2026 CVE Vulnerabilities

51,120 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-4161MEDIUM4.4The Review Map by RevuKangaroo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings...
CVE-2026-4143MEDIUM4.3The Neos Connector for Fakturama plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to ...
CVE-2026-4127MEDIUM4.3The Speedup Optimization plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including...
CVE-2026-4087MEDIUM6.5The Pre* Party Resource Hints plugin for WordPress is vulnerable to SQL Injection via the 'hint_ids' parameter of the pp...
CVE-2026-4086MEDIUM6.4The WP Random Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cat', 'nocat', and 'text...
CVE-2026-4084MEDIUM6.4The fyyd podcast shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fyyd-podcast', 'f...
CVE-2026-4077MEDIUM6.4The Ecover Builder For Dummies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter ...
CVE-2026-4072MEDIUM6.4The WordPress PayPal Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'donate' shortco...
CVE-2026-4069MEDIUM6.1The Alfie – Feed Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'naam' parameter in al...
CVE-2026-4067MEDIUM6.4The Ad Short plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ad' shortcode's 'client' attribu...
CVE-2026-4022MEDIUM6.4The Show Posts list – Easy designs, filters and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2026-4004MEDIUM6.5The Task Manager plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'search' AJAX action in all...
CVE-2026-3997MEDIUM6.4The Text Toggle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute of...
CVE-2026-3996MEDIUM6.4The WP Games Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [game] shortcode in all ver...
CVE-2026-3651MEDIUM5.3The Build App Online plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0...
CVE-2026-3645MEDIUM5.3The Punnel – Landing Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and...
CVE-2026-3641MEDIUM5.3The Appmax plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.0.3. ...
CVE-2026-3619MEDIUM6.4The Sheets2Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titles' shortcode attribute ...
CVE-2026-3617MEDIUM6.4The Paypal Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'amount' and 'name' short...
CVE-2026-3570MEDIUM5.3The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2....
CVE-2026-3554MEDIUM6.4The Sherk Custom Post Type Displays plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' sh...
CVE-2026-3546MEDIUM5.3The e-shot form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and ...
CVE-2026-3506MEDIUM5.3The WP-Chatbot for Messenger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu...
CVE-2026-3460MEDIUM5.3The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to...
CVE-2026-3354MEDIUM4.4The Wikilookup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Popup Width' setting in all ve...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now