2026 CVE Vulnerabilities
53,212 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1437 | MEDIUM | 6.1 | 0.2% | Feb 18, 2026 | Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack... |
| CVE-2026-1436 | MEDIUM | 6.5 | 0.2% | Feb 18, 2026 | Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs when modifying the user ID in the URL. An... |
| CVE-2026-2386 | MEDIUM | 4.3 | 0.2% | Feb 18, 2026 | The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for Wor... |
| CVE-2026-1317 | MEDIUM | 6.5 | 0.2% | Feb 18, 2026 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to SQL Injection in all versi... |
| CVE-2026-2426 | MEDIUM | 6.5 | 1.3% | Feb 18, 2026 | The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 v... |
| CVE-2026-1942 | MEDIUM | 6.5 | 0.3% | Feb 18, 2026 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of d... |
| CVE-2026-2126 | MEDIUM | 5.3 | 0.3% | Feb 18, 2026 | The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Incorre... |
| CVE-2026-2127 | MEDIUM | 5.4 | 0.3% | Feb 18, 2026 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to unauthorized arbitrary shortcode execution in all ve... |
| CVE-2026-1941 | MEDIUM | 6.4 | 0.3% | Feb 18, 2026 | The WP Event Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_events' s... |
| CVE-2026-1656 | MEDIUM | 5.3 | 0.3% | Feb 18, 2026 | The Business Directory Plugin for WordPress is vulnerable to authorization bypass due to a missing authorization check i... |
| CVE-2026-1649 | MEDIUM | 4.4 | 0.2% | Feb 18, 2026 | The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ce_venue_name' parameter... |
| CVE-2026-2112 | MEDIUM | 4.3 | 0.2% | Feb 18, 2026 | The Dam Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.... |
| CVE-2026-1943 | MEDIUM | 4.4 | 0.3% | Feb 18, 2026 | The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via setting... |
| CVE-2026-1938 | MEDIUM | 5.3 | 0.3% | Feb 18, 2026 | The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized license key deletion due t... |
| CVE-2026-1860 | MEDIUM | 4.3 | 0.3% | Feb 18, 2026 | The Kali Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi... |
| CVE-2026-1655 | MEDIUM | 4.3 | 0.3% | Feb 18, 2026 | The EventPrime plugin for WordPress is vulnerable to unauthorized post modification due to missing authorization checks ... |
| CVE-2026-2633 | MEDIUM | 4.3 | 0.3% | Feb 18, 2026 | The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Missing Authorization in all versions u... |
| CVE-2026-2281 | MEDIUM | 4.4 | 0.2% | Feb 18, 2026 | The Private Comment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Label text' setting in al... |
| CVE-2026-1857 | MEDIUM | 4.3 | 0.3% | Feb 18, 2026 | The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Server-Side Request Forgery in all vers... |
| CVE-2026-1807 | MEDIUM | 6.4 | 0.2% | Feb 18, 2026 | The InteractiveCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2026-1666 | MEDIUM | 6.1 | 0.3% | Feb 18, 2026 | The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' paramete... |
| CVE-2026-1640 | MEDIUM | 4.3 | 0.3% | Feb 18, 2026 | The Taskbuilder – WordPress Project Management & Task Management plugin for WordPress is vulnerable to authorization byp... |
| CVE-2026-2023 | MEDIUM | 4.3 | 0.2% | Feb 18, 2026 | The WP Plugin Info Card plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2026-1906 | MEDIUM | 4.3 | 0.3% | Feb 18, 2026 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference ... |
| CVE-2026-1639 | MEDIUM | 6.5 | 0.3% | Feb 18, 2026 | The Taskbuilder – WordPress Project Management & Task Management plugin for WordPress is vulnerable to time-based blind ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now