2026 CVE Vulnerabilities

67,286 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-85574HIGH8The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the conf...
CVE-2026-84750MEDIUM6.5The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uplo...
CVE-2026-76790HIGH7.1The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a ...
CVE-2026-76554HIGH7.2The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to...
CVE-2026-19860MEDIUM5.5The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PH...
CVE-2026-16557MEDIUM4.3The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-build...
CVE-2026-93741CRITICAL10A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the functio...
CVE-2026-92967MEDIUM6.1The Pochipp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword' parameter in versions...
CVE-2026-92807HIGH8.8The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions u...
CVE-2026-92229CRITICAL9.1The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitr...
CVE-2026-89334MEDIUM6.5The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to auth...
CVE-2026-89333MEDIUM6.5The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere...
CVE-2026-89274CRITICAL9.1The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and inclu...
CVE-2026-89093MEDIUM5.3The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Info...
CVE-2026-89081MEDIUM6.1The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin...
CVE-2026-88944MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to authorization bypass in all v...
CVE-2026-87909HIGH7.5The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_m...
CVE-2026-84434CRITICAL9.8The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1....
CVE-2026-15760MEDIUM6.5The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in versions up to, and including...
CVE-2026-15660MEDIUM4.3The SEO Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.4.7. Thi...
CVE-2026-13354HIGH7.2The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Cont...
CVE-2026-12042MEDIUM4.4The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v...
CVE-2026-77820MEDIUM6.4The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty' Shortcode Attribute in all ...
CVE-2026-93923HIGH8.8SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing st...
CVE-2026-93922HIGH8.8SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing store...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now