2026 CVE Vulnerabilities
50,937 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39566 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Designinvento DirectoryPress... |
| CVE-2026-39565 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Exploiting Incorrectly Conf... |
| CVE-2026-39564 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-... |
| CVE-2026-39563 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in ILLID Share This Image share-this-image allows Exploiting Incorrectly Configured ... |
| CVE-2026-39562 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting In... |
| CVE-2026-39561 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in WP Chill Revive.so revive-so allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2026-39543 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2026-39542 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Doofinder Doofinder for WooCommerce doofinder-for-woo... |
| CVE-2026-39541 | MEDIUM | 5.9 | 0.2% | Apr 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Boo... |
| CVE-2026-39536 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Chill RSVP and Event Mana... |
| CVE-2026-39535 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in fullworks Display Eventbrite Events widget-for-eventbrite-api allows Exploiting I... |
| CVE-2026-39528 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in WP Delicious WP Delicious delicious-recipes allows Exploiting Incorrectly Configu... |
| CVE-2026-39526 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in wpstream WpStream wpstream allows Exploiting Incorrect... |
| CVE-2026-39521 | MEDIUM | 4.9 | 0.1% | Apr 8, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Nelio Software Nelio Content nelio-content allows Server Side Reques... |
| CVE-2026-39520 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in weDevs weDocs wedocs allows Exploiting Incorrectly Configured Access Control Secu... |
| CVE-2026-39517 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Blog Fil... |
| CVE-2026-39516 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in POSIMYTH Nexter Blocks the-p... |
| CVE-2026-39509 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Con... |
| CVE-2026-39508 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Kohlbach Adva... |
| CVE-2026-39506 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in Jordy Meow AI Engine (Pro) ai-engine-pro allows Exploiting Incorrectly Configured... |
| CVE-2026-39505 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Explo... |
| CVE-2026-39504 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured ... |
| CVE-2026-39501 | MEDIUM | 5.3 | 0.3% | Apr 8, 2026 | Missing Authorization vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Exploiting Incorrectly Config... |
| CVE-2026-39500 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesflat themesf... |
| CVE-2026-39488 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in SureCart SureCart surecart allows Exploiting Incorrectly Configured Access Contro... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now