2026 CVE Vulnerabilities
53,206 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25428 | MEDIUM | 4.4 | 0.2% | Feb 19, 2026 | Server-Side Request Forgery (SSRF) vulnerability in totalsoft TS Poll poll-wp allows Server Side Request Forgery.This is... |
| CVE-2026-25422 | MEDIUM | 5.4 | 0.1% | Feb 19, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Themes4WP Popularis Extra popularis-extra allows Cross Site Request F... |
| CVE-2026-25420 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in MailerLite MailerLite official-mailerlite-sign-up-forms allows Exploiting Incorre... |
| CVE-2026-25419 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in flycart UpsellWP checkout-upsell-and-order-bumps allows Exploiting Incorrectly Co... |
| CVE-2026-25416 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Exploiting... |
| CVE-2026-25415 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Exploiting Incorrectly Configured A... |
| CVE-2026-25411 | MEDIUM | 4.3 | 0.1% | Feb 19, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in themastercut Revision Manager TMC revision-manager-tmc allows Cross S... |
| CVE-2026-25410 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in tstephenson WP-CORS wp-cors allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2026-25409 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in crgeary JAMstack Deployments wp-jamstack-deployments allows Exploiting Incorrectl... |
| CVE-2026-25408 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in PluginRx Broken Link Notifier broken-link-notifier allows Exploiting Incorrectly ... |
| CVE-2026-25407 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in cookiebot Cookiebot cookiebot allows Exploiting Incorrectly Configured Access Con... |
| CVE-2026-25404 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in Automattic WP Job Manager wp-job-manager allows Exploiting Incorrectly Configured... |
| CVE-2026-25402 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in echoplugins Knowledge Base for Documentation, FAQs with AI Assistance echo-knowle... |
| CVE-2026-25399 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in CryoutCreations Serious Slider cryout-serious-slider allows Exploiting Incorrectl... |
| CVE-2026-25395 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in ikreatethemes Business Roy business-roy allows Exploiting Incorrectly Configured ... |
| CVE-2026-25394 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in sparklewpthemes Fitness FSE fitness-fse allows Exploiting Incorrectly Configured ... |
| CVE-2026-25393 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in sparklewpthemes Hello FSE hello-fse allows Exploiting Incorrectly Configured Acce... |
| CVE-2026-25392 | MEDIUM | 4.7 | 0.2% | Feb 19, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in KaizenCoders Update URLs – Quick and Easy way to se... |
| CVE-2026-25391 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in WP Grids WP Wand ai-content-generation allows Exploiting Incorrectly Configured A... |
| CVE-2026-25389 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Metagauss EventPrime eventpr... |
| CVE-2026-25388 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in scripteo Ads Pro ap-plugin-scripteo allows Exploiting Incorrectly Configured Acce... |
| CVE-2026-25387 | MEDIUM | 4.3 | 0.3% | Feb 19, 2026 | Missing Authorization vulnerability in Elementor Image Optimizer by Elementor image-optimization allows Exploiting Incor... |
| CVE-2026-25386 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in Elementor Ally pojo-accessibility allows Exploiting Incorrectly Configured Access... |
| CVE-2026-25385 | MEDIUM | 5.5 | 0.2% | Feb 19, 2026 | Server-Side Request Forgery (SSRF) vulnerability in KaizenCoders URL Shortify url-shortify allows Server Side Request Fo... |
| CVE-2026-25384 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay allows Exploiting Incorrectly C... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now