2026 CVE Vulnerabilities

67,418 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-25443HIGH7.5Missing Authorization vulnerability in Dotstore Fraud Prevention For Woocommerce woo-blocker-lite-prevent-fake-orders-an...
CVE-2026-25442HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QantumThemes Kenth...
CVE-2026-25438HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Gutenber...
CVE-2026-21788MEDIUM5.4HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbi...
CVE-2026-3475MEDIUM5.3The Instant Popup Builder plugin for WordPress is vulnerable to Unauthenticated Arbitrary Shortcode Execution in all ver...
CVE-2026-25471HIGH8.1Authentication Bypass Using an Alternate Path or Channel vulnerability in Themepaste Admin Safety Guard admin-safety-gua...
CVE-2026-25312HIGH7.5Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incor...
CVE-2026-4120MEDIUM6.4The Info Cards – Add Text and Media in Card Layouts plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2026-4068MEDIUM4.3The Add Custom Fields to Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2026-4006MEDIUM6.4The Simple Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name' post meta...
CVE-2026-2571MEDIUM4.3The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check...
CVE-2026-27093HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-27091MEDIUM6.3Missing Authorization vulnerability in UiPress UiPress lite uipress-lite allows Exploiting Incorrectly Configured Access...
CVE-2026-28073HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tips and Tricks HQ...
CVE-2026-28070MEDIUM5.3Missing Authorization vulnerability in Tips and Tricks HQ WP eMember allows Exploiting Incorrectly Configured Access Con...
CVE-2026-28044MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media WP Rocket...
CVE-2026-27542CRITICAL9.8Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wh...
CVE-2026-27540CRITICAL9Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Captu...
CVE-2026-27413CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile...
CVE-2026-27397MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in Really Simple Plugins B.V. Really Simple Security Pro ...
CVE-2026-27096HIGH8.1Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio - Freelance Designer WordPress Theme allows O...
CVE-2026-1238HIGH7.2The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fh' (fingerprint) para...
CVE-2026-1276MEDIUM5.4IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows a...
CVE-2026-32000HIGH7.1OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execution t...
CVE-2026-31999HIGH7.8OpenClaw versions 2026.2.26 prior to 2026.3.1 on Windows contain a current working directory injection vulnerability in ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now