2026 CVE Vulnerabilities

64,858 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-17585MEDIUM5.3The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive ...
CVE-2026-11355MEDIUM5.3The DT LMS – elearning, WordPress LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a m...
CVE-2026-87919MEDIUM4.9The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its pr...
CVE-2026-87918MEDIUM5.3The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that ...
CVE-2026-87916MEDIUM5.3The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists st...
CVE-2026-87894MEDIUM5.3The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that...
CVE-2026-87892MEDIUM5.3The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment metho...
CVE-2026-87891MEDIUM6.5The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when s...
CVE-2026-87797MEDIUM4.3The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a ...
CVE-2026-86790MEDIUM6.8The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a ...
CVE-2026-84024MEDIUM4.3The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowin...
CVE-2026-84023MEDIUM6.5The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy...
CVE-2026-83532MEDIUM6.8The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes b...
CVE-2026-82847MEDIUM6.8The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting...
CVE-2026-78152MEDIUM5.3The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the str...
CVE-2026-77753MEDIUM5.5The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Ap...
CVE-2026-77689MEDIUM5.3The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actua...
CVE-2026-90467MEDIUM4aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESM...
CVE-2026-89268MEDIUM5.4QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping ...
CVE-2026-89267MEDIUM4.3starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an emp...
CVE-2026-90461MEDIUM6.3OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is conf...
CVE-2026-90457MEDIUM6.9The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one au...
CVE-2026-90455MEDIUM6.3A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later revert...
CVE-2026-90454MEDIUM5.3A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list o...
CVE-2026-90453MEDIUM5.1A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Refe...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now