2026 CVE Vulnerabilities

43,880 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-17023MEDIUM4.8The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth s...
CVE-2026-17022HIGH7.5The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before...
CVE-2026-17021MEDIUM5.3The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modif...
CVE-2026-17020MEDIUM4.3The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the calle...
CVE-2026-17019MEDIUM6.1The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and...
CVE-2026-17018MEDIUM4.9The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restric...
CVE-2026-17016LOW3.7The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amoun...
CVE-2026-17012MEDIUM5.3The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the Pa...
CVE-2026-17010MEDIUM5.4The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before o...
CVE-2026-16985HIGH8.8The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data writ...
CVE-2026-16949MEDIUM5.8The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL ...
CVE-2026-16299CRITICAL9.8The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing u...
CVE-2026-16298CRITICAL9.8The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthen...
CVE-2026-16257HIGH8.2The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, wh...
CVE-2026-15238MEDIUM5.4The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer reco...
CVE-2026-15237MEDIUM5.3The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a RES...
CVE-2026-15229MEDIUM5.3The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side, ...
CVE-2026-15047MEDIUM6.8The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside ...
CVE-2026-14941MEDIUM5.4The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on seve...
CVE-2026-14860MEDIUM5.3The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from ...
CVE-2026-14293HIGH8.8The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option ...
CVE-2026-14238MEDIUM4.1The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body...
CVE-2026-14237HIGH7.2The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorizat...
CVE-2026-14211LOW3.8The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated empl...
CVE-2026-14206HIGH7.5The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now