2026 CVE Vulnerabilities
45,067 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9233 | MEDIUM | 4.3 | 0.3% | Jun 27, 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass... |
| CVE-2026-3462 | MEDIUM | 6.5 | 0.3% | Jun 27, 2026 | The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks... |
| CVE-2026-13295 | MEDIUM | 6.4 | 0.2% | Jun 27, 2026 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Paramet... |
| CVE-2026-12471 | MEDIUM | 4.3 | 0.2% | Jun 27, 2026 | The Spexo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the activate_plu... |
| CVE-2026-12432 | MEDIUM | 5.3 | 0.3% | Jun 27, 2026 | The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.... |
| CVE-2026-12399 | MEDIUM | 4.4 | 0.2% | Jun 27, 2026 | The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2026-11987 | MEDIUM | 4.3 | 0.3% | Jun 27, 2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPr... |
| CVE-2026-11783 | MEDIUM | 6.4 | 0.2% | Jun 27, 2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPr... |
| CVE-2026-11773 | MEDIUM | 4.3 | 0.1% | Jun 27, 2026 | The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypas... |
| CVE-2026-11597 | MEDIUM | 6.4 | 0.2% | Jun 27, 2026 | The Surbma | Infusionsoft Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'infusions... |
| CVE-2026-11364 | MEDIUM | 4.3 | 0.2% | Jun 27, 2026 | The Product Specifications for WooCommerce plugin for WordPress is vulnerable to unauthorized modification, creation, an... |
| CVE-2026-9677 | MEDIUM | 4.8 | 0.2% | Jun 27, 2026 | The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl se... |
| CVE-2026-13245 | MEDIUM | 6.1 | 0.2% | Jun 27, 2026 | The MaxButtons – Create buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view' para... |
| CVE-2026-12404 | MEDIUM | 5.3 | 0.3% | Jun 27, 2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all ve... |
| CVE-2026-13422 | MEDIUM | 4.3 | 0.2% | Jun 27, 2026 | The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to ... |
| CVE-2026-13335 | MEDIUM | 6.4 | 0.2% | Jun 27, 2026 | The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point... |
| CVE-2026-13333 | MEDIUM | 6.5 | 0.3% | Jun 27, 2026 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection ... |
| CVE-2026-13331 | MEDIUM | 6.5 | 0.3% | Jun 27, 2026 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection ... |
| CVE-2026-11356 | MEDIUM | 4.4 | 0.3% | Jun 27, 2026 | The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'menu_t... |
| CVE-2026-28701 | MEDIUM | 5.3 | 0.8% | Jun 26, 2026 | Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape ... |
| CVE-2026-53577 | MEDIUM | 6.5 | 0.3% | Jun 26, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the previewFileFromExecution ... |
| CVE-2026-50767 | MEDIUM | 5.4 | 0.2% | Jun 26, 2026 | A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System... |
| CVE-2026-50766 | MEDIUM | 5.4 | 0.2% | Jun 26, 2026 | A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 throu... |
| CVE-2026-50765 | MEDIUM | 6.1 | 0.2% | Jun 26, 2026 | A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Man... |
| CVE-2026-38571 | MEDIUM | 4.6 | 0.2% | Jun 26, 2026 | Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now