2026 CVE Vulnerabilities
53,439 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24630 | MEDIUM | 6.5 | 0.1% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Design Stylish Cos... |
| CVE-2026-24629 | MEDIUM | 5.9 | 0.1% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ability, Inc Web A... |
| CVE-2026-24627 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in Trusona Trusona for WordPress trusona allows Exploiting Incorrectly Configured Ac... |
| CVE-2026-24626 | MEDIUM | 5.9 | 0.1% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LogicHunt Logo Sli... |
| CVE-2026-24625 | MEDIUM | 5.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in Imaginate Solutions File Uploads Addon for WooCommerce woo-addon-uploads allows E... |
| CVE-2026-24622 | MEDIUM | 5.4 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in Sergiy Dzysyak Suggestion Toolkit suggestion-toolkit allows Exploiting Incorrectl... |
| CVE-2026-24621 | MEDIUM | 5.9 | 0.1% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vladimir Statsenko... |
| CVE-2026-24620 | MEDIUM | 5.9 | 0.2% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps Landing ... |
| CVE-2026-24619 | MEDIUM | 5.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in PopCash PopCash.Net Code Integration Tool popcashnet-code-integration-tool allows... |
| CVE-2026-24617 | MEDIUM | 6.5 | 0.1% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Iser Easy M... |
| CVE-2026-24616 | MEDIUM | 6.5 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in Damian WP Popups wp-popups-lite allows Exploiting Incorrectly Configured Access C... |
| CVE-2026-24615 | MEDIUM | 5.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in themebeez Cream Magazine cream-magazine allows Exploiting Incorrectly Configured ... |
| CVE-2026-24614 | MEDIUM | 5.9 | 0.1% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Devsbrain Flex QR ... |
| CVE-2026-24613 | MEDIUM | 5.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in Ecwid by Lightspeed Ecommerce Shopping Cart Ecwid Shopping Cart ecwid-shopping-ca... |
| CVE-2026-24612 | MEDIUM | 5.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in themebeez Orchid Store orchid-store allows Exploiting Incorrectly Configured Acce... |
| CVE-2026-24607 | MEDIUM | 5.3 | 0.4% | Jan 23, 2026 | Missing Authorization vulnerability in wptravelengine Travel Monster travel-monster allows Exploiting Incorrectly Config... |
| CVE-2026-24606 | MEDIUM | 5.3 | 0.3% | Jan 23, 2026 | Missing Authorization vulnerability in Web Impian Bayarcash WooCommerce bayarcash-wc allows Exploiting Incorrectly Confi... |
| CVE-2026-24605 | MEDIUM | 4.3 | 0.3% | Jan 23, 2026 | Missing Authorization vulnerability in pencilwp X Addons for Elementor x-addons-elementor allows Exploiting Incorrectly ... |
| CVE-2026-24604 | MEDIUM | 5.3 | 0.3% | Jan 23, 2026 | Missing Authorization vulnerability in themebeez Simple GDPR Cookie Compliance simple-gdpr-cookie-compliance allows Expl... |
| CVE-2026-24603 | MEDIUM | 5.3 | 0.3% | Jan 23, 2026 | Missing Authorization vulnerability in themebeez Universal Google Adsense and Ads manager universal-google-adsense-and-a... |
| CVE-2026-24601 | MEDIUM | 6.5 | 0.2% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci ... |
| CVE-2026-24600 | MEDIUM | 6.5 | 0.2% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci ... |
| CVE-2026-24599 | MEDIUM | 5.3 | 0.3% | Jan 23, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextmove-li... |
| CVE-2026-24598 | MEDIUM | 4.3 | 0.3% | Jan 23, 2026 | Missing Authorization vulnerability in bestwebsoft Multilanguage by BestWebSoft multilanguage allows Exploiting Incorrec... |
| CVE-2026-24596 | MEDIUM | 4.3 | 0.1% | Jan 23, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in marynixie Related Posts Thumbnails Plugin for WordPress related-posts... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now