2026 CVE Vulnerabilities

50,938 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-2838MEDIUM4.4The Whole Enquiry Cart for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘woowho...
CVE-2026-5083MEDIUM5.3Ado::Sessions versions through 0.935 for Perl generates insecure session ids. The session id is generated from a SHA-1 ...
CVE-2026-5082MEDIUM5.3Amon2::Plugin::Web::CSRFDefender versions from 7.00 through 7.03 for Perl generate an insecure session id. The generate...
CVE-2026-3311MEDIUM6.4The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for Wor...
CVE-2026-27787MEDIUM5.4Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier. If this vulnerability is exploited, an arbitr...
CVE-2026-4785MEDIUM6.4The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2026-4341MEDIUM6.4The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'follo...
CVE-2026-4333MEDIUM6.4The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skin' a...
CVE-2026-4299MEDIUM5.3The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including...
CVE-2026-3646MEDIUM5.3The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to Missing Authorization via the plugin...
CVE-2026-3600MEDIUM6.4The Investi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'investi-announcements-accordion' ...
CVE-2026-3513MEDIUM6.4The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2026-3239MEDIUM6.4The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonial_v...
CVE-2026-4379MEDIUM6.4The LightPress Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `group` attribute in t...
CVE-2026-2988MEDIUM6.4The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'powerpress' and 'podca...
CVE-2026-1163MEDIUM4.1An insufficient session expiration vulnerability exists in the latest version of parisneo/lollms. The application fails ...
CVE-2026-32289MEDIUM6.1Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi...
CVE-2026-32288MEDIUM5.5tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb...
CVE-2026-32282MEDIUM6.4On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope...
CVE-2026-4788MEDIUM5.5IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.37 stores sensitive information in log files that could be read by a loc...
CVE-2026-4406MEDIUM4.7The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in t...
CVE-2026-4401MEDIUM5.4The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bu...
CVE-2026-4394MEDIUM6.1The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Ty...
CVE-2026-2263MEDIUM5.3The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modific...
CVE-2026-39936MEDIUM6.9Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now