2026 CVE Vulnerabilities

55,812 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-65550MEDIUM5.9Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.
CVE-2026-65540HIGH7.1Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.
CVE-2026-65539HIGH7.1Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.
CVE-2026-65538MEDIUM5.9Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.
CVE-2026-65537MEDIUM4.3Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
CVE-2026-65536MEDIUM6.5Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5...
CVE-2026-65535MEDIUM4.3Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
CVE-2026-65534MEDIUM5.9Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.
CVE-2026-65533MEDIUM6.5Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.
CVE-2026-65532HIGH7.6Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.
CVE-2026-65531MEDIUM4.8Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.
CVE-2026-65530MEDIUM4.3Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.
CVE-2026-65529MEDIUM5.3Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.
CVE-2026-65528MEDIUM6.5Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions.
CVE-2026-65527MEDIUM6.5Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.
CVE-2026-65526HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualiz...
CVE-2026-65525MEDIUM5.3Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.
CVE-2026-65524MEDIUM4.3Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
CVE-2026-65522MEDIUM6.5Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 ve...
CVE-2026-65521MEDIUM5.3Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.
CVE-2026-65519MEDIUM6.5Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.
CVE-2026-65518MEDIUM6.5Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.
CVE-2026-65516HIGH7.2Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVE-2026-65514MEDIUM6.5Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.
CVE-2026-65512MEDIUM5.4Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allow...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now