2026 CVE Vulnerabilities

67,265 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-1911MEDIUM6.4The Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tweet_title' parameter in t...
CVE-2026-1908MEDIUM6.4The Integration with Hubspot Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hubspotfor...
CVE-2026-1899MEDIUM6.4The Any Post Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aps_slider shortc...
CVE-2026-1891MEDIUM6.4The Simple Football Scoreboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ytmr_fb_scoreb...
CVE-2026-1889MEDIUM6.4The Outgrow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the 'outgrow' sh...
CVE-2026-1886MEDIUM6.4The Go Night Pro | WordPress Dark Mode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2026-1854MEDIUM6.4The Post Flagger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'flag' shortcode in ...
CVE-2026-1851MEDIUM6.4The iVysilani Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' shortcode attr...
CVE-2026-1822MEDIUM6.4The WP NG Weather plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ng-weather' shortc...
CVE-2026-1806MEDIUM6.4The Tour & Activity Operator Plugin for TourCMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2026-1800HIGH7.5The Fonts Manager | Custom Fonts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘fmcfIdSelectedF...
CVE-2026-1648HIGH7.2The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inc...
CVE-2026-1647MEDIUM6.1The Comment Genius plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` p...
CVE-2026-1575MEDIUM6.4The Schema Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `itemscope` shor...
CVE-2026-1503MEDIUM4.3The login_register plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in al...
CVE-2026-1397MEDIUM6.4The PQ Addons – Creative Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget ...
CVE-2026-1393MEDIUM4.3The Add Google Social Profiles to Knowledge Graph Box plugin for WordPress is vulnerable to Cross-Site Request Forgery i...
CVE-2026-1392MEDIUM4.3The SR WP Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2026-1390MEDIUM4.3The Redirect countdown plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2026-1378MEDIUM4.3The WP Posts Re-order plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2026-1313HIGH8.3The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in...
CVE-2026-1278MEDIUM4.4The Mandatory Field plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions...
CVE-2026-1275MEDIUM6.4The Multi Post Carousel by Category plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slides' s...
CVE-2026-1253MEDIUM4.3The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to unauthorized modification of data due to a...
CVE-2026-1247MEDIUM4.4The Survey plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now