2026 CVE Vulnerabilities
48,064 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9807 | MEDIUM | 4.3 | 0.2% | May 28, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.10.7, 18.11 before 18.11.4, an... |
| CVE-2026-9015 | MEDIUM | 4.3 | 0.3% | May 28, 2026 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl... |
| CVE-2026-8689 | MEDIUM | 4.3 | 0.2% | May 28, 2026 | The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Missing Authorization in a... |
| CVE-2026-7526 | MEDIUM | 4.3 | 0.4% | May 28, 2026 | The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi... |
| CVE-2026-7048 | MEDIUM | 6.5 | 0.5% | May 28, 2026 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based blind SQL In... |
| CVE-2026-6937 | MEDIUM | 5.3 | 0.6% | May 28, 2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Mis... |
| CVE-2026-4334 | MEDIUM | 6.4 | 0.2% | May 28, 2026 | The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headline' parameter in th... |
| CVE-2026-9806 | MEDIUM | 6.3 | 0.3% | May 28, 2026 | A stored cross-site scripting (XSS) vulnerability exists in the notification panel of CTI Transmute in versions prior to... |
| CVE-2026-9618 | MEDIUM | 4.3 | 0.1% | May 28, 2026 | The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) plugin ... |
| CVE-2026-8682 | MEDIUM | 4.3 | 0.2% | May 28, 2026 | The 3D Viewer – 3D Model Viewer – Augmented Reality – Virtual Try On plugin for WordPress is vulnerable to authorization... |
| CVE-2026-7660 | MEDIUM | 6.1 | 0.2% | May 28, 2026 | The Easy Updates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter ... |
| CVE-2026-7651 | MEDIUM | 5.3 | 0.4% | May 28, 2026 | The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom U... |
| CVE-2026-7621 | MEDIUM | 4.3 | 0.3% | May 28, 2026 | The SMTP2GO for WordPress – Email Made Easy plugin for WordPress is vulnerable to unauthorized access in all versions up... |
| CVE-2026-7552 | MEDIUM | 5.3 | 0.3% | May 28, 2026 | The Geo Mashup plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.13.19.... |
| CVE-2026-6427 | MEDIUM | 6.4 | 0.3% | May 28, 2026 | The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,... |
| CVE-2026-9803 | MEDIUM | 5.3 | 0.4% | May 28, 2026 | A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vuln... |
| CVE-2026-9802 | MEDIUM | 6.8 | 0.3% | May 28, 2026 | A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server... |
| CVE-2026-9801 | MEDIUM | 4.9 | 0.5% | May 28, 2026 | A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malici... |
| CVE-2026-9798 | MEDIUM | 4.3 | 0.3% | May 28, 2026 | A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily... |
| CVE-2026-9673 | MEDIUM | 6.8 | 0.2% | May 28, 2026 | Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjec... |
| CVE-2026-9644 | MEDIUM | 6.4 | 0.2% | May 28, 2026 | The LiveSmart Video Chat Live Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2026-7533 | MEDIUM | 4.3 | 0.1% | May 28, 2026 | The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2026-3173 | MEDIUM | 6.5 | 0.2% | May 28, 2026 | The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i... |
| CVE-2026-9796 | MEDIUM | 6.5 | 0.2% | May 28, 2026 | A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check ... |
| CVE-2026-9794 | MEDIUM | 5.3 | 0.3% | May 28, 2026 | A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially cra... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now