2026 CVE Vulnerabilities

67,696 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-92622MEDIUM6.4The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lightbox_class' Shortcode...
CVE-2026-92554MEDIUM6.1The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Reflecte...
CVE-2026-92249MEDIUM6.1The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter i...
CVE-2026-90981MEDIUM6.1The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting...
CVE-2026-89059HIGH7.5A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing ...
CVE-2026-89058HIGH7.4A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Ori...
CVE-2026-85705HIGH7.5The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and 'longitude' REST API...
CVE-2026-85652MEDIUM6.5The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injectio...
CVE-2026-75961MEDIUM4.9The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the ...
CVE-2026-75157HIGH7.5Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `E...
CVE-2026-67103HIGH7.6HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to ...
CVE-2026-67102HIGH8.1HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a lo...
CVE-2026-67101CRITICAL9.3HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functional...
CVE-2026-67100CRITICAL9.8HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. w...
CVE-2026-18442HIGH7.5The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injecti...
CVE-2026-17607MEDIUM6.5The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the ...
CVE-2026-17586MEDIUM6.4The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vkExUnit_cta_img...
CVE-2026-16777MEDIUM4.9The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to...
CVE-2026-15275HIGH7.5The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_searc...
CVE-2026-15004MEDIUM5.4The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-14472MEDIUM6.4The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kubio/copyright Block Co...
CVE-2026-14323HIGH7.5The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in...
CVE-2026-13471MEDIUM4.3The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direc...
CVE-2026-12954HIGH8.8The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including...
CVE-2026-12739MEDIUM4.3The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypas...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now