2026 CVE Vulnerabilities

65,813 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6087MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6086MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6085MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6084MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6083MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6082MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-96752HIGH7.2The Zero Spam for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Nested POST Array Keys...
CVE-2026-96568HIGH7.2The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_n...
CVE-2026-96448MEDIUM6.6A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management ...
CVE-2026-95866HIGH7.2The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v...
CVE-2026-95864HIGH7.2The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'css[fonts]' Parameter in all ...
CVE-2026-94573HIGH7.2The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater F...
CVE-2026-93901HIGH7.3The Optima Express IDX plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, ...
CVE-2026-93747MEDIUM6.4The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in v...
CVE-2026-93656MEDIUM6.4The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v...
CVE-2026-93654HIGH7.2The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2026-92713HIGH8.1The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due ...
CVE-2026-92609CRITICAL9.8Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticat...
CVE-2026-92608HIGH7.5Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated messa...
CVE-2026-89426HIGH8.8The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress is vulnerable to Privilege Escalation...
CVE-2026-89406HIGH7.5The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of p...
CVE-2026-88996MEDIUM6.1The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPres...
CVE-2026-84280HIGH7.2The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Order 'elemen...
CVE-2026-19804HIGH8.8The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin...
CVE-2026-17602MEDIUM4.9The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Directory Traversal in a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now