2026 CVE Vulnerabilities

68,114 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-85652MEDIUM6.5The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injectio...
CVE-2026-75961MEDIUM4.9The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the ...
CVE-2026-75157HIGH7.5Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `E...
CVE-2026-67103HIGH7.6HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to ...
CVE-2026-67102HIGH8.1HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a lo...
CVE-2026-67101CRITICAL9.3HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functional...
CVE-2026-67100CRITICAL9.8HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. w...
CVE-2026-18442HIGH7.5The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injecti...
CVE-2026-17607MEDIUM6.5The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the ...
CVE-2026-17586MEDIUM6.4The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vkExUnit_cta_img...
CVE-2026-16777MEDIUM4.9The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to...
CVE-2026-15275HIGH7.5The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_searc...
CVE-2026-15004MEDIUM5.4The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-14472MEDIUM6.4The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kubio/copyright Block Co...
CVE-2026-14323HIGH7.5The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in...
CVE-2026-13471MEDIUM4.3The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direc...
CVE-2026-12954HIGH8.8The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including...
CVE-2026-12739MEDIUM4.3The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypas...
CVE-2026-12384HIGH8.8Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse. ...
CVE-2026-11757MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Tec...
CVE-2026-92714MEDIUM6.5The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and inclu...
CVE-2026-92619HIGH7.2The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11...
CVE-2026-92561MEDIUM6.1The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in...
CVE-2026-91707MEDIUM5.3The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5....
CVE-2026-90977MEDIUM5.3The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is e...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now