2026 CVE Vulnerabilities
53,433 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1208 | MEDIUM | 4.3 | 0.2% | Jan 24, 2026 | The Friendly Functions for Welcart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... |
| CVE-2026-1191 | MEDIUM | 4.4 | 0.2% | Jan 24, 2026 | The JavaScript Notifier plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all ver... |
| CVE-2026-1189 | MEDIUM | 6.4 | 0.2% | Jan 24, 2026 | The LeadBI Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_id' para... |
| CVE-2026-1127 | MEDIUM | 6.1 | 0.2% | Jan 24, 2026 | The Timeline Event History plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `id` parameter i... |
| CVE-2026-1098 | MEDIUM | 6.4 | 0.2% | Jan 24, 2026 | The CM CSS Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' shortcode attribute i... |
| CVE-2026-0687 | MEDIUM | 4.3 | 0.2% | Jan 24, 2026 | The Meta-box GalleryMeta plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi... |
| CVE-2026-1103 | MEDIUM | 5.4 | 0.2% | Jan 24, 2026 | The AIKTP plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on... |
| CVE-2026-1099 | MEDIUM | 6.4 | 0.2% | Jan 24, 2026 | The Administrative Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'login' and 'log... |
| CVE-2026-1097 | MEDIUM | 6.4 | 0.2% | Jan 24, 2026 | The ThemeRuby Multi Authors – Assign Multiple Writers to Posts plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2026-1095 | MEDIUM | 6.4 | 0.3% | Jan 24, 2026 | The Canto Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fx' shortcode attribut... |
| CVE-2026-1088 | MEDIUM | 4.3 | 0.2% | Jan 24, 2026 | The Login Page Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2026-1084 | MEDIUM | 4.4 | 0.3% | Jan 24, 2026 | The Cookie consent for developers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple setting... |
| CVE-2026-1081 | MEDIUM | 4.3 | 0.2% | Jan 24, 2026 | The Set Bulk Post Categories plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and... |
| CVE-2026-1076 | MEDIUM | 4.3 | 0.2% | Jan 24, 2026 | The Star Review Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2026-1075 | MEDIUM | 4.3 | 0.2% | Jan 24, 2026 | The ZT Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.... |
| CVE-2026-1070 | MEDIUM | 4.3 | 0.2% | Jan 24, 2026 | The Alex User Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2026-0806 | MEDIUM | 4.9 | 0.4% | Jan 24, 2026 | The WP-ClanWars plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, a... |
| CVE-2026-24420 | MEDIUM | 6.5 | 0.4% | Jan 24, 2026 | phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below allow an authenticated user without the dlatta... |
| CVE-2026-24421 | MEDIUM | 6.5 | 1.7% | Jan 24, 2026 | phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below have flawed authorization logic which exposes ... |
| CVE-2026-24401 | MEDIUM | 6.5 | 0.3% | Jan 24, 2026 | Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions... |
| CVE-2026-24399 | MEDIUM | 5.4 | 0.3% | Jan 24, 2026 | ChatterMate is a no-code AI chatbot agent framework. In versions 1.0.8 and below, the chatbot accepts and executes malic... |
| CVE-2026-24474 | MEDIUM | 5.3 | 0.4% | Jan 24, 2026 | Dioxus Components is a shadcn-style component library for the Dioxus app framework. Prior to commit 41e4242ecb1062d04ae4... |
| CVE-2026-24140 | MEDIUM | 5.3 | 0.3% | Jan 24, 2026 | MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below have a Mass Assignme... |
| CVE-2026-24139 | MEDIUM | 6.5 | 0.3% | Jan 24, 2026 | MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below do not safeguard aga... |
| CVE-2026-24128 | MEDIUM | 6.1 | 0.5% | Jan 24, 2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 7.0-mi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now