2026 CVE Vulnerabilities

53,348 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-2295MEDIUM5.3The WPZOOM Addons for Elementor – Starter Templates & Widgets plugin for WordPress is vulnerable to unauthorized access ...
CVE-2026-1885MEDIUM6.4The Slideshow Wp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sswpid' attribute of the 'ss...
CVE-2026-1853MEDIUM6.4The BuddyHolis ListSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'listsearch...
CVE-2026-1833MEDIUM5.3The WaMate Confirm – Order Confirmation plugin for WordPress is vulnerable to unauthorized access in all versions up to,...
CVE-2026-1827MEDIUM6.4The Flask Micro code-editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's codeflask...
CVE-2026-1826MEDIUM6.4The OpenPOS Lite – Point of Sale for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2026-1821MEDIUM6.4The Microtango plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'restkey' parameter of the mt_r...
CVE-2026-1809MEDIUM6.4The HTML Tag Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in...
CVE-2026-1804MEDIUM6.4The WDES Responsive Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wdes-popup...
CVE-2026-1786MEDIUM6.5The Twitter posts to Blog plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2026-1748MEDIUM4.3The Invoct – PDF Invoices & Billing for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data du...
CVE-2026-1215MEDIUM4.3The MMA Call Tracking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2026-0815MEDIUM4.4The Category Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag-image' parameter in al...
CVE-2026-0724MEDIUM4.4The WPlyr Media Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_wplyr_accent_color' pa...
CVE-2026-1235MEDIUM6.5The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthentic...
CVE-2026-26079MEDIUM4.7Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comme...
CVE-2026-1893MEDIUM6.4The Orbisius Random Name Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_label'...
CVE-2026-1231MEDIUM6.4The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site ...
CVE-2026-1571MEDIUM6.1User-controlled input is reflected into the HTML output without proper encoding on TP-Link Archer C60 v3, allowing arbit...
CVE-2026-25872MEDIUM6.9JUNG Smart Panel KNX firmware version L1.12.22 and prior contain an unauthenticated path traversal vulnerability in the ...
CVE-2026-25870MEDIUM6.9DoraCMS version 3.1 and prior contains a server-side request forgery (SSRF) vulnerability in its UEditor remote image fe...
CVE-2026-26007MEDIUM6.5cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5,...
CVE-2026-26006MEDIUM6.5AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut...
CVE-2026-1495MEDIUM6.5The vulnerability, if exploited, could allow an attacker with Event Log Reader (S-1-5-32-573) privileges to obtain proxy...
CVE-2026-2303MEDIUM6.9The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrap...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now