2026 CVE Vulnerabilities
53,334 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0736 | MEDIUM | 6.4 | 0.3% | Feb 14, 2026 | The Chatbot for WordPress by Collect.chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_in... |
| CVE-2026-0735 | MEDIUM | 4.4 | 0.2% | Feb 14, 2026 | The User Language Switch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tab_color_picker_lan... |
| CVE-2026-0727 | MEDIUM | 5.4 | 0.3% | Feb 14, 2026 | The Accordion and Accordion Slider plugin for WordPress is vulnerable to authorization bypass in all versions up to, and... |
| CVE-2026-0693 | MEDIUM | 4.4 | 0.2% | Feb 14, 2026 | The Allow HTML in Category Descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via category d... |
| CVE-2026-0559 | MEDIUM | 6.4 | 0.2% | Feb 14, 2026 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Stored Cro... |
| CVE-2026-0557 | MEDIUM | 6.4 | 0.2% | Feb 14, 2026 | The WP Data Access plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpda_app' shortco... |
| CVE-2026-1932 | MEDIUM | 5.3 | 0.3% | Feb 14, 2026 | The Appointment Booking Calendar Plugin – Bookr plugin for WordPress is vulnerable to unauthorized modification of data ... |
| CVE-2026-2027 | MEDIUM | 4.4 | 0.2% | Feb 14, 2026 | The AMP Enhancer – Compatibility Layer for Official AMP Plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2026-1983 | MEDIUM | 4.3 | 0.1% | Feb 14, 2026 | The SEATT: Simple Event Attendance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... |
| CVE-2026-1912 | MEDIUM | 6.4 | 0.2% | Feb 14, 2026 | The Citations tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'code' parameter in the 'c... |
| CVE-2026-1904 | MEDIUM | 6.4 | 0.2% | Feb 14, 2026 | The Simple Wp colorfull Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' para... |
| CVE-2026-1754 | MEDIUM | 6.1 | 0.2% | Feb 14, 2026 | The personal-authors-category plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in a... |
| CVE-2026-1164 | MEDIUM | 6.1 | 0.2% | Feb 14, 2026 | The Easy Voice Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all... |
| CVE-2026-25964 | MEDIUM | 4.9 | 0.4% | Feb 13, 2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, a P... |
| CVE-2026-21870 | MEDIUM | 5.5 | 0.2% | Feb 13, 2026 | BACnet Protocol Stack library provides a BACnet application layer, network layer and media access (MAC) layer communicat... |
| CVE-2026-2026 | MEDIUM | 6.1 | 0.1% | Feb 13, 2026 | A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could all... |
| CVE-2026-26226 | MEDIUM | 5.3 | 0.5% | Feb 13, 2026 | beautiful-mermaid versions prior to 0.1.3 contain an SVG attribute injection issue that can lead to cross-site scripting... |
| CVE-2026-25531 | MEDIUM | 4.3 | 0.2% | Feb 13, 2026 | Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, The fix for CVE-2023-33968 is in... |
| CVE-2026-1578 | MEDIUM | 5.1 | 0.1% | Feb 13, 2026 | HP App for Android is potentially vulnerable to cross-site scripting (XSS) when using an outdated version of the applica... |
| CVE-2026-2443 | MEDIUM | 5.3 | 0.4% | Feb 13, 2026 | A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted H... |
| CVE-2026-22892 | MEDIUM | 4.3 | 0.2% | Feb 13, 2026 | Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user permissions when creati... |
| CVE-2026-1721 | MEDIUM | 6.2 | 0.4% | Feb 13, 2026 | Summary A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the AI Playground's OAuth callback handl... |
| CVE-2026-26188 | MEDIUM | 5.4 | 0.3% | Feb 12, 2026 | Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. An authenticated, low-privilege user ... |
| CVE-2026-26185 | MEDIUM | 5.3 | 0.3% | Feb 12, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Before 11.14.1, a timing-based user enu... |
| CVE-2026-26075 | MEDIUM | 5.4 | 0.1% | Feb 12, 2026 | FastGPT is an AI Agent building platform. Due to the fact that FastGPT's web page acquisition nodes, HTTP nodes, etc. ne... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now