2026 CVE Vulnerabilities

67,214 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-25340CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Jobmonste...
CVE-2026-25339MEDIUM6.5Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allo...
CVE-2026-25334HIGH8.1Incorrect Privilege Assignment vulnerability in wordpresschef Salon Booking System Pro salon-booking-plugin-pro allows P...
CVE-2026-25328MEDIUM6.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Product File...
CVE-2026-25327MEDIUM6.5Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Explo...
CVE-2026-25317HIGH7.5Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-deliver...
CVE-2026-25309HIGH7.5Missing Authorization vulnerability in PublishPress PublishPress Authors publishpress-authors allows Exploiting Incorrec...
CVE-2026-25306HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core...
CVE-2026-25304HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Jaroti ja...
CVE-2026-25035CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker / ContestGallery developer Co...
CVE-2026-25034MEDIUM6.5Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorr...
CVE-2026-25033HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uixthemes Motta Ad...
CVE-2026-25032CRITICAL9.8Deserialization of Untrusted Data vulnerability in park_of_ideas Ricky ricky allows Object Injection.This issue affects ...
CVE-2026-25031CRITICAL9.8Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This iss...
CVE-2026-25030CRITICAL9.8Deserialization of Untrusted Data vulnerability in park_of_ideas Goldish goldish allows Object Injection.This issue affe...
CVE-2026-25029CRITICAL9.8Deserialization of Untrusted Data vulnerability in park_of_ideas KIDZ kidz allows Object Injection.This issue affects KI...
CVE-2026-25026HIGH7.5Missing Authorization vulnerability in RadiusTheme Team tlp-team allows Exploiting Incorrectly Configured Access Control...
CVE-2026-25025HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRestau...
CVE-2026-25018HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan NaturaLife ...
CVE-2026-25017HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-25013HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WHMCSdes Phox Host...
CVE-2026-25009MEDIUM6.5Missing Authorization vulnerability in raratheme Education Zone education-zone allows Exploiting Incorrectly Configured ...
CVE-2026-25007HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Element Invader El...
CVE-2026-25002HIGH7.5Authentication Bypass Using an Alternate Path or Channel vulnerability in ThimPress LearnPress – Sepay Payment learnpres...
CVE-2026-25001HIGH8.5Improper Control of Generation of Code ('Code Injection') vulnerability in Saad Iqbal Post Snippets post-snippets allows...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now