2026 CVE Vulnerabilities

51,132 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-3554MEDIUM6.4The Sherk Custom Post Type Displays plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' sh...
CVE-2026-3546MEDIUM5.3The e-shot form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and ...
CVE-2026-3506MEDIUM5.3The WP-Chatbot for Messenger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu...
CVE-2026-3460MEDIUM5.3The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to...
CVE-2026-3354MEDIUM4.4The Wikilookup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Popup Width' setting in all ve...
CVE-2026-3353MEDIUM4.4The Comment SPAM Wiper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'API Key' setting in al...
CVE-2026-3347MEDIUM5.5The Multi Functional Flexi Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `arv_lb[me...
CVE-2026-3335MEDIUM5.3The Canto plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1 via th...
CVE-2026-3333MEDIUM6.4The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linkgate' ...
CVE-2026-3332MEDIUM4.3The Xhanch - My Advanced Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to...
CVE-2026-3331MEDIUM4.3The Lobot Slider Administrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i...
CVE-2026-2837MEDIUM4.4The Ricerca – advanced search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settings in...
CVE-2026-2723MEDIUM6.1The Post Snippits plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2026-2720MEDIUM6.5The Hr Press Lite plugin for WordPress is vulnerable to unauthorized access of sensitive employee data due to a missing ...
CVE-2026-2503MEDIUM6.5The ElementCamp plugin for WordPress is vulnerable to time-based SQL Injection via the 'meta_query[compare]' parameter i...
CVE-2026-2501MEDIUM6.4The Ed's Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `social_share` ...
CVE-2026-2496MEDIUM6.4The Ed's Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `eds_font_aweso...
CVE-2026-2427MEDIUM6.1The itsukaita plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'day_from' and 'day_to' param...
CVE-2026-2424MEDIUM4.4The Reward Video Ad for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i...
CVE-2026-2375MEDIUM6.5The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Privilege Escalat...
CVE-2026-2351MEDIUM6.5The Task Manager plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.0.2 v...
CVE-2026-2294MEDIUM4.3The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthoriz...
CVE-2026-2277MEDIUM6.1The rexCrawler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' and 'regex' parameters...
CVE-2026-2121MEDIUM4.4The Weaver Show Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_class' parameter in...
CVE-2026-1935MEDIUM4.3The Company Posts for LinkedIn plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and in...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now