2026 CVE Vulnerabilities

53,433 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-1208MEDIUM4.3The Friendly Functions for Welcart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...
CVE-2026-1191MEDIUM4.4The JavaScript Notifier plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all ver...
CVE-2026-1189MEDIUM6.4The LeadBI Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_id' para...
CVE-2026-1127MEDIUM6.1The Timeline Event History plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `id` parameter i...
CVE-2026-1098MEDIUM6.4The CM CSS Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' shortcode attribute i...
CVE-2026-0687MEDIUM4.3The Meta-box GalleryMeta plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2026-1103MEDIUM5.4The AIKTP plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on...
CVE-2026-1099MEDIUM6.4The Administrative Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'login' and 'log...
CVE-2026-1097MEDIUM6.4The ThemeRuby Multi Authors – Assign Multiple Writers to Posts plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2026-1095MEDIUM6.4The Canto Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fx' shortcode attribut...
CVE-2026-1088MEDIUM4.3The Login Page Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2026-1084MEDIUM4.4The Cookie consent for developers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple setting...
CVE-2026-1081MEDIUM4.3The Set Bulk Post Categories plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and...
CVE-2026-1076MEDIUM4.3The Star Review Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2026-1075MEDIUM4.3The ZT Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1....
CVE-2026-1070MEDIUM4.3The Alex User Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2026-0806MEDIUM4.9The WP-ClanWars plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, a...
CVE-2026-24420MEDIUM6.5phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below allow an authenticated user without the dlatta...
CVE-2026-24421MEDIUM6.5phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below have flawed authorization logic which exposes ...
CVE-2026-24401MEDIUM6.5Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions...
CVE-2026-24399MEDIUM5.4ChatterMate is a no-code AI chatbot agent framework. In versions 1.0.8 and below, the chatbot accepts and executes malic...
CVE-2026-24474MEDIUM5.3Dioxus Components is a shadcn-style component library for the Dioxus app framework. Prior to commit 41e4242ecb1062d04ae4...
CVE-2026-24140MEDIUM5.3MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below have a Mass Assignme...
CVE-2026-24139MEDIUM6.5MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below do not safeguard aga...
CVE-2026-24128MEDIUM6.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 7.0-mi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now