2026 CVE Vulnerabilities
50,938 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2838 | MEDIUM | 4.4 | 0.2% | Apr 8, 2026 | The Whole Enquiry Cart for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘woowho... |
| CVE-2026-5083 | MEDIUM | 5.3 | 0.4% | Apr 8, 2026 | Ado::Sessions versions through 0.935 for Perl generates insecure session ids. The session id is generated from a SHA-1 ... |
| CVE-2026-5082 | MEDIUM | 5.3 | 0.4% | Apr 8, 2026 | Amon2::Plugin::Web::CSRFDefender versions from 7.00 through 7.03 for Perl generate an insecure session id. The generate... |
| CVE-2026-3311 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for Wor... |
| CVE-2026-27787 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier. If this vulnerability is exploited, an arbitr... |
| CVE-2026-4785 | MEDIUM | 6.4 | 0.4% | Apr 8, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2026-4341 | MEDIUM | 6.4 | 0.4% | Apr 8, 2026 | The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'follo... |
| CVE-2026-4333 | MEDIUM | 6.4 | 0.3% | Apr 8, 2026 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skin' a... |
| CVE-2026-4299 | MEDIUM | 5.3 | 0.5% | Apr 8, 2026 | The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including... |
| CVE-2026-3646 | MEDIUM | 5.3 | 0.4% | Apr 8, 2026 | The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to Missing Authorization via the plugin... |
| CVE-2026-3600 | MEDIUM | 6.4 | 0.3% | Apr 8, 2026 | The Investi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'investi-announcements-accordion' ... |
| CVE-2026-3513 | MEDIUM | 6.4 | 0.3% | Apr 8, 2026 | The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2026-3239 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonial_v... |
| CVE-2026-4379 | MEDIUM | 6.4 | 0.3% | Apr 8, 2026 | The LightPress Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `group` attribute in t... |
| CVE-2026-2988 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'powerpress' and 'podca... |
| CVE-2026-1163 | MEDIUM | 4.1 | 0.2% | Apr 8, 2026 | An insufficient session expiration vulnerability exists in the latest version of parisneo/lollms. The application fails ... |
| CVE-2026-32289 | MEDIUM | 6.1 | 0.3% | Apr 8, 2026 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi... |
| CVE-2026-32288 | MEDIUM | 5.5 | 0.3% | Apr 8, 2026 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb... |
| CVE-2026-32282 | MEDIUM | 6.4 | 0.3% | Apr 8, 2026 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope... |
| CVE-2026-4788 | MEDIUM | 5.5 | 0.1% | Apr 8, 2026 | IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.37 stores sensitive information in log files that could be read by a loc... |
| CVE-2026-4406 | MEDIUM | 4.7 | 0.4% | Apr 8, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in t... |
| CVE-2026-4401 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bu... |
| CVE-2026-4394 | MEDIUM | 6.1 | 0.3% | Apr 8, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Ty... |
| CVE-2026-2263 | MEDIUM | 5.3 | 0.4% | Apr 8, 2026 | The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modific... |
| CVE-2026-39936 | MEDIUM | 6.9 | 0.3% | Apr 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now