2026 CVE Vulnerabilities

48,925 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28179MEDIUM5.9Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.
CVE-2026-28178MEDIUM6.5Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
CVE-2026-28177HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
CVE-2026-28172HIGH7.1Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
CVE-2026-28169MEDIUM5.3Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.
CVE-2026-28146MEDIUM6.5Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 vers...
CVE-2026-28143HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
CVE-2026-28141HIGH7.1Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
CVE-2026-28140HIGH7.5Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
CVE-2026-28139CRITICAL9.8Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
CVE-2026-28111HIGH8.8Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
CVE-2026-28082HIGH7.1Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
CVE-2026-28005CRITICAL9.8Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
CVE-2026-25403MEDIUM6.5Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
CVE-2026-19045MEDIUM5.3A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog...
CVE-2026-19044MEDIUM5.3A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of...
CVE-2026-15246MEDIUM4.3The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, no...
CVE-2026-64993CRITICAL9.1Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remo...
CVE-2026-5134CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Info...
CVE-2026-19041MEDIUM6.3A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageSe...
CVE-2026-19040MEDIUM6.3A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/...
CVE-2026-18501MEDIUM6.4The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre...
CVE-2026-16731HIGH8.3OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authe...
CVE-2026-16316MEDIUM4.3OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame...
CVE-2026-16315HIGH8.7OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authe...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now