2026 CVE Vulnerabilities

67,214 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-24993CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced...
CVE-2026-24989CRITICAL9.8Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.Thi...
CVE-2026-24987MEDIUM6.5Missing Authorization vulnerability in activity-log.com WP System Log winterlock allows Exploiting Incorrectly Configure...
CVE-2026-24983HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UpSolution UpSolut...
CVE-2026-24981HIGH8.8Deserialization of Untrusted Data vulnerability in NooTheme Visionary Core noo-visionary-core allows Object Injection.Th...
CVE-2026-24980HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Visionary...
CVE-2026-24979HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobica Co...
CVE-2026-24978HIGH8.8Deserialization of Untrusted Data vulnerability in NooTheme Jobica Core jobica-core allows Object Injection.This issue a...
CVE-2026-24977HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Organici ...
CVE-2026-24976HIGH8.8Deserialization of Untrusted Data vulnerability in NooTheme Organici Library noo-organici-library allows Object Injectio...
CVE-2026-24975HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Organici ...
CVE-2026-24974HIGH8.8Deserialization of Untrusted Data vulnerability in NooTheme CitiLights noo-citilights allows Object Injection.This issue...
CVE-2026-24973HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme CitiLight...
CVE-2026-24972MEDIUM6.5Missing Authorization vulnerability in Elated-Themes Elated Listing eltd-listing allows Exploiting Incorrectly Configure...
CVE-2026-24971CRITICAL9.8Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issu...
CVE-2026-24970HIGH7.7Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Energox e...
CVE-2026-24969HIGH7.7Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Instant V...
CVE-2026-24968CRITICAL9.8Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue aff...
CVE-2026-24964MEDIUM6.4Server-Side Request Forgery (SSRF) vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-...
CVE-2026-24391HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeMakers Car De...
CVE-2026-24382HIGH7.5Missing Authorization vulnerability in wproyal News Magazine X news-magazine-x allows Exploiting Incorrectly Configured ...
CVE-2026-24378CRITICAL9.8Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Obje...
CVE-2026-24376MEDIUM6.5Missing Authorization vulnerability in Javier Casares WPVulnerability wpvulnerability allows Exploiting Incorrectly Conf...
CVE-2026-24373HIGH8.1Incorrect Privilege Assignment vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submis...
CVE-2026-24372HIGH7.5Authentication Bypass by Spoofing vulnerability in WP Swings Subscriptions for WooCommerce subscriptions-for-woocommerce...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now