2026 CVE Vulnerabilities
50,066 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1852 | MEDIUM | 6.1 | 0.1% | Apr 15, 2026 | The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u... |
| CVE-2026-40786 | MEDIUM | 4.3 | 0.1% | Apr 15, 2026 | Missing Authorization vulnerability in Long Watch Studio MyRewards woorewards allows Exploiting Incorrectly Configured A... |
| CVE-2026-40778 | MEDIUM | 5.3 | 0.2% | Apr 15, 2026 | Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly ... |
| CVE-2026-40763 | MEDIUM | 5.3 | 0.2% | Apr 15, 2026 | Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrec... |
| CVE-2026-40742 | MEDIUM | 5.3 | 0.2% | Apr 15, 2026 | Missing Authorization vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Exploiting Incorrectly Co... |
| CVE-2026-40740 | MEDIUM | 5.4 | 0.2% | Apr 15, 2026 | Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2026-40737 | MEDIUM | 5.3 | 0.2% | Apr 15, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in VillaTheme COMPE compe-woo-compare-products allows Exp... |
| CVE-2026-40734 | MEDIUM | 6.5 | 0.1% | Apr 15, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zahlan Categories ... |
| CVE-2026-40730 | MEDIUM | 5.3 | 0.2% | Apr 15, 2026 | Missing Authorization vulnerability in ThemeGrill ThemeGrill Demo Importer themegrill-demo-importer allows Exploiting In... |
| CVE-2026-40729 | MEDIUM | 4.3 | 0.1% | Apr 15, 2026 | Missing Authorization vulnerability in bPlugins 3D viewer – Embed 3D Models 3d-viewer allows Exploiting Incorrectly Conf... |
| CVE-2026-40728 | MEDIUM | 4.3 | 0.1% | Apr 15, 2026 | Missing Authorization vulnerability in BlockArt Magazine Blocks magazine-blocks allows Exploiting Incorrectly Configured... |
| CVE-2026-0636 | MEDIUM | 6.5 | 0.5% | Apr 15, 2026 | Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Boun... |
| CVE-2026-5717 | MEDIUM | 6.4 | 0.2% | Apr 15, 2026 | The VI: Include Post By plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_container' attr... |
| CVE-2026-4091 | MEDIUM | 6.1 | 0.2% | Apr 15, 2026 | The OPEN-BRAIN plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.... |
| CVE-2026-4011 | MEDIUM | 6.4 | 0.3% | Apr 15, 2026 | The Power Charts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [p... |
| CVE-2026-4005 | MEDIUM | 6.4 | 0.3% | Apr 15, 2026 | The Coachific Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userhash' shortcode a... |
| CVE-2026-4002 | MEDIUM | 4.3 | 0.2% | Apr 15, 2026 | The Petje.af plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 2.1.8.... |
| CVE-2026-3998 | MEDIUM | 6.4 | 0.3% | Apr 15, 2026 | The WM JqMath plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' shortcode attribute of t... |
| CVE-2026-3659 | MEDIUM | 6.4 | 0.3% | Apr 15, 2026 | The WP Circliful plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of t... |
| CVE-2026-3649 | MEDIUM | 5.3 | 0.3% | Apr 15, 2026 | The Katalogportal PDF Sync plugin for WordPress is vulnerable to Missing Authorization in all versions up to and includi... |
| CVE-2026-3642 | MEDIUM | 5.3 | 0.4% | Apr 15, 2026 | The e-shot™ form builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including... |
| CVE-2026-1782 | MEDIUM | 5.3 | 0.3% | Apr 15, 2026 | The MetForm Pro plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 3... |
| CVE-2026-6293 | MEDIUM | 4.3 | 0.2% | Apr 15, 2026 | The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cr... |
| CVE-2026-5160 | MEDIUM | 6.1 | 0.3% | Apr 15, 2026 | Versions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS... |
| CVE-2026-26291 | MEDIUM | 5.4 | 0.2% | Apr 15, 2026 | Stored cross-site scripting vulnerability exists in GROWI v7.4.6 and earlier. If this vulnerability is exploited, an arb... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now