2026 CVE Vulnerabilities

50,066 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-1852MEDIUM6.1The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u...
CVE-2026-40786MEDIUM4.3Missing Authorization vulnerability in Long Watch Studio MyRewards woorewards allows Exploiting Incorrectly Configured A...
CVE-2026-40778MEDIUM5.3Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly ...
CVE-2026-40763MEDIUM5.3Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrec...
CVE-2026-40742MEDIUM5.3Missing Authorization vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Exploiting Incorrectly Co...
CVE-2026-40740MEDIUM5.4Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control S...
CVE-2026-40737MEDIUM5.3Authorization Bypass Through User-Controlled Key vulnerability in VillaTheme COMPE compe-woo-compare-products allows Exp...
CVE-2026-40734MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zahlan Categories ...
CVE-2026-40730MEDIUM5.3Missing Authorization vulnerability in ThemeGrill ThemeGrill Demo Importer themegrill-demo-importer allows Exploiting In...
CVE-2026-40729MEDIUM4.3Missing Authorization vulnerability in bPlugins 3D viewer – Embed 3D Models 3d-viewer allows Exploiting Incorrectly Conf...
CVE-2026-40728MEDIUM4.3Missing Authorization vulnerability in BlockArt Magazine Blocks magazine-blocks allows Exploiting Incorrectly Configured...
CVE-2026-0636MEDIUM6.5Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Boun...
CVE-2026-5717MEDIUM6.4The VI: Include Post By plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_container' attr...
CVE-2026-4091MEDIUM6.1The OPEN-BRAIN plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0....
CVE-2026-4011MEDIUM6.4The Power Charts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [p...
CVE-2026-4005MEDIUM6.4The Coachific Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userhash' shortcode a...
CVE-2026-4002MEDIUM4.3The Petje.af plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 2.1.8....
CVE-2026-3998MEDIUM6.4The WM JqMath plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' shortcode attribute of t...
CVE-2026-3659MEDIUM6.4The WP Circliful plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of t...
CVE-2026-3649MEDIUM5.3The Katalogportal PDF Sync plugin for WordPress is vulnerable to Missing Authorization in all versions up to and includi...
CVE-2026-3642MEDIUM5.3The e-shot™ form builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including...
CVE-2026-1782MEDIUM5.3The MetForm Pro plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 3...
CVE-2026-6293MEDIUM4.3The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cr...
CVE-2026-5160MEDIUM6.1Versions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS...
CVE-2026-26291MEDIUM5.4Stored cross-site scripting vulnerability exists in GROWI v7.4.6 and earlier. If this vulnerability is exploited, an arb...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now