2026 CVE Vulnerabilities
53,348 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2295 | MEDIUM | 5.3 | 0.3% | Feb 11, 2026 | The WPZOOM Addons for Elementor – Starter Templates & Widgets plugin for WordPress is vulnerable to unauthorized access ... |
| CVE-2026-1885 | MEDIUM | 6.4 | 0.2% | Feb 11, 2026 | The Slideshow Wp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sswpid' attribute of the 'ss... |
| CVE-2026-1853 | MEDIUM | 6.4 | 0.2% | Feb 11, 2026 | The BuddyHolis ListSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'listsearch... |
| CVE-2026-1833 | MEDIUM | 5.3 | 0.3% | Feb 11, 2026 | The WaMate Confirm – Order Confirmation plugin for WordPress is vulnerable to unauthorized access in all versions up to,... |
| CVE-2026-1827 | MEDIUM | 6.4 | 0.2% | Feb 11, 2026 | The Flask Micro code-editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's codeflask... |
| CVE-2026-1826 | MEDIUM | 6.4 | 0.3% | Feb 11, 2026 | The OpenPOS Lite – Point of Sale for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2026-1821 | MEDIUM | 6.4 | 0.2% | Feb 11, 2026 | The Microtango plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'restkey' parameter of the mt_r... |
| CVE-2026-1809 | MEDIUM | 6.4 | 0.3% | Feb 11, 2026 | The HTML Tag Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in... |
| CVE-2026-1804 | MEDIUM | 6.4 | 0.2% | Feb 11, 2026 | The WDES Responsive Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wdes-popup... |
| CVE-2026-1786 | MEDIUM | 6.5 | 0.3% | Feb 11, 2026 | The Twitter posts to Blog plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2026-1748 | MEDIUM | 4.3 | 0.3% | Feb 11, 2026 | The Invoct – PDF Invoices & Billing for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data du... |
| CVE-2026-1215 | MEDIUM | 4.3 | 0.2% | Feb 11, 2026 | The MMA Call Tracking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2026-0815 | MEDIUM | 4.4 | 0.2% | Feb 11, 2026 | The Category Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag-image' parameter in al... |
| CVE-2026-0724 | MEDIUM | 4.4 | 0.3% | Feb 11, 2026 | The WPlyr Media Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_wplyr_accent_color' pa... |
| CVE-2026-1235 | MEDIUM | 6.5 | 0.3% | Feb 11, 2026 | The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthentic... |
| CVE-2026-26079 | MEDIUM | 4.7 | 0.3% | Feb 11, 2026 | Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comme... |
| CVE-2026-1893 | MEDIUM | 6.4 | 0.2% | Feb 11, 2026 | The Orbisius Random Name Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_label'... |
| CVE-2026-1231 | MEDIUM | 6.4 | 0.2% | Feb 11, 2026 | The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site ... |
| CVE-2026-1571 | MEDIUM | 6.1 | 0.3% | Feb 11, 2026 | User-controlled input is reflected into the HTML output without proper encoding on TP-Link Archer C60 v3, allowing arbit... |
| CVE-2026-25872 | MEDIUM | 6.9 | 0.7% | Feb 10, 2026 | JUNG Smart Panel KNX firmware version L1.12.22 and prior contain an unauthenticated path traversal vulnerability in the ... |
| CVE-2026-25870 | MEDIUM | 6.9 | 0.3% | Feb 10, 2026 | DoraCMS version 3.1 and prior contains a server-side request forgery (SSRF) vulnerability in its UEditor remote image fe... |
| CVE-2026-26007 | MEDIUM | 6.5 | 0.3% | Feb 10, 2026 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5,... |
| CVE-2026-26006 | MEDIUM | 6.5 | 0.5% | Feb 10, 2026 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut... |
| CVE-2026-1495 | MEDIUM | 6.5 | 0.1% | Feb 10, 2026 | The vulnerability, if exploited, could allow an attacker with Event Log Reader (S-1-5-32-573) privileges to obtain proxy... |
| CVE-2026-2303 | MEDIUM | 6.9 | 0.2% | Feb 10, 2026 | The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrap... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now