2026 CVE Vulnerabilities

46,973 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-8909MEDIUM4.3The WpMobi plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.3....
CVE-2026-8907MEDIUM6.1The WP-Ultimate-Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1...
CVE-2026-8904MEDIUM4.3The FastPicker, an order picker and order management system (oms) for WooCommerce on steroids plugin for WordPress is vu...
CVE-2026-8902MEDIUM4.3The AJAX Report Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2026-8895MEDIUM6.4The kk blog card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blog-card' shortcod...
CVE-2026-8883MEDIUM6.4The Global Body Mass Index Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gbmical...
CVE-2026-8882MEDIUM6.4The WP ApplicantStack Jobs Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attri...
CVE-2026-8880MEDIUM6.4The RomanCart Ecommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blclass' attribute (a...
CVE-2026-8841MEDIUM6.4The Extra Settings for RocketChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rocketchat'...
CVE-2026-8499MEDIUM5.3The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in ver...
CVE-2026-7662MEDIUM6.4The ePaperFlip Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'publicationid' attri...
CVE-2026-41980MEDIUM5.5Permission control vulnerability in the file preview module. Impact: Successful exploitation of this vulnerability may a...
CVE-2026-41979MEDIUM5.5Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect i...
CVE-2026-41978MEDIUM4.4Permission control vulnerability in the clone module. Impact: Successful exploitation of this vulnerability may affect s...
CVE-2026-41975MEDIUM6.3Permission management vulnerability in the network management module. Impact: Successful exploitation of this vulnerabil...
CVE-2026-41854MEDIUM6.5Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provid...
CVE-2026-41853MEDIUM5.3Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Fr...
CVE-2026-41852MEDIUM5.3A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocati...
CVE-2026-41847MEDIUM5.3Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions:...
CVE-2026-41846MEDIUM6.1Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP ...
CVE-2026-41845MEDIUM6.1Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the br...
CVE-2026-41844MEDIUM6.1A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly sp...
CVE-2026-41843MEDIUM5.9Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected ...
CVE-2026-41841MEDIUM5.9Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. A...
CVE-2026-41840MEDIUM5.9Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affect...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now