2026 CVE Vulnerabilities

53,017 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-2433MEDIUM6.1The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to DOM-Ba...
CVE-2026-2420MEDIUM4.4The LotekMedia Popup Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in a...
CVE-2026-1825MEDIUM6.4The Show YouTube video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'syv' shortcod...
CVE-2026-1824MEDIUM6.4The Infomaniak Connect for OpenID plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'endpoint_lo...
CVE-2026-1823MEDIUM6.4The Consensus Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's consensus shortco...
CVE-2026-1820MEDIUM6.4The Media Library Alt Text Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bv...
CVE-2026-1805MEDIUM6.4The DA Media GigList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's damedia_giglist ...
CVE-2026-1574MEDIUM6.4The MyQtip – easy qTip2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `myqtip` shor...
CVE-2026-1569MEDIUM6.4The Wueen plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wueen-blocket` shortcode i...
CVE-2026-1087MEDIUM4.3The Guardian News Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2026-1086MEDIUM4.3The Font Pairing Preview For Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi...
CVE-2026-1085MEDIUM4.3The True Ranker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2...
CVE-2026-1073MEDIUM4.3The Purchase Button For Affiliate Link plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions ...
CVE-2026-1071MEDIUM4.4The Carta Online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up...
CVE-2026-30842MEDIUM4.3Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, Wallos allows an authenti...
CVE-2026-30841MEDIUM6.1Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, passwordreset.php outputs...
CVE-2026-30839MEDIUM4.3Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, testwebhooknotifications....
CVE-2026-30830MEDIUM6.1Defuddle cleans up HTML pages. Prior to version 0.9.0, the _findContentBySchemaText method in src/defuddle.ts interpolat...
CVE-2026-30829MEDIUM5.3Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and...
CVE-2026-30825MEDIUM6.5hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke e...
CVE-2026-27797MEDIUM5.3Homarr is an open-source dashboard. Prior to version 1.54.0, an unauthenticated Server-Side Request Forgery (SSRF) vulne...
CVE-2026-2722MEDIUM4.8The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up...
CVE-2026-2721MEDIUM4.8The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up...
CVE-2026-2494MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery...
CVE-2026-2488MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message delet...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now