2026 CVE Vulnerabilities
49,638 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6236 | MEDIUM | 6.4 | 0.2% | Apr 22, 2026 | The Posts map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' shortcode attribute in al... |
| CVE-2026-6041 | MEDIUM | 4.4 | 0.3% | Apr 22, 2026 | The Buzz Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom Buzz Avatar' (buzz_c... |
| CVE-2026-5820 | MEDIUM | 6.4 | 0.2% | Apr 22, 2026 | The Zypento Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table of Contents block in ... |
| CVE-2026-5767 | MEDIUM | 6.4 | 0.2% | Apr 22, 2026 | The SlideShowPro SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `slideShowProSC` ... |
| CVE-2026-5748 | MEDIUM | 6.4 | 0.2% | Apr 22, 2026 | The Text Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ts` shortcode in a... |
| CVE-2026-4353 | MEDIUM | 6.4 | 0.2% | Apr 22, 2026 | The CI HUB Connector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the `ci... |
| CVE-2026-4280 | MEDIUM | 6.5 | 0.8% | Apr 22, 2026 | The Breaking News WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.... |
| CVE-2026-4279 | MEDIUM | 6.4 | 0.2% | Apr 22, 2026 | The Bread & Butter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'breadbutter-customevent-bu... |
| CVE-2026-4142 | MEDIUM | 4.4 | 0.3% | Apr 22, 2026 | The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2026-4140 | MEDIUM | 4.3 | 0.2% | Apr 22, 2026 | The Ni WooCommerce Order Export plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to a... |
| CVE-2026-4139 | MEDIUM | 4.3 | 0.2% | Apr 22, 2026 | The mCatFilter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.5.... |
| CVE-2026-4138 | MEDIUM | 4.3 | 0.2% | Apr 22, 2026 | The DX Unanswered Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2026-4133 | MEDIUM | 4.3 | 0.2% | Apr 22, 2026 | The TextP2P Texting Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and in... |
| CVE-2026-4131 | MEDIUM | 6.1 | 0.2% | Apr 22, 2026 | The WP Responsive Popup + Optin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to a... |
| CVE-2026-4128 | MEDIUM | 4.3 | 0.2% | Apr 22, 2026 | The TP Restore Categories And Taxonomies plugin for WordPress is vulnerable to Missing Authorization in all versions up ... |
| CVE-2026-4126 | MEDIUM | 4.3 | 0.3% | Apr 22, 2026 | The Table Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2026-4125 | MEDIUM | 6.4 | 0.3% | Apr 22, 2026 | The WPMK Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attribute in ... |
| CVE-2026-4121 | MEDIUM | 4.3 | 0.2% | Apr 22, 2026 | The Kcaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.0.1.... |
| CVE-2026-4118 | MEDIUM | 4.3 | 0.2% | Apr 22, 2026 | The Call To Action Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2026-4117 | MEDIUM | 5.3 | 0.4% | Apr 22, 2026 | The CalJ plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5. This is ... |
| CVE-2026-4090 | MEDIUM | 6.1 | 0.2% | Apr 22, 2026 | The Inquiry Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2026-4089 | MEDIUM | 6.4 | 0.3% | Apr 22, 2026 | The Twittee Text Tweet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribut... |
| CVE-2026-4088 | MEDIUM | 6.4 | 0.4% | Apr 22, 2026 | The Switch CTA Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wppw_cta_box' shortcode in... |
| CVE-2026-4085 | MEDIUM | 6.4 | 0.3% | Apr 22, 2026 | The Easy Social Photos Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wrapper_class'... |
| CVE-2026-4082 | MEDIUM | 6.4 | 0.3% | Apr 22, 2026 | The ER Swiffy Insert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [swiffy] shortcode in all... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now