2026 CVE Vulnerabilities
53,211 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25323 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in MiKa OSM osm allows Exploiting Incorrectly Configured Access Control Security Lev... |
| CVE-2026-25322 | MEDIUM | 5.4 | 0.1% | Feb 19, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in PublishPress PublishPress Revisions revisionary allows Cross Site Req... |
| CVE-2026-25321 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in PSM Plugins SupportCandy supportcandy allows Exploiting Incorrectly Configured Ac... |
| CVE-2026-25320 | MEDIUM | 5.3 | 0.3% | Feb 19, 2026 | Missing Authorization vulnerability in Cool Plugins Elementor Contact Form DB sb-elementor-contact-form-db allows Exploi... |
| CVE-2026-25319 | MEDIUM | 4.3 | 0.1% | Feb 19, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpzita Zita Elementor Site Library zita-site-library allows Cross Sit... |
| CVE-2026-25318 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in Wisernotify team WiserReview Product Reviews for WooCommerce wiser-review allows ... |
| CVE-2026-25315 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in hcaptcha hCaptcha for WP hcaptcha-for-forms-and-more allows Exploiting Incorrectl... |
| CVE-2026-25314 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in WP Messiah TOP Table Of Contents top-table-of-contents allows Exploiting Incorrec... |
| CVE-2026-25313 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in Shahjahan Jewel FluentForm fluentform allows Exploiting Incorrectly Configured Ac... |
| CVE-2026-25311 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in 10up Autoshare for Twitter autoshare-for-twitter allows Exploiting Incorrectly Co... |
| CVE-2026-25310 | MEDIUM | 4.9 | 0.2% | Feb 19, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Alobaidi Extend Link extend-link allows Server Side Request Forgery.... |
| CVE-2026-25308 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in wp.insider Simple Membership simple-membership allows Exploiting Incorrectly Conf... |
| CVE-2026-25307 | MEDIUM | 6.5 | 0.2% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core... |
| CVE-2026-25305 | MEDIUM | 6.5 | 0.2% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore xsto... |
| CVE-2026-25008 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Shahjahan Jewel Ninja Tables ninja-tables allows Retr... |
| CVE-2026-25006 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore xstore allo... |
| CVE-2026-25005 | MEDIUM | 5.3 | 0.3% | Feb 19, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in N-Media Frontend File Manager nmedia-user-file-uploade... |
| CVE-2026-25004 | MEDIUM | 5.9 | 0.2% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolut... |
| CVE-2026-25003 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in madalin.ungureanu Client Portal client-portal allows Exploiting Incorrectly Confi... |
| CVE-2026-25000 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in Kraft Plugins Wheel of Life wheel-of-life allows Exploiting Incorrectly Configure... |
| CVE-2026-24999 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in Alma Alma alma-gateway-for-woocommerce allows Exploiting Incorrectly Configured A... |
| CVE-2026-24392 | MEDIUM | 5.9 | 0.2% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nabil Lemsieh Hurr... |
| CVE-2026-24375 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in WP Swings Ultimate Gift Cards For WooCommerce woo-gift-cards-lite allows Exploiti... |
| CVE-2026-23804 | MEDIUM | 5.4 | 0.3% | Feb 19, 2026 | Missing Authorization vulnerability in BBR Plugins Better Business Reviews better-business-reviews allows Exploiting Inc... |
| CVE-2026-23803 | MEDIUM | 6.4 | 0.2% | Feb 19, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Burhan Nasir Smart Auto Upload Images smart-auto-upload-images allow... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now