2026 CVE Vulnerabilities

48,064 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-9807MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.10.7, 18.11 before 18.11.4, an...
CVE-2026-9015MEDIUM4.3The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl...
CVE-2026-8689MEDIUM4.3The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Missing Authorization in a...
CVE-2026-7526MEDIUM4.3The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi...
CVE-2026-7048MEDIUM6.5The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based blind SQL In...
CVE-2026-6937MEDIUM5.3The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Mis...
CVE-2026-4334MEDIUM6.4The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headline' parameter in th...
CVE-2026-9806MEDIUM6.3A stored cross-site scripting (XSS) vulnerability exists in the notification panel of CTI Transmute in versions prior to...
CVE-2026-9618MEDIUM4.3The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) plugin ...
CVE-2026-8682MEDIUM4.3The 3D Viewer – 3D Model Viewer – Augmented Reality – Virtual Try On plugin for WordPress is vulnerable to authorization...
CVE-2026-7660MEDIUM6.1The Easy Updates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter ...
CVE-2026-7651MEDIUM5.3The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom U...
CVE-2026-7621MEDIUM4.3The SMTP2GO for WordPress – Email Made Easy plugin for WordPress is vulnerable to unauthorized access in all versions up...
CVE-2026-7552MEDIUM5.3The Geo Mashup plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.13.19....
CVE-2026-6427MEDIUM6.4The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,...
CVE-2026-9803MEDIUM5.3A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vuln...
CVE-2026-9802MEDIUM6.8A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server...
CVE-2026-9801MEDIUM4.9A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malici...
CVE-2026-9798MEDIUM4.3A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily...
CVE-2026-9673MEDIUM6.8Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjec...
CVE-2026-9644MEDIUM6.4The LiveSmart Video Chat Live Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2026-7533MEDIUM4.3The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2026-3173MEDIUM6.5The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i...
CVE-2026-9796MEDIUM6.5A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check ...
CVE-2026-9794MEDIUM5.3A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially cra...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now