2026 CVE Vulnerabilities

43,891 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-18465MEDIUM6.5The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is a...
CVE-2026-18464HIGH7.5The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is a...
CVE-2026-18357HIGH7.5The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of...
CVE-2026-18037MEDIUM6.5The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of it...
CVE-2026-18032HIGH7.5The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthent...
CVE-2026-17044HIGH8.6The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it ...
CVE-2026-17017HIGH8.1The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in...
CVE-2026-17014MEDIUM5.3The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its ...
CVE-2026-17011LOW3.8The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpo...
CVE-2026-16992MEDIUM6.5The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of it...
CVE-2026-16988HIGH7.5The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker dat...
CVE-2026-16965MEDIUM4.3The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, a...
CVE-2026-16957LOW2.7The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed ...
CVE-2026-16032MEDIUM6.1The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated an...
CVE-2026-15038CRITICAL9.8The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenti...
CVE-2026-19334MEDIUM5.3A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown pa...
CVE-2026-19333MEDIUM5.3A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a...
CVE-2026-19332MEDIUM5.3A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functi...
CVE-2026-19331MEDIUM5.3A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanva...
CVE-2026-19330MEDIUM5.3A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0. The impacted element is the function create_s...
CVE-2026-19329MEDIUM5.3A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390. The affected element i...
CVE-2026-10595HIGH7.5A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemen...
CVE-2026-19328MEDIUM5.3A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/insta...
CVE-2026-19327MEDIUM5.3A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue affects the function getEnrichedData/enrichSession ...
CVE-2026-19326MEDIUM4.4A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now