2026 CVE Vulnerabilities

53,334 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-0736MEDIUM6.4The Chatbot for WordPress by Collect.chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_in...
CVE-2026-0735MEDIUM4.4The User Language Switch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tab_color_picker_lan...
CVE-2026-0727MEDIUM5.4The Accordion and Accordion Slider plugin for WordPress is vulnerable to authorization bypass in all versions up to, and...
CVE-2026-0693MEDIUM4.4The Allow HTML in Category Descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via category d...
CVE-2026-0559MEDIUM6.4The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Stored Cro...
CVE-2026-0557MEDIUM6.4The WP Data Access plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpda_app' shortco...
CVE-2026-1932MEDIUM5.3The Appointment Booking Calendar Plugin – Bookr plugin for WordPress is vulnerable to unauthorized modification of data ...
CVE-2026-2027MEDIUM4.4The AMP Enhancer – Compatibility Layer for Official AMP Plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2026-1983MEDIUM4.3The SEATT: Simple Event Attendance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...
CVE-2026-1912MEDIUM6.4The Citations tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'code' parameter in the 'c...
CVE-2026-1904MEDIUM6.4The Simple Wp colorfull Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' para...
CVE-2026-1754MEDIUM6.1The personal-authors-category plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in a...
CVE-2026-1164MEDIUM6.1The Easy Voice Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all...
CVE-2026-25964MEDIUM4.9Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, a P...
CVE-2026-21870MEDIUM5.5BACnet Protocol Stack library provides a BACnet application layer, network layer and media access (MAC) layer communicat...
CVE-2026-2026MEDIUM6.1A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could all...
CVE-2026-26226MEDIUM5.3beautiful-mermaid versions prior to 0.1.3 contain an SVG attribute injection issue that can lead to cross-site scripting...
CVE-2026-25531MEDIUM4.3Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, The fix for CVE-2023-33968 is in...
CVE-2026-1578MEDIUM5.1HP App for Android is potentially vulnerable to cross-site scripting (XSS) when using an outdated version of the applica...
CVE-2026-2443MEDIUM5.3A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted H...
CVE-2026-22892MEDIUM4.3Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user permissions when creati...
CVE-2026-1721MEDIUM6.2Summary A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the AI Playground's OAuth callback handl...
CVE-2026-26188MEDIUM5.4Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. An authenticated, low-privilege user ...
CVE-2026-26185MEDIUM5.3Directus is a real-time API and App dashboard for managing SQL database content. Before 11.14.1, a timing-based user enu...
CVE-2026-26075MEDIUM5.4FastGPT is an AI Agent building platform. Due to the fact that FastGPT's web page acquisition nodes, HTTP nodes, etc. ne...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now