2026 CVE Vulnerabilities

69,870 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-30247HIGH7.5WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0....
CVE-2026-3352HIGH7.2The Easy PHP Settings plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0...
CVE-2026-2722MEDIUM4.8The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up...
CVE-2026-2721MEDIUM4.8The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up...
CVE-2026-2494MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery...
CVE-2026-2488MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message delet...
CVE-2026-2431MEDIUM6.1The CM Custom Reports plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date_from' and 'date...
CVE-2026-2429MEDIUM4.9The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'ce_venue_name' CSV field in the `on_sa...
CVE-2026-2020HIGH7.5The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1...
CVE-2026-1902MEDIUM6.4The Hammas Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'apix' parameter in the 'h...
CVE-2026-1650MEDIUM5.3The MDJM Event Management plugin for WordPress is vulnerable to unauthorized data modification due to a missing capabili...
CVE-2026-25073MEDIUM5.4XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a stored cross-site scripting vulnerabil...
CVE-2026-25072CRITICAL9.8XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a predictable session identifier vulnera...
CVE-2026-25071HIGH7.5XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability i...
CVE-2026-25070CRITICAL9.8XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in...
CVE-2026-2371MEDIUM5.3The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Insecure Direct Object Referenc...
CVE-2026-1981MEDIUM4.3The HUMN-1 AI Website Scanner & Human Certification by Winston AI plugin for WordPress is vulnerable to unauthorized mod...
CVE-2026-1644MEDIUM4.3The WP Frontend Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2026-3233——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-30244HIGH7.5Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate work...
CVE-2026-30242HIGH8.5Plane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/seri...
CVE-2026-30241HIGH8.2Mercurius is a GraphQL adapter for Fastify. Prior to version 16.8.0, Mercurius fails to enforce the configured queryDept...
CVE-2026-30238MEDIUM6.1Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.155, 25.0.88, a...
CVE-2026-30237MEDIUM6.1Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.155, 25.0.88, a...
CVE-2026-27142MEDIUM6.1Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now