2026 CVE Vulnerabilities

48,279 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-8837MEDIUM6.4The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'adi...
CVE-2026-8708MEDIUM4.3The Genzel breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2026-8707MEDIUM6.1The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF in all versi...
CVE-2026-8703MEDIUM6.4The Endless Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all ver...
CVE-2026-8702MEDIUM6.4The GBI To Print plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the 'div' attribut...
CVE-2026-8701MEDIUM6.4The GNTT Post Title Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the `tit...
CVE-2026-8698MEDIUM6.4The Cryptocurrency Prijsvergelijking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version...
CVE-2026-8048MEDIUM6.4The My Email Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subject' shortcode att...
CVE-2026-8040MEDIUM6.4The faq shortocde plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute ...
CVE-2026-7614MEDIUM4.3The Old Posts Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2026-9236MEDIUM4.3The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress is vulnerable to Cros...
CVE-2026-6287MEDIUM5.4The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2026-9022MEDIUM6.4The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in...
CVE-2026-48999MEDIUM5.7Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users a...
CVE-2026-2255MEDIUM4.3Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, e...
CVE-2026-2254MEDIUM6.3Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, d...
CVE-2026-9609MEDIUM4.7A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The ...
CVE-2026-7493MEDIUM5.3The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to den...
CVE-2026-6565MEDIUM6.4The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulner...
CVE-2026-9607MEDIUM6.3A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of ...
CVE-2026-8606MEDIUM5.9A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker t...
CVE-2026-9604MEDIUM4.3A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragMod...
CVE-2026-8647MEDIUM4.8Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available. ...
CVE-2026-46740MEDIUM5.3Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values w...
CVE-2026-9603MEDIUM6.5A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now