVE-2026-39628MEDIUM5.3Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes DukaMarket duk...
CVE-2026-39627MEDIUM4.3Missing Authorization vulnerability in wproyal Ashe ashe allows Exploiting Incorrectly Configured Access Control Securit...
CVE-2026-39626MEDIUM5.3Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes Armania armani...
CVE-2026-39625MEDIUM5.3Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes TechOne techon...
CVE-2026-39624MEDIUM5.3Missing Authorization vulnerability in kutethemes Biolife biolife allows Exploiting Incorrectly Configured Access Contro...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now