2026 CVE Vulnerabilities

56,974 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-11575HIGH7.5The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming paymen...
CVE-2026-10525MEDIUM6.1The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and...
CVE-2026-15982CRITICAL9.8The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable ...
CVE-2026-15094MEDIUM6.1The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parame...
CVE-2026-60060MEDIUM6.3Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provide...
CVE-2026-58317MEDIUM6.3Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Pr...
CVE-2026-41993MEDIUM6.7Improper Access Control vulnerability in the Removable Media Validation function of TXOne Networks products allows a loc...
CVE-2026-21770MEDIUM6.5HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker ...
CVE-2026-15759MEDIUM6.4The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable t...
CVE-2026-15457MEDIUM4.9The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversa...
CVE-2026-15349MEDIUM4.3The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization b...
CVE-2026-15161MEDIUM6.4The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and ...
CVE-2026-14503MEDIUM6.5The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc...
CVE-2026-13765HIGH7.5The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive...
CVE-2026-13352HIGH8.8The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres...
CVE-2026-8616MEDIUM5.3The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...
CVE-2026-15395HIGH7.2The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2026-15160MEDIUM4.3The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and incl...
CVE-2026-15159MEDIUM4.3The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up...
CVE-2026-11324MEDIUM6.1The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cros...
CVE-2026-62387HIGH7.1The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default C...
CVE-2026-62386HIGH8.2The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query...
CVE-2026-62241CRITICAL9.3clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me')...
CVE-2026-62238HIGH8.8OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint ...
CVE-2026-62237MEDIUM6.5Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now