2026 CVE Vulnerabilities
65,632 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39544 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-39543 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2026-39542 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Doofinder Doofinder for WooCommerce doofinder-for-woo... |
| CVE-2026-39541 | MEDIUM | 5.9 | 0.2% | Apr 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Boo... |
| CVE-2026-39538 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-39536 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Chill RSVP and Event Mana... |
| CVE-2026-39535 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in fullworks Display Eventbrite Events widget-for-eventbrite-api allows Exploiting I... |
| CVE-2026-39528 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in WP Delicious WP Delicious delicious-recipes allows Exploiting Incorrectly Configu... |
| CVE-2026-39526 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in wpstream WpStream wpstream allows Exploiting Incorrect... |
| CVE-2026-39521 | MEDIUM | 4.9 | 0.1% | Apr 8, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Nelio Software Nelio Content nelio-content allows Server Side Reques... |
| CVE-2026-39520 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in weDevs weDocs wedocs allows Exploiting Incorrectly Configured Access Control Secu... |
| CVE-2026-39517 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Blog Fil... |
| CVE-2026-39516 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in POSIMYTH Nexter Blocks the-p... |
| CVE-2026-39510 | LOW | 2.7 | 0.2% | Apr 8, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-ti... |
| CVE-2026-39509 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Con... |
| CVE-2026-39508 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Kohlbach Adva... |
| CVE-2026-39506 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in Jordy Meow AI Engine (Pro) ai-engine-pro allows Exploiting Incorrectly Configured... |
| CVE-2026-39505 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Explo... |
| CVE-2026-39504 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured ... |
| CVE-2026-39501 | MEDIUM | 5.3 | 0.3% | Apr 8, 2026 | Missing Authorization vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Exploiting Incorrectly Config... |
| CVE-2026-39500 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesflat themesf... |
| CVE-2026-39497 | HIGH | 7.6 | 0.3% | Apr 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 FOX woo... |
| CVE-2026-39496 | HIGH | 7.6 | 0.3% | Apr 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayMai... |
| CVE-2026-39495 | HIGH | 8.5 | 0.3% | Apr 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NSquared Simply Sc... |
| CVE-2026-39488 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in SureCart SureCart surecart allows Exploiting Incorrectly Configured Access Contro... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now