2026 CVE Vulnerabilities
68,985 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32367 | CRITICAL | 9.1 | 0.4% | Mar 13, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Yannick Lefebvre Modal Dialog modal-dialog al... |
| CVE-2026-32366 | HIGH | 8.5 | 0.2% | Mar 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsin... |
| CVE-2026-32365 | HIGH | 8.5 | 0.3% | Mar 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsin... |
| CVE-2026-32364 | HIGH | 7.5 | 0.4% | Mar 13, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-32363 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in Funlus Oy WPLifeCycle free-php-version-info allows Exploiting Incorrectly Configu... |
| CVE-2026-32362 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows E... |
| CVE-2026-32361 | MEDIUM | 6.5 | 0.2% | Mar 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marketing Fire Edi... |
| CVE-2026-32360 | MEDIUM | 5.9 | 0.2% | Mar 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in richplugins Rich S... |
| CVE-2026-32359 | MEDIUM | 6.5 | 0.2% | Mar 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Icon List... |
| CVE-2026-32358 | HIGH | 7.6 | 0.3% | Mar 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevelop Booking ... |
| CVE-2026-32357 | MEDIUM | 6.4 | 0.2% | Mar 13, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Katsushi Kawamori Simple Blog Card simple-blog-card allows Server Si... |
| CVE-2026-32356 | MEDIUM | 6.5 | 0.2% | Mar 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gall... |
| CVE-2026-32355 | HIGH | 8.8 | 0.4% | Mar 13, 2026 | Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Object Injection.This issue af... |
| CVE-2026-32354 | MEDIUM | 5.3 | 0.3% | Mar 13, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Retri... |
| CVE-2026-32353 | MEDIUM | 6.4 | 0.2% | Mar 13, 2026 | Server-Side Request Forgery (SSRF) vulnerability in MailerPress Team MailerPress mailerpress allows Server Side Request ... |
| CVE-2026-32352 | MEDIUM | 6.5 | 0.2% | Mar 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elemento... |
| CVE-2026-32351 | MEDIUM | 5.9 | 0.2% | Mar 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blubrry PowerPress... |
| CVE-2026-32350 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in wpradiant Chocolate House chocolate-house allows Exploiting Incorrectly Configure... |
| CVE-2026-32349 | MEDIUM | 4.9 | 0.2% | Mar 13, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Andy Fragen Embed PDF Viewer embed-pdf-viewer allows Server Side Req... |
| CVE-2026-32348 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in MadrasThemes MAS Videos masvideos allows Exploiting Incorrectly Configured Access... |
| CVE-2026-32347 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in raratheme Restaurant and Cafe restaurant-and-cafe allows Exploiting Incorrectly C... |
| CVE-2026-32346 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in raratheme Travel Agency travel-agency allows Exploiting Incorrectly Configured Ac... |
| CVE-2026-32345 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in raratheme Perfect Portfolio perfect-portfolio allows Exploiting Incorrectly Confi... |
| CVE-2026-32344 | MEDIUM | 4.3 | 0.1% | Mar 13, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in desertthemes Corpiva corpiva allows Cross Site Request Forgery.This i... |
| CVE-2026-32343 | MEDIUM | 4.3 | 0.1% | Mar 13, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Magazine3 Easy Table of Contents easy-table-of-contents allows Cross ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now