2026 CVE Vulnerabilities

53,212 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-1437MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack...
CVE-2026-1436MEDIUM6.5Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs when modifying the user ID in the URL. An...
CVE-2026-2386MEDIUM4.3The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for Wor...
CVE-2026-1317MEDIUM6.5The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to SQL Injection in all versi...
CVE-2026-2426MEDIUM6.5The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 v...
CVE-2026-1942MEDIUM6.5The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of d...
CVE-2026-2126MEDIUM5.3The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Incorre...
CVE-2026-2127MEDIUM5.4The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to unauthorized arbitrary shortcode execution in all ve...
CVE-2026-1941MEDIUM6.4The WP Event Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_events' s...
CVE-2026-1656MEDIUM5.3The Business Directory Plugin for WordPress is vulnerable to authorization bypass due to a missing authorization check i...
CVE-2026-1649MEDIUM4.4The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ce_venue_name' parameter...
CVE-2026-2112MEDIUM4.3The Dam Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0....
CVE-2026-1943MEDIUM4.4The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via setting...
CVE-2026-1938MEDIUM5.3The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized license key deletion due t...
CVE-2026-1860MEDIUM4.3The Kali Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi...
CVE-2026-1655MEDIUM4.3The EventPrime plugin for WordPress is vulnerable to unauthorized post modification due to missing authorization checks ...
CVE-2026-2633MEDIUM4.3The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Missing Authorization in all versions u...
CVE-2026-2281MEDIUM4.4The Private Comment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Label text' setting in al...
CVE-2026-1857MEDIUM4.3The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Server-Side Request Forgery in all vers...
CVE-2026-1807MEDIUM6.4The InteractiveCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2026-1666MEDIUM6.1The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' paramete...
CVE-2026-1640MEDIUM4.3The Taskbuilder – WordPress Project Management & Task Management plugin for WordPress is vulnerable to authorization byp...
CVE-2026-2023MEDIUM4.3The WP Plugin Info Card plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2026-1906MEDIUM4.3The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference ...
CVE-2026-1639MEDIUM6.5The Taskbuilder – WordPress Project Management & Task Management plugin for WordPress is vulnerable to time-based blind ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now