2026 CVE Vulnerabilities

43,286 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-15730MEDIUM6.4The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ...
CVE-2026-15673MEDIUM4.4The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera...
CVE-2026-15671MEDIUM4.9The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera...
CVE-2026-15670MEDIUM4.9The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera...
CVE-2026-6251MEDIUM6.5The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and i...
CVE-2026-16811MEDIUM4.9The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-bas...
CVE-2026-16797MEDIUM4.3The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure...
CVE-2026-16587MEDIUM4.3The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in...
CVE-2026-15136MEDIUM4.3The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery...
CVE-2026-15012MEDIUM5.3The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory C...
CVE-2026-14926MEDIUM4.2The FluentCart A New Era of eCommerce WordPress plugin before 1.4.0 does not verify that a subscription belongs to the ...
CVE-2026-12124MEDIUM5.3The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for Word...
CVE-2026-17528MEDIUM6.1Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the <select> element....
CVE-2026-65448MEDIUM6.5Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner &#8211; AcyChecker <= 1.8.1 versions.
CVE-2026-65445MEDIUM6.5Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.
CVE-2026-51565MEDIUM6.1Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attacker...
CVE-2026-59240MEDIUM6.9The vulnerability involves an Insecure Direct Object Reference (IDOR) in the `DeleteNotificationController::delete()` me...
CVE-2026-53669MEDIUM6.1React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backsl...
CVE-2026-53668MEDIUM6.9React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow ...
CVE-2026-53667MEDIUM6.1React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validatio...
CVE-2026-53666MEDIUM6.1React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allo...
CVE-2026-51564MEDIUM4.9An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external...
CVE-2026-66825MEDIUM6.9Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component. Values associated with li...
CVE-2026-64776MEDIUM5.5The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, m...
CVE-2026-64755MEDIUM5.5An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6. An...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now