2026 CVE Vulnerabilities

43,669 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-13754MEDIUM6.5The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' param...
CVE-2026-12979MEDIUM5.5The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a t...
CVE-2026-12869MEDIUM6.1The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for ...
CVE-2026-12684MEDIUM6.5The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or non...
CVE-2026-12510MEDIUM5.9The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a c...
CVE-2026-12395MEDIUM6.5The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a ...
CVE-2026-11866MEDIUM5.4The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing a...
CVE-2026-11371MEDIUM6.1The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and...
CVE-2026-15458MEDIUM4.9The SEO Booster plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_field' parameter in all versio...
CVE-2026-15445MEDIUM4.9The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versio...
CVE-2026-15306MEDIUM6.1The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflec...
CVE-2026-15652MEDIUM6.4The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2026-15336MEDIUM4.3The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and includin...
CVE-2026-14987MEDIUM6.4The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2026-13005MEDIUM4.4The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2026-12941MEDIUM6.5The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to generi...
CVE-2026-12434MEDIUM4.3The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and ...
CVE-2026-12409MEDIUM4.3The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress i...
CVE-2026-15909MEDIUM6.3A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is a...
CVE-2026-62314MEDIUM5.8Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scrap...
CVE-2026-53447MEDIUM6.5Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js use...
CVE-2026-53446MEDIUM6.2Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan webhook integration URLs in models/integrations.js a...
CVE-2026-52892MEDIUM6.5Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use r...
CVE-2026-50183MEDIUM4.7WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerabilit...
CVE-2026-50182MEDIUM6.1WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Reflected XSS vulnerabil...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now