2026 CVE Vulnerabilities

67,251 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4514MEDIUM6.3A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/ad...
CVE-2026-4513MEDIUM6.3A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is the function ask of the fi...
CVE-2026-4511MEDIUM6.3A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. Affected is the function exec of the file /src...
CVE-2026-4510MEDIUM4.3A weakness has been identified in PbootCMS up to 3.2.12. This impacts the function alert_location of the file apps/home/...
CVE-2026-4373HIGH7.5The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, a...
CVE-2026-4509MEDIUM6.3A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function...
CVE-2026-4261HIGH8.8The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2....
CVE-2026-4161MEDIUM4.4The Review Map by RevuKangaroo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings...
CVE-2026-4143MEDIUM4.3The Neos Connector for Fakturama plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to ...
CVE-2026-4127MEDIUM4.3The Speedup Optimization plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including...
CVE-2026-4087MEDIUM6.5The Pre* Party Resource Hints plugin for WordPress is vulnerable to SQL Injection via the 'hint_ids' parameter of the pp...
CVE-2026-4086MEDIUM6.4The WP Random Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cat', 'nocat', and 'text...
CVE-2026-4084MEDIUM6.4The fyyd podcast shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fyyd-podcast', 'f...
CVE-2026-4077MEDIUM6.4The Ecover Builder For Dummies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter ...
CVE-2026-4072MEDIUM6.4The WordPress PayPal Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'donate' shortco...
CVE-2026-4069MEDIUM6.1The Alfie – Feed Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'naam' parameter in al...
CVE-2026-4067MEDIUM6.4The Ad Short plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ad' shortcode's 'client' attribu...
CVE-2026-4022MEDIUM6.4The Show Posts list – Easy designs, filters and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2026-4004MEDIUM6.5The Task Manager plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'search' AJAX action in all...
CVE-2026-3997MEDIUM6.4The Text Toggle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute of...
CVE-2026-3996MEDIUM6.4The WP Games Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [game] shortcode in all ver...
CVE-2026-3651MEDIUM5.3The Build App Online plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0...
CVE-2026-3645MEDIUM5.3The Punnel – Landing Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and...
CVE-2026-3641MEDIUM5.3The Appmax plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.0.3. ...
CVE-2026-3619MEDIUM6.4The Sheets2Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titles' shortcode attribute ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now