2026 CVE Vulnerabilities
48,366 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5075 | MEDIUM | 4.3 | 0.3% | May 20, 2026 | The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'internalOptions' localized ... |
| CVE-2026-8685 | MEDIUM | 6.5 | 0.4% | May 20, 2026 | The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order' parameters in all ... |
| CVE-2026-8627 | MEDIUM | 6.1 | 0.2% | May 20, 2026 | The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] var... |
| CVE-2026-8626 | MEDIUM | 6.1 | 0.3% | May 20, 2026 | The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all version... |
| CVE-2026-8624 | MEDIUM | 6.1 | 0.3% | May 20, 2026 | The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Param... |
| CVE-2026-8610 | MEDIUM | 4.3 | 0.3% | May 20, 2026 | The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all versions up to, and... |
| CVE-2026-8424 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | The Remove Yellow BGBOX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2026-8423 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | The JaviBola Custom Theme Test plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a... |
| CVE-2026-8420 | MEDIUM | 6.1 | 0.2% | May 20, 2026 | The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2026-8419 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | The Amazon Scraper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2026-8418 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | The Games Catalog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2... |
| CVE-2026-8038 | MEDIUM | 6.4 | 0.2% | May 20, 2026 | The Faces of Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribu... |
| CVE-2026-7472 | MEDIUM | 4.9 | 0.4% | May 20, 2026 | The Read More & Accordion plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' paramet... |
| CVE-2026-7462 | MEDIUM | 6.1 | 0.3% | May 20, 2026 | The VatanSMS WP SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` parameter in all... |
| CVE-2026-6549 | MEDIUM | 6.4 | 0.2% | May 20, 2026 | The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute ... |
| CVE-2026-6452 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | The Bigfishgames Syndicate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2026-6404 | MEDIUM | 4.4 | 0.2% | May 20, 2026 | The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2026-6401 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | The Bottom Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.1.... |
| CVE-2026-6400 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions... |
| CVE-2026-6399 | MEDIUM | 4.4 | 0.2% | May 20, 2026 | The General Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.... |
| CVE-2026-6397 | MEDIUM | 6.4 | 0.2% | May 20, 2026 | The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `cvmh-sticky` shortcode `readmorete... |
| CVE-2026-6395 | MEDIUM | 6.1 | 0.2% | May 20, 2026 | The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting ... |
| CVE-2026-6394 | MEDIUM | 5.4 | 0.3% | May 20, 2026 | The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server... |
| CVE-2026-6391 | MEDIUM | 6.1 | 0.2% | May 20, 2026 | The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in... |
| CVE-2026-6072 | MEDIUM | 6.5 | 0.5% | May 20, 2026 | The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorization Bypass Through Us... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now