2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15452 | MEDIUM | 4.7 | 0.2% | Aug 5, 2026 | The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-Sit... |
| CVE-2026-0931 | MEDIUM | 6.9 | — | Aug 5, 2026 | Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cau... |
| CVE-2026-7726 | MEDIUM | 6.5 | 0.3% | Aug 5, 2026 | The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on... |
| CVE-2026-7441 | MEDIUM | 6.4 | 0.2% | Aug 5, 2026 | The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute... |
| CVE-2026-7105 | MEDIUM | 4.3 | 0.2% | Aug 5, 2026 | The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on... |
| CVE-2026-71212 | MEDIUM | 4.4 | 0.1% | Aug 5, 2026 | xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py... |
| CVE-2026-71210 | MEDIUM | 5.3 | 0.2% | Aug 5, 2026 | Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the r... |
| CVE-2026-71208 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cl... |
| CVE-2026-71205 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP ... |
| CVE-2026-71204 | MEDIUM | 6.2 | 0.2% | Aug 5, 2026 | changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into... |
| CVE-2026-71203 | MEDIUM | 5.3 | 0.2% | Aug 5, 2026 | changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-ke... |
| CVE-2026-6972 | MEDIUM | 6.4 | 0.2% | Aug 5, 2026 | The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `chart_size` attribute of th... |
| CVE-2026-5651 | MEDIUM | 4.9 | 0.4% | Aug 5, 2026 | The Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in multiple AJAX actions (a... |
| CVE-2026-5116 | MEDIUM | 4.4 | 0.3% | Aug 5, 2026 | The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ver... |
| CVE-2026-5108 | MEDIUM | 4.4 | 0.2% | Aug 5, 2026 | The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_setti... |
| CVE-2026-55998 | MEDIUM | 5.3 | — | Aug 5, 2026 | The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid ... |
| CVE-2026-55996 | MEDIUM | 4.3 | 0.1% | Aug 5, 2026 | A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent com... |
| CVE-2026-55747 | MEDIUM | 6.8 | 0.3% | Aug 5, 2026 | The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir... |
| CVE-2026-17532 | MEDIUM | 6.1 | 0.3% | Aug 5, 2026 | The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_p... |
| CVE-2026-17505 | MEDIUM | 6.1 | 0.8% | Aug 5, 2026 | The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v... |
| CVE-2026-15281 | MEDIUM | 6.5 | 0.3% | Aug 5, 2026 | The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the w... |
| CVE-2026-11977 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to ... |
| CVE-2026-11969 | MEDIUM | 4.9 | 0.3% | Aug 5, 2026 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Paramete... |
| CVE-2026-11920 | MEDIUM | 4.9 | 0.3% | Aug 5, 2026 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL ... |
| CVE-2026-11454 | MEDIUM | 6.5 | 0.4% | Aug 5, 2026 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now