2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-15452MEDIUM4.7The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-Sit...
CVE-2026-0931MEDIUM6.9Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cau...
CVE-2026-7726MEDIUM6.5The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on...
CVE-2026-7441MEDIUM6.4The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute...
CVE-2026-7105MEDIUM4.3The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on...
CVE-2026-71212MEDIUM4.4xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py...
CVE-2026-71210MEDIUM5.3Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the r...
CVE-2026-71208MEDIUM6.5KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cl...
CVE-2026-71205MEDIUM6.5changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP ...
CVE-2026-71204MEDIUM6.2changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into...
CVE-2026-71203MEDIUM5.3changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-ke...
CVE-2026-6972MEDIUM6.4The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `chart_size` attribute of th...
CVE-2026-5651MEDIUM4.9The Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in multiple AJAX actions (a...
CVE-2026-5116MEDIUM4.4The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ver...
CVE-2026-5108MEDIUM4.4The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_setti...
CVE-2026-55998MEDIUM5.3The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid ...
CVE-2026-55996MEDIUM4.3A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent com...
CVE-2026-55747MEDIUM6.8The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir...
CVE-2026-17532MEDIUM6.1The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_p...
CVE-2026-17505MEDIUM6.1The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v...
CVE-2026-15281MEDIUM6.5The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the w...
CVE-2026-11977MEDIUM6.5The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to ...
CVE-2026-11969MEDIUM4.9The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Paramete...
CVE-2026-11920MEDIUM4.9The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL ...
CVE-2026-11454MEDIUM6.5The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now