2026 CVE Vulnerabilities
51,120 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4161 | MEDIUM | 4.4 | 0.3% | Mar 21, 2026 | The Review Map by RevuKangaroo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings... |
| CVE-2026-4143 | MEDIUM | 4.3 | 0.1% | Mar 21, 2026 | The Neos Connector for Fakturama plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to ... |
| CVE-2026-4127 | MEDIUM | 4.3 | 0.2% | Mar 21, 2026 | The Speedup Optimization plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including... |
| CVE-2026-4087 | MEDIUM | 6.5 | 0.3% | Mar 21, 2026 | The Pre* Party Resource Hints plugin for WordPress is vulnerable to SQL Injection via the 'hint_ids' parameter of the pp... |
| CVE-2026-4086 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The WP Random Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cat', 'nocat', and 'text... |
| CVE-2026-4084 | MEDIUM | 6.4 | 0.3% | Mar 21, 2026 | The fyyd podcast shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fyyd-podcast', 'f... |
| CVE-2026-4077 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Ecover Builder For Dummies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter ... |
| CVE-2026-4072 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The WordPress PayPal Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'donate' shortco... |
| CVE-2026-4069 | MEDIUM | 6.1 | 0.2% | Mar 21, 2026 | The Alfie – Feed Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'naam' parameter in al... |
| CVE-2026-4067 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Ad Short plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ad' shortcode's 'client' attribu... |
| CVE-2026-4022 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Show Posts list – Easy designs, filters and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2026-4004 | MEDIUM | 6.5 | 0.3% | Mar 21, 2026 | The Task Manager plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'search' AJAX action in all... |
| CVE-2026-3997 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Text Toggle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute of... |
| CVE-2026-3996 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The WP Games Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [game] shortcode in all ver... |
| CVE-2026-3651 | MEDIUM | 5.3 | 0.3% | Mar 21, 2026 | The Build App Online plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0... |
| CVE-2026-3645 | MEDIUM | 5.3 | 0.3% | Mar 21, 2026 | The Punnel – Landing Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and... |
| CVE-2026-3641 | MEDIUM | 5.3 | 0.3% | Mar 21, 2026 | The Appmax plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.0.3. ... |
| CVE-2026-3619 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Sheets2Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titles' shortcode attribute ... |
| CVE-2026-3617 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Paypal Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'amount' and 'name' short... |
| CVE-2026-3570 | MEDIUM | 5.3 | 0.3% | Mar 21, 2026 | The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.... |
| CVE-2026-3554 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Sherk Custom Post Type Displays plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' sh... |
| CVE-2026-3546 | MEDIUM | 5.3 | 0.2% | Mar 21, 2026 | The e-shot form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and ... |
| CVE-2026-3506 | MEDIUM | 5.3 | 0.3% | Mar 21, 2026 | The WP-Chatbot for Messenger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu... |
| CVE-2026-3460 | MEDIUM | 5.3 | 0.3% | Mar 21, 2026 | The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to... |
| CVE-2026-3354 | MEDIUM | 4.4 | 0.2% | Mar 21, 2026 | The Wikilookup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Popup Width' setting in all ve... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now