2026 CVE Vulnerabilities
48,279 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8837 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'adi... |
| CVE-2026-8708 | MEDIUM | 4.3 | 0.1% | May 27, 2026 | The Genzel breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2026-8707 | MEDIUM | 6.1 | 0.2% | May 27, 2026 | The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF in all versi... |
| CVE-2026-8703 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Endless Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all ver... |
| CVE-2026-8702 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The GBI To Print plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the 'div' attribut... |
| CVE-2026-8701 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The GNTT Post Title Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the `tit... |
| CVE-2026-8698 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Cryptocurrency Prijsvergelijking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version... |
| CVE-2026-8048 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The My Email Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subject' shortcode att... |
| CVE-2026-8040 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The faq shortocde plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute ... |
| CVE-2026-7614 | MEDIUM | 4.3 | 0.1% | May 27, 2026 | The Old Posts Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2026-9236 | MEDIUM | 4.3 | 0.1% | May 27, 2026 | The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress is vulnerable to Cros... |
| CVE-2026-6287 | MEDIUM | 5.4 | 0.2% | May 27, 2026 | The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2026-9022 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in... |
| CVE-2026-48999 | MEDIUM | 5.7 | 0.2% | May 27, 2026 | Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users a... |
| CVE-2026-2255 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, e... |
| CVE-2026-2254 | MEDIUM | 6.3 | 0.2% | May 27, 2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, d... |
| CVE-2026-9609 | MEDIUM | 4.7 | 0.2% | May 27, 2026 | A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The ... |
| CVE-2026-7493 | MEDIUM | 5.3 | 0.4% | May 27, 2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to den... |
| CVE-2026-6565 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulner... |
| CVE-2026-9607 | MEDIUM | 6.3 | 0.2% | May 27, 2026 | A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of ... |
| CVE-2026-8606 | MEDIUM | 5.9 | 0.4% | May 27, 2026 | A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker t... |
| CVE-2026-9604 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragMod... |
| CVE-2026-8647 | MEDIUM | 4.8 | 0.2% | May 26, 2026 | Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available. ... |
| CVE-2026-46740 | MEDIUM | 5.3 | 0.3% | May 26, 2026 | Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values w... |
| CVE-2026-9603 | MEDIUM | 6.5 | 0.3% | May 26, 2026 | A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now