2026 CVE Vulnerabilities

47,533 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-9280MEDIUM6.1The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL ...
CVE-2026-9197MEDIUM4.9The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1...
CVE-2026-8991MEDIUM4.4The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Script...
CVE-2026-8978MEDIUM4.9The OptinCraft – Drag & Drop Optins & Popup Builder for WordPress plugin for WordPress is vulnerable to generic SQL Inje...
CVE-2026-8502MEDIUM5.3The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive...
CVE-2026-7796MEDIUM6.4The EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more plugin for WordPress i...
CVE-2026-7795MEDIUM6.4The Click to Chat – WA Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [chat] shortcode...
CVE-2026-7792MEDIUM5.3The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vu...
CVE-2026-7665MEDIUM5.3The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Informa...
CVE-2026-7566MEDIUM6.6The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up t...
CVE-2026-7565MEDIUM4.9The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Travers...
CVE-2026-2500MEDIUM4.4The Quick Playground plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.4. T...
CVE-2026-9281MEDIUM6.4The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPress...
CVE-2026-9008MEDIUM4.3The Page-list plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.2. Thi...
CVE-2026-9719MEDIUM4.3The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Req...
CVE-2026-8976MEDIUM4.3The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is...
CVE-2026-8900MEDIUM6.4The Simple SEO Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in a...
CVE-2026-8893MEDIUM6.4The Express Payment For Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribut...
CVE-2026-8608MEDIUM5.3The Event Monster – Event Management, Events Calendar, Tickets plugin for WordPress is vulnerable to Insufficient Verifi...
CVE-2026-7047MEDIUM4.3The Frontend User Notes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2026-6448MEDIUM4.9The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL...
CVE-2026-6242MEDIUM6.8An authenticated format string vulnerability exists in the ONVIF Subscribe service in Tapo C520WS v2 due to improper han...
CVE-2026-6241MEDIUM6.8An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled ...
CVE-2026-6240MEDIUM6.8A stack-based buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF DeleteUsers service, due to insufficie...
CVE-2026-6239MEDIUM6.8A stack‑based buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF CreateUsers service, where the device ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now