2026 CVE Vulnerabilities

50,938 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-39485MEDIUM4.3Missing Authorization vulnerability in embedplus Youtube Embed Plus youtube-embed-plus allows Exploiting Incorrectly Con...
CVE-2026-39484MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows Phis...
CVE-2026-39483MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidekazu Ishikawa ...
CVE-2026-39482MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Post ...
CVE-2026-39477MEDIUM4.3Missing Authorization vulnerability in Brainstorm Force CartFlows cartflows allows Exploiting Incorrectly Configured Acc...
CVE-2026-39476MEDIUM4.3Missing Authorization vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Exploiting Incorrectly Configu...
CVE-2026-39473MEDIUM5.3Insertion of Sensitive Information Into Sent Data vulnerability in Pär Thernström Simple History simple-history allows R...
CVE-2026-39469MEDIUM4.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Softaculous PageLayer pagela...
CVE-2026-39464MEDIUM5.5Server-Side Request Forgery (SSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by ...
CVE-2026-1396MEDIUM6.4The Magic Conversation For Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'magi...
CVE-2026-4655MEDIUM6.4The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG Imag...
CVE-2026-4654MEDIUM5.3The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object R...
CVE-2026-4330MEDIUM4.3The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass through u...
CVE-2026-5508MEDIUM6.4The WowPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wowpress` shortcode in ...
CVE-2026-5506MEDIUM6.4The Wavr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wave` shortcode in all vers...
CVE-2026-5169MEDIUM4.4The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Form Heade...
CVE-2026-5167MEDIUM5.3The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Authoriza...
CVE-2026-4871MEDIUM6.4The Sports Club Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before' and 'after...
CVE-2026-4141MEDIUM4.3The Quran Translations plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2026-3781MEDIUM5.4The Attendance Manager plugin for WordPress is vulnerable to SQL Injection via the 'attmgr_off' parameter in all version...
CVE-2026-3618MEDIUM6.4The Columns by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attr...
CVE-2026-3594MEDIUM5.3The Riaxe Product Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,...
CVE-2026-3480MEDIUM6.5The WP Blockade plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 0.9.14. ...
CVE-2026-3477MEDIUM5.3The PZ Frontend Manager plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including ...
CVE-2026-3142MEDIUM6.4The Pinterest Site Verification plugin using Meta Tag plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now