2026 CVE Vulnerabilities

55,897 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15827MEDIUM5.3The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check ...
CVE-2026-15794MEDIUM6.4The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shor...
CVE-2026-15786MEDIUM4.4The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is v...
CVE-2026-15761MEDIUM6.5The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event...
CVE-2026-15647MEDIUM4.4The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term...
CVE-2026-15646MEDIUM6.4The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attri...
CVE-2026-15448MEDIUM6.5The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order...
CVE-2026-15404MEDIUM6.4The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and inc...
CVE-2026-15394MEDIUM6.4The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross...
CVE-2026-15348MEDIUM6.3The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all...
CVE-2026-15017HIGH8.8The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin...
CVE-2026-15015CRITICAL9.8The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions u...
CVE-2026-15011CRITICAL9.8The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parame...
CVE-2026-14481MEDIUM6.4The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl...
CVE-2026-14282CRITICAL9.8The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for ...
CVE-2026-13119MEDIUM6.5The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'stan...
CVE-2026-13009MEDIUM6.5The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Param...
CVE-2026-52688HIGH7.5RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
CVE-2026-52686LOW3.7The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signat...
CVE-2026-52684LOW3.7If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data...
CVE-2026-16723CRITICAL9A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable ...
CVE-2026-16287HIGH7.8Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILG...
CVE-2026-9729MEDIUM6.4The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_noti...
CVE-2026-9713HIGH7.5The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table'...
CVE-2026-9635MEDIUM6.4The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parame...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now