2026 CVE Vulnerabilities
48,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8898 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Events In City plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'org-events' shortcode in v... |
| CVE-2026-8897 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Shortcode Buddy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all ve... |
| CVE-2026-8894 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The iWR Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `iwrtooltip` shortcod... |
| CVE-2026-8891 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The BitForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bitform' shortcode in ve... |
| CVE-2026-8887 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Listen Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'listen' shortcode in ver... |
| CVE-2026-8886 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The hk_shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title-plane' shortcode in ve... |
| CVE-2026-8884 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Instant-Quote.co Quotation Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attr... |
| CVE-2026-8877 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Responsive Video Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rem_video' shor... |
| CVE-2026-8875 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Easy Prism Syntax Highlighter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'co... |
| CVE-2026-8873 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Content Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all ... |
| CVE-2026-8872 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Animate Your Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animation-s... |
| CVE-2026-8871 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Formidable Kinetic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'kinetic_link' shortcod... |
| CVE-2026-8870 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Team Master – A Modern WordPress Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2026-8869 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Mutual Funds Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attrib... |
| CVE-2026-8868 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Single Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'single-mailchimp' shortc... |
| CVE-2026-8867 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Post Category Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'postcatego... |
| CVE-2026-8866 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The jQuery googleslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'googleslides' shortco... |
| CVE-2026-8847 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Dideo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dideo' shortcode in versio... |
| CVE-2026-8846 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Tuxquote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'TUXQUOTE' shortcode in versions ... |
| CVE-2026-8845 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Islamic Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'islamicDB-roqya' shortco... |
| CVE-2026-8844 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Responsive Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rspcheck' shortcode in v... |
| CVE-2026-8842 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Google+ Link Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gplusnamelink' shortcod... |
| CVE-2026-8837 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'adi... |
| CVE-2026-8708 | MEDIUM | 4.3 | 0.1% | May 27, 2026 | The Genzel breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2026-8707 | MEDIUM | 6.1 | 0.2% | May 27, 2026 | The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF in all versi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now