2026 CVE Vulnerabilities

64,772 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-93983MEDIUM5OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users ...
CVE-2026-93981MEDIUM4.7hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a stri...
CVE-2026-9858MEDIUM4.3The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and ...
CVE-2026-9766MEDIUM4.3The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin...
CVE-2026-9613MEDIUM4.3The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all version...
CVE-2026-9289MEDIUM5.3The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi...
CVE-2026-8354MEDIUM6.4The Gum Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pop_tag' paramete...
CVE-2026-76579MEDIUM4.7The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all ...
CVE-2026-5410MEDIUM6.4The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions ...
CVE-2026-1256MEDIUM6.4The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple A...
CVE-2026-18346MEDIUM5.3The TikTok plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.1. This ...
CVE-2026-9855MEDIUM6.5The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the 'post_ID' parameter in all...
CVE-2026-9832MEDIUM5.3The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptograph...
CVE-2026-9615MEDIUM4.3The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. T...
CVE-2026-9232MEDIUM6.5The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in...
CVE-2026-87917MEDIUM6.1The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data' Dynam...
CVE-2026-7527MEDIUM4.7The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all version...
CVE-2026-75959MEDIUM4.9The GoPay for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'log_table_filter' paramet...
CVE-2026-6295MEDIUM4.9The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and inc...
CVE-2026-5400MEDIUM6.4The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media field filter values ...
CVE-2026-4792MEDIUM5.3The Bread plugin for WordPress is vulnerable to information exposure in versions up to and including 2.9.12. This is due...
CVE-2026-2422MEDIUM6.4The WP Composer – The Easiest Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pb...
CVE-2026-2278MEDIUM4.3The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch...
CVE-2026-1984MEDIUM5.3The Ibtana – Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a...
CVE-2026-1641MEDIUM6.5The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now