2026 CVE Vulnerabilities
65,632 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39487 | HIGH | 7.6 | 0.3% | Apr 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ameliabooking Amel... |
| CVE-2026-39486 | HIGH | 8.5 | 0.3% | Apr 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Chill Download ... |
| CVE-2026-39485 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in embedplus Youtube Embed Plus youtube-embed-plus allows Exploiting Incorrectly Con... |
| CVE-2026-39484 | MEDIUM | 4.7 | 0.2% | Apr 8, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows Phis... |
| CVE-2026-39483 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidekazu Ishikawa ... |
| CVE-2026-39482 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Post ... |
| CVE-2026-39479 | HIGH | 7.6 | 0.3% | Apr 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force O... |
| CVE-2026-39477 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in Brainstorm Force CartFlows cartflows allows Exploiting Incorrectly Configured Acc... |
| CVE-2026-39476 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Exploiting Incorrectly Configu... |
| CVE-2026-39475 | HIGH | 7.6 | 0.3% | Apr 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User F... |
| CVE-2026-39473 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Pär Thernström Simple History simple-history allows R... |
| CVE-2026-39469 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Softaculous PageLayer pagela... |
| CVE-2026-39466 | HIGH | 7.6 | 0.3% | Apr 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMU DEV - Your Al... |
| CVE-2026-39464 | MEDIUM | 5.5 | 0.2% | Apr 8, 2026 | Server-Side Request Forgery (SSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by ... |
| CVE-2026-33088 | CRITICAL | 9.8 | 0.3% | Apr 8, 2026 | Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute a... |
| CVE-2026-25776 | CRITICAL | 9.8 | 0.5% | Apr 8, 2026 | Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute a... |
| CVE-2026-1396 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | The Magic Conversation For Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'magi... |
| CVE-2026-4655 | MEDIUM | 6.4 | 0.4% | Apr 8, 2026 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG Imag... |
| CVE-2026-4654 | MEDIUM | 5.3 | 0.3% | Apr 8, 2026 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object R... |
| CVE-2026-4483 | HIGH | 7 | 0.3% | Apr 8, 2026 | An exposed IOCTL with an insufficient access control vulnerability has been identified in the utility, MxGeneralIo, for... |
| CVE-2026-4330 | MEDIUM | 4.3 | 0.5% | Apr 8, 2026 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass through u... |
| CVE-2026-5508 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | The WowPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wowpress` shortcode in ... |
| CVE-2026-5506 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | The Wavr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wave` shortcode in all vers... |
| CVE-2026-5169 | MEDIUM | 4.4 | 0.3% | Apr 8, 2026 | The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Form Heade... |
| CVE-2026-5167 | MEDIUM | 5.3 | 0.4% | Apr 8, 2026 | The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Authoriza... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now