2026 CVE Vulnerabilities

45,447 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-42378MEDIUM6.5Subscriber Broken Authentication in WP Full Stripe Free <= 8.4.1 versions.
CVE-2026-41556MEDIUM6.5Subscriber Cross Site Scripting (XSS) in ProfilePress <= 4.16.13 versions.
CVE-2026-40799MEDIUM5.3Unauthenticated Broken Authentication in Simple Cloudflare Turnstile <= 1.38.0 versions.
CVE-2026-40796MEDIUM6.5Subscriber Sensitive Data Exposure in WPPizza <= 3.19.9 versions.
CVE-2026-40795MEDIUM6.5Subscriber Broken Access Control in Amelia <= 2.2 versions.
CVE-2026-40794MEDIUM6.5Subscriber Broken Access Control in myCred <= 3.0.3 versions.
CVE-2026-40793MEDIUM6.5Subscriber Broken Access Control in Groundhogg < 4.4.1 versions.
CVE-2026-40792MEDIUM6.3Subscriber Insecure Direct Object References (IDOR) in KiviCare <= 4.2.1 versions.
CVE-2026-40790MEDIUM6.5Subscriber Sensitive Data Exposure in WP SMS <= 7.2.1 versions.
CVE-2026-40782MEDIUM6.5Unauthenticated Broken Access Control in WPAdverts <= 2.3.0 versions.
CVE-2026-40773MEDIUM6.5Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 versions.
CVE-2026-40743MEDIUM6.5Unauthenticated Broken Access Control in Tutor LMS <= 3.9.7 versions.
CVE-2026-39594MEDIUM6.4Subscriber Broken Access Control in Ultra Addons for WPForms <= 1.0.11 versions.
CVE-2026-39584MEDIUM6.5Subscriber Broken Access Control in RepairBuddy <= 4.1132 versions.
CVE-2026-39540MEDIUM6.5Subscriber Cross Site Scripting (XSS) in Shipment Tracker for Woocommerce <= 1.5.3.2 versions.
CVE-2026-39527MEDIUM5.4Subscriber Arbitrary File Upload in WpStream < 4.11.2 versions.
CVE-2026-39525MEDIUM6.5Unauthenticated Broken Access Control in Booking Activities <= 1.16.48.1 versions.
CVE-2026-39515MEDIUM6.5Subscriber Broken Access Control in Motors < 1.4.107 versions.
CVE-2026-39491MEDIUM6.5Subscriber Cross Site Scripting (XSS) in JupiterX Core <= 4.14.1 versions.
CVE-2026-39489MEDIUM4.4Author Arbitrary File Download in Download Monitor <= 5.1.9 versions.
CVE-2026-39468MEDIUM6.8Contributor Arbitrary File Deletion in Meta Box – WordPress Custom Fields Framework <= 5.11.1 versions.
CVE-2026-39451MEDIUM6.3Unauthenticated Cross Site Scripting (XSS) in WP Google Review Slider <= 18.0 versions.
CVE-2026-34892MEDIUM6.5Subscriber Broken Access Control in Rank Math SEO <= 1.0.271 versions.
CVE-2026-25440MEDIUM5.3Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions.
CVE-2026-52721MEDIUM5.3Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trig...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now