2026 CVE Vulnerabilities

65,632 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-39487HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ameliabooking Amel...
CVE-2026-39486HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Chill Download ...
CVE-2026-39485MEDIUM4.3Missing Authorization vulnerability in embedplus Youtube Embed Plus youtube-embed-plus allows Exploiting Incorrectly Con...
CVE-2026-39484MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows Phis...
CVE-2026-39483MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidekazu Ishikawa ...
CVE-2026-39482MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Post ...
CVE-2026-39479HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force O...
CVE-2026-39477MEDIUM4.3Missing Authorization vulnerability in Brainstorm Force CartFlows cartflows allows Exploiting Incorrectly Configured Acc...
CVE-2026-39476MEDIUM4.3Missing Authorization vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Exploiting Incorrectly Configu...
CVE-2026-39475HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User F...
CVE-2026-39473MEDIUM5.3Insertion of Sensitive Information Into Sent Data vulnerability in Pär Thernström Simple History simple-history allows R...
CVE-2026-39469MEDIUM4.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Softaculous PageLayer pagela...
CVE-2026-39466HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMU DEV - Your Al...
CVE-2026-39464MEDIUM5.5Server-Side Request Forgery (SSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by ...
CVE-2026-33088CRITICAL9.8Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute a...
CVE-2026-25776CRITICAL9.8Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute a...
CVE-2026-1396MEDIUM6.4The Magic Conversation For Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'magi...
CVE-2026-4655MEDIUM6.4The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG Imag...
CVE-2026-4654MEDIUM5.3The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object R...
CVE-2026-4483HIGH7An exposed IOCTL with an  insufficient access control vulnerability has been identified in the utility, MxGeneralIo, for...
CVE-2026-4330MEDIUM4.3The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass through u...
CVE-2026-5508MEDIUM6.4The WowPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wowpress` shortcode in ...
CVE-2026-5506MEDIUM6.4The Wavr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wave` shortcode in all vers...
CVE-2026-5169MEDIUM4.4The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Form Heade...
CVE-2026-5167MEDIUM5.3The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Authoriza...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now