2026 CVE Vulnerabilities
67,251 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4514 | MEDIUM | 6.3 | 0.2% | Mar 21, 2026 | A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/ad... |
| CVE-2026-4513 | MEDIUM | 6.3 | 0.2% | Mar 21, 2026 | A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is the function ask of the fi... |
| CVE-2026-4511 | MEDIUM | 6.3 | 0.2% | Mar 21, 2026 | A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. Affected is the function exec of the file /src... |
| CVE-2026-4510 | MEDIUM | 4.3 | 0.3% | Mar 21, 2026 | A weakness has been identified in PbootCMS up to 3.2.12. This impacts the function alert_location of the file apps/home/... |
| CVE-2026-4373 | HIGH | 7.5 | 0.4% | Mar 21, 2026 | The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, a... |
| CVE-2026-4509 | MEDIUM | 6.3 | 0.3% | Mar 21, 2026 | A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function... |
| CVE-2026-4261 | HIGH | 8.8 | 0.3% | Mar 21, 2026 | The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2.... |
| CVE-2026-4161 | MEDIUM | 4.4 | 0.3% | Mar 21, 2026 | The Review Map by RevuKangaroo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings... |
| CVE-2026-4143 | MEDIUM | 4.3 | 0.1% | Mar 21, 2026 | The Neos Connector for Fakturama plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to ... |
| CVE-2026-4127 | MEDIUM | 4.3 | 0.2% | Mar 21, 2026 | The Speedup Optimization plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including... |
| CVE-2026-4087 | MEDIUM | 6.5 | 0.3% | Mar 21, 2026 | The Pre* Party Resource Hints plugin for WordPress is vulnerable to SQL Injection via the 'hint_ids' parameter of the pp... |
| CVE-2026-4086 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The WP Random Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cat', 'nocat', and 'text... |
| CVE-2026-4084 | MEDIUM | 6.4 | 0.3% | Mar 21, 2026 | The fyyd podcast shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fyyd-podcast', 'f... |
| CVE-2026-4077 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Ecover Builder For Dummies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter ... |
| CVE-2026-4072 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The WordPress PayPal Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'donate' shortco... |
| CVE-2026-4069 | MEDIUM | 6.1 | 0.2% | Mar 21, 2026 | The Alfie – Feed Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'naam' parameter in al... |
| CVE-2026-4067 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Ad Short plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ad' shortcode's 'client' attribu... |
| CVE-2026-4022 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Show Posts list – Easy designs, filters and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2026-4004 | MEDIUM | 6.5 | 0.3% | Mar 21, 2026 | The Task Manager plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'search' AJAX action in all... |
| CVE-2026-3997 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Text Toggle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute of... |
| CVE-2026-3996 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The WP Games Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [game] shortcode in all ver... |
| CVE-2026-3651 | MEDIUM | 5.3 | 0.3% | Mar 21, 2026 | The Build App Online plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0... |
| CVE-2026-3645 | MEDIUM | 5.3 | 0.3% | Mar 21, 2026 | The Punnel – Landing Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and... |
| CVE-2026-3641 | MEDIUM | 5.3 | 0.3% | Mar 21, 2026 | The Appmax plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.0.3. ... |
| CVE-2026-3619 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Sheets2Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titles' shortcode attribute ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now