2026 CVE Vulnerabilities
51,132 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1914 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fusedesk_newcase shortco... |
| CVE-2026-1911 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tweet_title' parameter in t... |
| CVE-2026-1908 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Integration with Hubspot Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hubspotfor... |
| CVE-2026-1899 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Any Post Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aps_slider shortc... |
| CVE-2026-1891 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Simple Football Scoreboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ytmr_fb_scoreb... |
| CVE-2026-1889 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Outgrow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the 'outgrow' sh... |
| CVE-2026-1886 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Go Night Pro | WordPress Dark Mode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'... |
| CVE-2026-1854 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Post Flagger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'flag' shortcode in ... |
| CVE-2026-1851 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The iVysilani Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' shortcode attr... |
| CVE-2026-1822 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The WP NG Weather plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ng-weather' shortc... |
| CVE-2026-1806 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Tour & Activity Operator Plugin for TourCMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2026-1647 | MEDIUM | 6.1 | 0.3% | Mar 21, 2026 | The Comment Genius plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` p... |
| CVE-2026-1575 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Schema Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `itemscope` shor... |
| CVE-2026-1503 | MEDIUM | 4.3 | 0.1% | Mar 21, 2026 | The login_register plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in al... |
| CVE-2026-1397 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The PQ Addons – Creative Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget ... |
| CVE-2026-1393 | MEDIUM | 4.3 | 0.1% | Mar 21, 2026 | The Add Google Social Profiles to Knowledge Graph Box plugin for WordPress is vulnerable to Cross-Site Request Forgery i... |
| CVE-2026-1392 | MEDIUM | 4.3 | 0.1% | Mar 21, 2026 | The SR WP Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2026-1390 | MEDIUM | 4.3 | 0.1% | Mar 21, 2026 | The Redirect countdown plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2026-1378 | MEDIUM | 4.3 | 0.1% | Mar 21, 2026 | The WP Posts Re-order plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2026-1278 | MEDIUM | 4.4 | 0.2% | Mar 21, 2026 | The Mandatory Field plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions... |
| CVE-2026-1275 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Multi Post Carousel by Category plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slides' s... |
| CVE-2026-1253 | MEDIUM | 4.3 | 0.3% | Mar 21, 2026 | The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to unauthorized modification of data due to a... |
| CVE-2026-1247 | MEDIUM | 4.4 | 0.2% | Mar 21, 2026 | The Survey plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, a... |
| CVE-2026-1093 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The WPFAQBlock– FAQ & Accordion Plugin For Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2026-0609 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin plugin for WordPress is vulnerable to Stored ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now