2026 CVE Vulnerabilities

67,265 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-3334HIGH8.8The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and '...
CVE-2026-3333MEDIUM6.4The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linkgate' ...
CVE-2026-3332MEDIUM4.3The Xhanch - My Advanced Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to...
CVE-2026-3331MEDIUM4.3The Lobot Slider Administrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i...
CVE-2026-3003HIGH7.2The Vagaro Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vagaro_code’ parame...
CVE-2026-2941HIGH8.8The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...
CVE-2026-2837MEDIUM4.4The Ricerca – advanced search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settings in...
CVE-2026-2723MEDIUM6.1The Post Snippits plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2026-2720MEDIUM6.5The Hr Press Lite plugin for WordPress is vulnerable to unauthorized access of sensitive employee data due to a missing ...
CVE-2026-2503MEDIUM6.5The ElementCamp plugin for WordPress is vulnerable to time-based SQL Injection via the 'meta_query[compare]' parameter i...
CVE-2026-2501MEDIUM6.4The Ed's Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `social_share` ...
CVE-2026-2496MEDIUM6.4The Ed's Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `eds_font_aweso...
CVE-2026-2468HIGH7.5The Quentn WP plugin for WordPress is vulnerable to SQL Injection via the 'qntn_wp_access' cookie in all versions up to,...
CVE-2026-2440HIGH7.2The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5...
CVE-2026-2427MEDIUM6.1The itsukaita plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'day_from' and 'day_to' param...
CVE-2026-2424MEDIUM4.4The Reward Video Ad for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i...
CVE-2026-2375MEDIUM6.5The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Privilege Escalat...
CVE-2026-2351MEDIUM6.5The Task Manager plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.0.2 v...
CVE-2026-2294MEDIUM4.3The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthoriz...
CVE-2026-2290LOW3.8The Post Affiliate Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and incl...
CVE-2026-2279HIGH7.2The myLinksDump plugin for WordPress is vulnerable to SQL Injection via the 'sort_by' and 'sort_order' parameters in all...
CVE-2026-2277MEDIUM6.1The rexCrawler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' and 'regex' parameters...
CVE-2026-2121MEDIUM4.4The Weaver Show Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_class' parameter in...
CVE-2026-1935MEDIUM4.3The Company Posts for LinkedIn plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and in...
CVE-2026-1914MEDIUM6.4The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fusedesk_newcase shortco...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now