2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-6236MEDIUM6.4The Posts map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' shortcode attribute in al...
CVE-2026-6041MEDIUM4.4The Buzz Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom Buzz Avatar' (buzz_c...
CVE-2026-5820MEDIUM6.4The Zypento Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table of Contents block in ...
CVE-2026-5767MEDIUM6.4The SlideShowPro SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `slideShowProSC` ...
CVE-2026-5748MEDIUM6.4The Text Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ts` shortcode in a...
CVE-2026-4353MEDIUM6.4The CI HUB Connector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the `ci...
CVE-2026-4280MEDIUM6.5The Breaking News WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1....
CVE-2026-4279MEDIUM6.4The Bread & Butter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'breadbutter-customevent-bu...
CVE-2026-4142MEDIUM4.4The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2026-4140MEDIUM4.3The Ni WooCommerce Order Export plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to a...
CVE-2026-4139MEDIUM4.3The mCatFilter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.5....
CVE-2026-4138MEDIUM4.3The DX Unanswered Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2026-4133MEDIUM4.3The TextP2P Texting Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and in...
CVE-2026-4131MEDIUM6.1The WP Responsive Popup + Optin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to a...
CVE-2026-4128MEDIUM4.3The TP Restore Categories And Taxonomies plugin for WordPress is vulnerable to Missing Authorization in all versions up ...
CVE-2026-4126MEDIUM4.3The Table Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2026-4125MEDIUM6.4The WPMK Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attribute in ...
CVE-2026-4121MEDIUM4.3The Kcaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.0.1....
CVE-2026-4118MEDIUM4.3The Call To Action Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2026-4117MEDIUM5.3The CalJ plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5. This is ...
CVE-2026-4090MEDIUM6.1The Inquiry Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2026-4089MEDIUM6.4The Twittee Text Tweet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribut...
CVE-2026-4088MEDIUM6.4The Switch CTA Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wppw_cta_box' shortcode in...
CVE-2026-4085MEDIUM6.4The Easy Social Photos Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wrapper_class'...
CVE-2026-4082MEDIUM6.4The ER Swiffy Insert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [swiffy] shortcode in all...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now