2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-14870HIGH7.1The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and e...
CVE-2026-14821LOW2.7The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting out...
CVE-2026-14819LOW3.5The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputtin...
CVE-2026-14545CRITICAL9.8The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password throu...
CVE-2026-14490HIGH7.5The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory D...
CVE-2026-12124MEDIUM5.3The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for Word...
CVE-2026-17528MEDIUM6.1Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the <select> element....
CVE-2026-17524HIGH8.7Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path va...
CVE-2026-66473HIGH7.5Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
CVE-2026-65448MEDIUM6.5Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner &#8211; AcyChecker <= 1.8.1 versions.
CVE-2026-65447HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
CVE-2026-65446HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
CVE-2026-65445MEDIUM6.5Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.
CVE-2026-65443HIGH7.1Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
CVE-2026-65442HIGH7.2Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
CVE-2026-65441HIGH7.1Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.
CVE-2026-65440HIGH7.1Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.
CVE-2026-65439HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.
CVE-2026-65438HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.
CVE-2026-65437HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.
CVE-2026-61957HIGH7.1Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
CVE-2026-61953HIGH7.2Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
CVE-2026-51565MEDIUM6.1Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attacker...
CVE-2026-59240MEDIUM6.9The vulnerability involves an Insecure Direct Object Reference (IDOR) in the `DeleteNotificationController::delete()` me...
CVE-2026-55685HIGH7.5React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauth...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now