2026 CVE Vulnerabilities
67,265 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3334 | HIGH | 8.8 | 0.3% | Mar 21, 2026 | The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and '... |
| CVE-2026-3333 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linkgate' ... |
| CVE-2026-3332 | MEDIUM | 4.3 | 0.1% | Mar 21, 2026 | The Xhanch - My Advanced Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to... |
| CVE-2026-3331 | MEDIUM | 4.3 | 0.1% | Mar 21, 2026 | The Lobot Slider Administrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i... |
| CVE-2026-3003 | HIGH | 7.2 | 0.3% | Mar 21, 2026 | The Vagaro Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vagaro_code’ parame... |
| CVE-2026-2941 | HIGH | 8.8 | 0.3% | Mar 21, 2026 | The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2026-2837 | MEDIUM | 4.4 | 0.2% | Mar 21, 2026 | The Ricerca – advanced search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settings in... |
| CVE-2026-2723 | MEDIUM | 6.1 | 0.1% | Mar 21, 2026 | The Post Snippits plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2026-2720 | MEDIUM | 6.5 | 0.2% | Mar 21, 2026 | The Hr Press Lite plugin for WordPress is vulnerable to unauthorized access of sensitive employee data due to a missing ... |
| CVE-2026-2503 | MEDIUM | 6.5 | 0.2% | Mar 21, 2026 | The ElementCamp plugin for WordPress is vulnerable to time-based SQL Injection via the 'meta_query[compare]' parameter i... |
| CVE-2026-2501 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Ed's Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `social_share` ... |
| CVE-2026-2496 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Ed's Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `eds_font_aweso... |
| CVE-2026-2468 | HIGH | 7.5 | 0.4% | Mar 21, 2026 | The Quentn WP plugin for WordPress is vulnerable to SQL Injection via the 'qntn_wp_access' cookie in all versions up to,... |
| CVE-2026-2440 | HIGH | 7.2 | 0.3% | Mar 21, 2026 | The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5... |
| CVE-2026-2427 | MEDIUM | 6.1 | 0.3% | Mar 21, 2026 | The itsukaita plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'day_from' and 'day_to' param... |
| CVE-2026-2424 | MEDIUM | 4.4 | 0.2% | Mar 21, 2026 | The Reward Video Ad for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i... |
| CVE-2026-2375 | MEDIUM | 6.5 | 0.3% | Mar 21, 2026 | The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Privilege Escalat... |
| CVE-2026-2351 | MEDIUM | 6.5 | 0.3% | Mar 21, 2026 | The Task Manager plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.0.2 v... |
| CVE-2026-2294 | MEDIUM | 4.3 | 0.2% | Mar 21, 2026 | The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthoriz... |
| CVE-2026-2290 | LOW | 3.8 | 0.3% | Mar 21, 2026 | The Post Affiliate Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and incl... |
| CVE-2026-2279 | HIGH | 7.2 | 0.4% | Mar 21, 2026 | The myLinksDump plugin for WordPress is vulnerable to SQL Injection via the 'sort_by' and 'sort_order' parameters in all... |
| CVE-2026-2277 | MEDIUM | 6.1 | 0.3% | Mar 21, 2026 | The rexCrawler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' and 'regex' parameters... |
| CVE-2026-2121 | MEDIUM | 4.4 | 0.2% | Mar 21, 2026 | The Weaver Show Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_class' parameter in... |
| CVE-2026-1935 | MEDIUM | 4.3 | 0.2% | Mar 21, 2026 | The Company Posts for LinkedIn plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and in... |
| CVE-2026-1914 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fusedesk_newcase shortco... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now