2026 CVE Vulnerabilities
51,132 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3554 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Sherk Custom Post Type Displays plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' sh... |
| CVE-2026-3546 | MEDIUM | 5.3 | 0.2% | Mar 21, 2026 | The e-shot form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and ... |
| CVE-2026-3506 | MEDIUM | 5.3 | 0.3% | Mar 21, 2026 | The WP-Chatbot for Messenger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu... |
| CVE-2026-3460 | MEDIUM | 5.3 | 0.3% | Mar 21, 2026 | The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to... |
| CVE-2026-3354 | MEDIUM | 4.4 | 0.2% | Mar 21, 2026 | The Wikilookup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Popup Width' setting in all ve... |
| CVE-2026-3353 | MEDIUM | 4.4 | 0.2% | Mar 21, 2026 | The Comment SPAM Wiper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'API Key' setting in al... |
| CVE-2026-3347 | MEDIUM | 5.5 | 0.3% | Mar 21, 2026 | The Multi Functional Flexi Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `arv_lb[me... |
| CVE-2026-3335 | MEDIUM | 5.3 | 0.4% | Mar 21, 2026 | The Canto plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1 via th... |
| CVE-2026-3333 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linkgate' ... |
| CVE-2026-3332 | MEDIUM | 4.3 | 0.1% | Mar 21, 2026 | The Xhanch - My Advanced Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to... |
| CVE-2026-3331 | MEDIUM | 4.3 | 0.1% | Mar 21, 2026 | The Lobot Slider Administrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i... |
| CVE-2026-2837 | MEDIUM | 4.4 | 0.2% | Mar 21, 2026 | The Ricerca – advanced search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settings in... |
| CVE-2026-2723 | MEDIUM | 6.1 | 0.1% | Mar 21, 2026 | The Post Snippits plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2026-2720 | MEDIUM | 6.5 | 0.2% | Mar 21, 2026 | The Hr Press Lite plugin for WordPress is vulnerable to unauthorized access of sensitive employee data due to a missing ... |
| CVE-2026-2503 | MEDIUM | 6.5 | 0.2% | Mar 21, 2026 | The ElementCamp plugin for WordPress is vulnerable to time-based SQL Injection via the 'meta_query[compare]' parameter i... |
| CVE-2026-2501 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Ed's Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `social_share` ... |
| CVE-2026-2496 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Ed's Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `eds_font_aweso... |
| CVE-2026-2427 | MEDIUM | 6.1 | 0.3% | Mar 21, 2026 | The itsukaita plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'day_from' and 'day_to' param... |
| CVE-2026-2424 | MEDIUM | 4.4 | 0.2% | Mar 21, 2026 | The Reward Video Ad for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings i... |
| CVE-2026-2375 | MEDIUM | 6.5 | 0.3% | Mar 21, 2026 | The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Privilege Escalat... |
| CVE-2026-2351 | MEDIUM | 6.5 | 0.3% | Mar 21, 2026 | The Task Manager plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.0.2 v... |
| CVE-2026-2294 | MEDIUM | 4.3 | 0.2% | Mar 21, 2026 | The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthoriz... |
| CVE-2026-2277 | MEDIUM | 6.1 | 0.3% | Mar 21, 2026 | The rexCrawler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' and 'regex' parameters... |
| CVE-2026-2121 | MEDIUM | 4.4 | 0.2% | Mar 21, 2026 | The Weaver Show Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_class' parameter in... |
| CVE-2026-1935 | MEDIUM | 4.3 | 0.2% | Mar 21, 2026 | The Company Posts for LinkedIn plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and in... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now