2026 CVE Vulnerabilities

65,524 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-96896HIGH7.2The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation c...
CVE-2026-96895MEDIUM6.8The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before output...
CVE-2026-92995MEDIUM5.3The Verge3D Publishing and E-Commerce WordPress plugin through 4.13.0 does not restrict access to a file-download handle...
CVE-2026-92436MEDIUM5.3The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication or verify ownership before loa...
CVE-2026-89006MEDIUM6.8The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it ...
CVE-2026-89003MEDIUM4.1The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user...
CVE-2026-89001MEDIUM4.9The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is per...
CVE-2026-89000MEDIUM4.1The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destin...
CVE-2026-86841MEDIUM4.7The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of u...
CVE-2026-86839LOW3.8The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and ...
CVE-2026-86609HIGH8.8The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked ...
CVE-2026-85002MEDIUM6.8The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an...
CVE-2026-84069MEDIUM5.3The WebFacing™ WordPress plugin before 5.4 does not restrict access to one of its bundled scripts and does not validate...
CVE-2026-82841MEDIUM5.3The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin ...
CVE-2026-81655HIGH7.5The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making ...
CVE-2026-100746HIGH7.3A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /web...
CVE-2026-100865HIGH8.8Heym before 0.0.53 evaluates workflow condition expressions using Python's eval() with insufficient sandboxing in the wo...
CVE-2026-100864HIGH8.8heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback re...
CVE-2026-100863MEDIUM5Heym versions 0.0.90 and earlier contain two server-side request forgery (SSRF) egress gaps, both remediated in app/serv...
CVE-2026-100862MEDIUM4.9heym, a workflow automation platform, stores and returns multiple capability secrets in plaintext in versions prior to 0...
CVE-2026-100861MEDIUM5heym before 0.0.105 fails to apply egress guards to integration services that use credential-supplied base URLs, allowin...
CVE-2026-100860MEDIUM5.5heym before 0.0.105 does not act on the result of the credential authorization lookup in the Redis workflow node (backen...
CVE-2026-100859MEDIUM6.5Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/test endpoint that all...
CVE-2026-100858MEDIUM6.8heym before 0.0.109 contains a server-side request forgery vulnerability in the Slack, Discord, and Crawler workflow nod...
CVE-2026-100857HIGH8AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now