2026 CVE Vulnerabilities

45,067 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-9233MEDIUM4.3The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass...
CVE-2026-3462MEDIUM6.5The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks...
CVE-2026-13295MEDIUM6.4The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Paramet...
CVE-2026-12471MEDIUM4.3The Spexo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the activate_plu...
CVE-2026-12432MEDIUM5.3The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8....
CVE-2026-12399MEDIUM4.4The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-11987MEDIUM4.3The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPr...
CVE-2026-11783MEDIUM6.4The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPr...
CVE-2026-11773MEDIUM4.3The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypas...
CVE-2026-11597MEDIUM6.4The Surbma | Infusionsoft Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'infusions...
CVE-2026-11364MEDIUM4.3The Product Specifications for WooCommerce plugin for WordPress is vulnerable to unauthorized modification, creation, an...
CVE-2026-9677MEDIUM4.8The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl se...
CVE-2026-13245MEDIUM6.1The MaxButtons – Create buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view' para...
CVE-2026-12404MEDIUM5.3The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all ve...
CVE-2026-13422MEDIUM4.3The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to ...
CVE-2026-13335MEDIUM6.4The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point...
CVE-2026-13333MEDIUM6.5The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection ...
CVE-2026-13331MEDIUM6.5The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection ...
CVE-2026-11356MEDIUM4.4The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'menu_t...
CVE-2026-28701MEDIUM5.3Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape ...
CVE-2026-53577MEDIUM6.5Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the previewFileFromExecution ...
CVE-2026-50767MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System...
CVE-2026-50766MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 throu...
CVE-2026-50765MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Man...
CVE-2026-38571MEDIUM4.6Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now