2026 CVE Vulnerabilities

42,921 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-19426HIGH8.2POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directl...
CVE-2026-66659CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome ...
CVE-2026-19594HIGH8.1Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-dep...
CVE-2026-19217The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTM...
CVE-2026-19073The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one o...
CVE-2026-19052The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX ac...
CVE-2026-19050The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the ca...
CVE-2026-18962The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload int...
CVE-2026-18943The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allow...
CVE-2026-18789The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, ...
CVE-2026-18474The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL sta...
CVE-2026-18391The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stor...
CVE-2026-18366The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access ...
CVE-2026-18230The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL sta...
CVE-2026-18057The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it i...
CVE-2026-18049The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its ...
CVE-2026-18048The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a f...
CVE-2026-18046The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability...
CVE-2026-18035The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allo...
CVE-2026-17013The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it...
CVE-2026-16977The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is ...
CVE-2026-16737The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a ca...
CVE-2026-16538The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top...
CVE-2026-16294The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode...
CVE-2026-16253The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-resto...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now