2026 CVE Vulnerabilities

64,889 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-85132MEDIUM4.3The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie ...
CVE-2026-85037MEDIUM5.3The Sunshine Photo Cart WordPress plugin before 3.7 does not validate that a client-supplied price identifier belongs t...
CVE-2026-84908MEDIUM5.3The WPFunnels plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.12.13. Thi...
CVE-2026-84222MEDIUM5.3The Kirki WordPress plugin before 6.3.0 does not check whether the requester is allowed to read a post before rendering...
CVE-2026-84113MEDIUM4.1The Quentn WP WordPress plugin before 1.2.15 does not properly sanitise and escape a parameter before using it in an SQL...
CVE-2026-83541MEDIUM6.8The Sina Extension for Elementor WordPress plugin before 3.10.4 does not properly escape a Table widget setting before o...
CVE-2026-82848MEDIUM5.3The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enro...
CVE-2026-82185MEDIUM4.3The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have capability or nonce checks on some of its A/B testi...
CVE-2026-82184MEDIUM5.3The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visit...
CVE-2026-81741MEDIUM4.7The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict the redirect...
CVE-2026-81022MEDIUM5.3The SupportCandy WordPress plugin before 3.5.3 does not validate a submitted per-ticket authorization code before discl...
CVE-2026-81021MEDIUM5.3The SupportCandy WordPress plugin before 3.5.3 does not perform an authorization check on one of its support-ticket att...
CVE-2026-80341MEDIUM5.9The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not verify that a stored payment method b...
CVE-2026-80340MEDIUM5.3The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not validate the order key before adding ...
CVE-2026-80339MEDIUM5.3The Payment Plugins for Stripe WooCommerce WordPress plugin before 4.0.12 does not validate the order key before adding ...
CVE-2026-75905MEDIUM4.3The WP Recipe Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10....
CVE-2026-75861MEDIUM6.5The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not verify that the user redeeming a gift ca...
CVE-2026-19946MEDIUM4.3The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9....
CVE-2026-18042MEDIUM5.3The WP Travel WordPress plugin before 12.0.2 does not verify that the requester is authorized to act on the booking tar...
CVE-2026-87737MEDIUM5.9An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST ...
CVE-2026-87736MEDIUM4.3An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds ...
CVE-2026-87735MEDIUM4.3An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml. There is an undocumented exception for a...
CVE-2026-87733MEDIUM6.2An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Ds...
CVE-2026-87732MEDIUM6.2An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and C...
CVE-2026-21113MEDIUM5.5Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now