2026 CVE Vulnerabilities

53,439 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15394MEDIUM6.4The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross...
CVE-2026-15348MEDIUM6.3The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all...
CVE-2026-15017HIGH8.8The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin...
CVE-2026-15015CRITICAL9.8The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions u...
CVE-2026-15011CRITICAL9.8The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parame...
CVE-2026-14481MEDIUM6.4The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl...
CVE-2026-14282CRITICAL9.8The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for ...
CVE-2026-13119MEDIUM6.5The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'stan...
CVE-2026-13009MEDIUM6.5The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Param...
CVE-2026-52688HIGH7.5RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
CVE-2026-52686LOW3.7The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signat...
CVE-2026-52684LOW3.7If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data...
CVE-2026-16723CRITICAL9A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable ...
CVE-2026-16287HIGH7.8Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILG...
CVE-2026-9729MEDIUM6.4The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_noti...
CVE-2026-9713HIGH7.5The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table'...
CVE-2026-9635MEDIUM6.4The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parame...
CVE-2026-59678HIGH7.1An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary fi...
CVE-2026-59677MEDIUM6.8A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined ...
CVE-2026-12421HIGH7.2The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all version...
CVE-2026-9577MEDIUM4.8The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before ref...
CVE-2026-9066MEDIUM6.1The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asse...
CVE-2026-59676MEDIUM5.8A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user ...
CVE-2026-14291HIGH7.5The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its ...
CVE-2026-12082HIGH7.5The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now