2026 CVE Vulnerabilities

67,696 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-12384HIGH8.8Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse. ...
CVE-2026-11757MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Tec...
CVE-2026-92714MEDIUM6.5The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and inclu...
CVE-2026-92619HIGH7.2The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11...
CVE-2026-92561MEDIUM6.1The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in...
CVE-2026-91707MEDIUM5.3The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5....
CVE-2026-90977MEDIUM5.3The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is e...
CVE-2026-90976MEDIUM5.3The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled before creating an acco...
CVE-2026-89413HIGH8.1The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1....
CVE-2026-89330MEDIUM6.1The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for ...
CVE-2026-89278MEDIUM5.3The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is v...
CVE-2026-89138MEDIUM4.3The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1....
CVE-2026-88994MEDIUM6.6The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a ...
CVE-2026-86800MEDIUM5.3The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before ...
CVE-2026-86796MEDIUM5.3The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request befo...
CVE-2026-84909MEDIUM6.4The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2026-79713MEDIUM6.5The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page-...
CVE-2026-75017MEDIUM4.3The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plu...
CVE-2026-75016MEDIUM6.4The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's client...
CVE-2026-18317MEDIUM4.3The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to a...
CVE-2026-17576MEDIUM6.5The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to,...
CVE-2026-12106MEDIUM6.4The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, ...
CVE-2026-93485HIGH7.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPre...
CVE-2026-90984MEDIUM5.8The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch...
CVE-2026-90978HIGH7.1The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonc...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now