2026 CVE Vulnerabilities
51,445 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32435 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in vowelweb VW Pet Shop vw-pet-shop allows Exploiting Incorrectly Configured Access ... |
| CVE-2026-32434 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in vowelweb VW Fitness vw-fitness allows Exploiting Incorrectly Configured Access Co... |
| CVE-2026-32432 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allows Exploitin... |
| CVE-2026-32431 | MEDIUM | 6.5 | 0.2% | Mar 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force A... |
| CVE-2026-32430 | MEDIUM | 6.5 | 0.2% | Mar 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IdeaBox Creations ... |
| CVE-2026-32429 | MEDIUM | 6.5 | 0.2% | Mar 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical ... |
| CVE-2026-32428 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in Ays Pro Popup Like box ays-facebook-popup-likebox allows Exploiting Incorrectly C... |
| CVE-2026-32427 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in vowelweb VW Education Lite vw-education-lite allows Exploiting Incorrectly Config... |
| CVE-2026-32425 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in linknacional Payment Gateway Pix For GiveWP payment-gateway-pix-for-givewp allows... |
| CVE-2026-32424 | MEDIUM | 6.5 | 0.2% | Mar 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Sprout Cl... |
| CVE-2026-32423 | MEDIUM | 5.4 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Exploiting ... |
| CVE-2026-32421 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in Agile Logix Post Timeline post-timeline allows Exploiting Incorrectly Configured ... |
| CVE-2026-32420 | MEDIUM | 5.4 | 0.1% | Mar 13, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ruben Garcia GamiPress gamipress allows Cross Site Request Forgery.Th... |
| CVE-2026-32419 | MEDIUM | 5.9 | 0.2% | Mar 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fernando Briano Li... |
| CVE-2026-32417 | MEDIUM | 5.4 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in wppochipp Pochipp pochipp allows Exploiting Incorrectly Configured Access Control... |
| CVE-2026-32416 | MEDIUM | 5.4 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in bPlugins PDF Poster pdf-poster allows Exploiting Incorrectly Configured Access Co... |
| CVE-2026-32415 | MEDIUM | 5 | 0.3% | Mar 13, 2026 | Path Traversal: '.../...//' vulnerability in Bogdan Bendziukov Squeeze squeeze allows Path Traversal.This issue affects ... |
| CVE-2026-32413 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in Maciej Bis Permalink Manager Lite permalink-manager allows Exploiting Incorrectly... |
| CVE-2026-32412 | MEDIUM | 5.4 | 0.2% | Mar 13, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Gift Up! Gift Up Gift Cards for WordPress and WooCommerce gift-up al... |
| CVE-2026-32411 | MEDIUM | 6.5 | 0.2% | Mar 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simpma Embed Calen... |
| CVE-2026-32410 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in WBW Plugins WBW Currency Switcher for WooCommerce woo-currency allows Exploiting ... |
| CVE-2026-32409 | MEDIUM | 5.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows Exploi... |
| CVE-2026-32408 | MEDIUM | 4.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in themefusecom Brizy brizy allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2026-32407 | MEDIUM | 4.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in WPClever WPC Smart Wishlist for WooCommerce woo-smart-wishlist allows Exploiting ... |
| CVE-2026-32406 | MEDIUM | 4.3 | 0.2% | Mar 13, 2026 | Missing Authorization vulnerability in WPClever WPC Product Bundles for WooCommerce woo-product-bundle allows Exploiting... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now