2026 CVE Vulnerabilities

48,366 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-5075MEDIUM4.3The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'internalOptions' localized ...
CVE-2026-8685MEDIUM6.5The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order' parameters in all ...
CVE-2026-8627MEDIUM6.1The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] var...
CVE-2026-8626MEDIUM6.1The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all version...
CVE-2026-8624MEDIUM6.1The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Param...
CVE-2026-8610MEDIUM4.3The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all versions up to, and...
CVE-2026-8424MEDIUM4.3The Remove Yellow BGBOX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2026-8423MEDIUM4.3The JaviBola Custom Theme Test plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2026-8420MEDIUM6.1The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2026-8419MEDIUM4.3The Amazon Scraper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2026-8418MEDIUM4.3The Games Catalog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2...
CVE-2026-8038MEDIUM6.4The Faces of Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribu...
CVE-2026-7472MEDIUM4.9The Read More & Accordion plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' paramet...
CVE-2026-7462MEDIUM6.1The VatanSMS WP SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` parameter in all...
CVE-2026-6549MEDIUM6.4The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute ...
CVE-2026-6452MEDIUM4.3The Bigfishgames Syndicate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2026-6404MEDIUM4.4The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2026-6401MEDIUM4.3The Bottom Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.1....
CVE-2026-6400MEDIUM4.3The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
CVE-2026-6399MEDIUM4.4The General Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1....
CVE-2026-6397MEDIUM6.4The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `cvmh-sticky` shortcode `readmorete...
CVE-2026-6395MEDIUM6.1The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting ...
CVE-2026-6394MEDIUM5.4The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server...
CVE-2026-6391MEDIUM6.1The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2026-6072MEDIUM6.5The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorization Bypass Through Us...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now