2026 CVE Vulnerabilities

65,977 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-93399CRITICAL9.1The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2...
CVE-2026-93303HIGH7.2The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cros...
CVE-2026-92829MEDIUM4.3The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass in all ve...
CVE-2026-92799MEDIUM5.3The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorization Bypass...
CVE-2026-92746MEDIUM6.4The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-92212MEDIUM6.1The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi...
CVE-2026-89055CRITICAL9.1The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, a...
CVE-2026-84281HIGH7.2The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'productTitle' in '_fpd...
CVE-2026-84279HIGH7.2The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'output_format' par...
CVE-2026-83591HIGH7.2The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment ...
CVE-2026-78397MEDIUM4The Link Library WordPress plugin before 7.9.6 does not validate the destination of a user-supplied URL before falling b...
CVE-2026-78394MEDIUM4.1The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a gen...
CVE-2026-78393MEDIUM6.1The Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the ad...
CVE-2026-75553LOW2.4Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an att...
CVE-2026-62062HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This is...
CVE-2026-19775MEDIUM4.3The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is vulnerable to authorizat...
CVE-2026-14281CRITICAL9.8The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulne...
CVE-2026-97721LOW2.7A weakness has been identified in Sanluan PublicCMS up to 6.202506.e. This vulnerability affects the function CmsContent...
CVE-2026-97818HIGH8.6phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.
CVE-2026-97764LOW3.7django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configu...
CVE-2026-97737HIGH7.4In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leadin...
CVE-2026-97736MEDIUM5.4tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular e...
CVE-2026-97735HIGH8ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages ...
CVE-2026-97732MEDIUM5.1IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client executables by checking for exp...
CVE-2026-97731HIGH7.1MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now