2026 CVE Vulnerabilities
53,457 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24562 | MEDIUM | 5.3 | 0.3% | Jan 23, 2026 | Missing Authorization vulnerability in Ryviu Ryviu – Product Reviews for WooCommerce ryviu allows Exploiting Incorrectly... |
| CVE-2026-24561 | MEDIUM | 5.4 | 0.3% | Jan 23, 2026 | Missing Authorization vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows Exploiting Incorrectly Conf... |
| CVE-2026-24560 | MEDIUM | 5.4 | 0.3% | Jan 23, 2026 | Missing Authorization vulnerability in Cloudinary Cloudinary cloudinary-image-management-and-manipulation-in-the-cloud-c... |
| CVE-2026-24559 | MEDIUM | 5.3 | 0.2% | Jan 23, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in CRM Perks Integration for Contact Form 7 HubSpot cf7-... |
| CVE-2026-24558 | MEDIUM | 6.5 | 0.2% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in antoniobg ABG Rich... |
| CVE-2026-24557 | MEDIUM | 5.3 | 0.2% | Jan 23, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WEN Solutions Contact Form 7 GetResponse Extension co... |
| CVE-2026-24556 | MEDIUM | 5.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in wpdive ElementCamp element-camp allows Exploiting Incorrectly Configured Access C... |
| CVE-2026-24555 | MEDIUM | 6.5 | 0.2% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in artplacer ArtPlace... |
| CVE-2026-24553 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Dotstore Fraud Prevention Fo... |
| CVE-2026-24551 | MEDIUM | 5.4 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in monetagwp Monetag Official Plugin monetag-official allows Exploiting Incorrectly ... |
| CVE-2026-24550 | MEDIUM | 6.5 | 0.2% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kaira Blockons blo... |
| CVE-2026-24549 | MEDIUM | 4.3 | 0.1% | Jan 23, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Paolo GeoDirectory geodirectory allows Cross Site Request Forgery.Thi... |
| CVE-2026-24548 | MEDIUM | 5.4 | 0.2% | Jan 23, 2026 | Server-Side Request Forgery (SSRF) vulnerability in princeahmed Radio Player radio-player allows Server Side Request For... |
| CVE-2026-24544 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in Harmonic Design HD Quiz hd-quiz allows Exploiting Incorrectly Configured Access C... |
| CVE-2026-24543 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in Horea Radu Materialis Companion materialis-companion allows Exploiting Incorrectl... |
| CVE-2026-24542 | MEDIUM | 4.3 | 0.1% | Jan 23, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in John James Jacoby WP Term Order wp-term-order allows Cross Site Reque... |
| CVE-2026-24541 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in mkscripts Download After Email download-after-email allows Exploiting Incorrectly... |
| CVE-2026-24540 | MEDIUM | 5.4 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in princeahmed Integrate Google Drive integrate-google-drive allows Exploiting Incor... |
| CVE-2026-24539 | MEDIUM | 5.3 | 0.3% | Jan 23, 2026 | Missing Authorization vulnerability in ABCdatos Protección de datos – RGPD proteccion-datos-rgpd allows Exploiting Incor... |
| CVE-2026-24536 | MEDIUM | 5.3 | 0.3% | Jan 23, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in webpushr Webpushr webpushr-w... |
| CVE-2026-24535 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in webdevstudios Automatic Featured Images from Videos automatic-featured-images-fro... |
| CVE-2026-24534 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in uPress Booter booter-bots-crawlers-manager allows Exploiting Incorrectly Configur... |
| CVE-2026-24532 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in SiteLock SiteLock Security – WP Hardening, Login Security & Malware Scans siteloc... |
| CVE-2026-24530 | MEDIUM | 5.3 | 0.4% | Jan 23, 2026 | Missing Authorization vulnerability in sheepfish WebP Conversion webp-conversion allows Exploiting Incorrectly Configure... |
| CVE-2026-24529 | MEDIUM | 5.3 | 0.3% | Jan 23, 2026 | Missing Authorization vulnerability in Alejandro Quick Restaurant Reservations quick-restaurant-reservations allows Expl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now