2026 CVE Vulnerabilities
43,769 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13755 | MEDIUM | 6.4 | — | Jul 16, 2026 | The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_... |
| CVE-2026-13754 | MEDIUM | 6.5 | 0.2% | Jul 16, 2026 | The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' param... |
| CVE-2026-12979 | MEDIUM | 5.5 | — | Jul 16, 2026 | The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a t... |
| CVE-2026-12869 | MEDIUM | 6.1 | — | Jul 16, 2026 | The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for ... |
| CVE-2026-12684 | MEDIUM | 6.5 | 0.2% | Jul 16, 2026 | The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or non... |
| CVE-2026-12510 | MEDIUM | 5.9 | 0.1% | Jul 16, 2026 | The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a c... |
| CVE-2026-12395 | MEDIUM | 6.5 | 0.2% | Jul 16, 2026 | The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a ... |
| CVE-2026-11866 | MEDIUM | 5.4 | 0.1% | Jul 16, 2026 | The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing a... |
| CVE-2026-11371 | MEDIUM | 6.1 | — | Jul 16, 2026 | The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and... |
| CVE-2026-15458 | MEDIUM | 4.9 | 0.3% | Jul 16, 2026 | The SEO Booster plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_field' parameter in all versio... |
| CVE-2026-15445 | MEDIUM | 4.9 | — | Jul 16, 2026 | The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versio... |
| CVE-2026-15306 | MEDIUM | 6.1 | 0.2% | Jul 16, 2026 | The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflec... |
| CVE-2026-15652 | MEDIUM | 6.4 | 0.2% | Jul 16, 2026 | The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2026-15336 | MEDIUM | 4.3 | 0.3% | Jul 16, 2026 | The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and includin... |
| CVE-2026-14987 | MEDIUM | 6.4 | 0.2% | Jul 16, 2026 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2026-13005 | MEDIUM | 4.4 | 0.2% | Jul 16, 2026 | The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scrip... |
| CVE-2026-12941 | MEDIUM | 6.5 | 0.3% | Jul 16, 2026 | The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to generi... |
| CVE-2026-12434 | MEDIUM | 4.3 | 0.2% | Jul 16, 2026 | The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and ... |
| CVE-2026-12409 | MEDIUM | 4.3 | 0.1% | Jul 16, 2026 | The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress i... |
| CVE-2026-15909 | MEDIUM | 6.3 | 0.2% | Jul 16, 2026 | A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is a... |
| CVE-2026-62314 | MEDIUM | 5.8 | 0.3% | Jul 15, 2026 | Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scrap... |
| CVE-2026-53447 | MEDIUM | 6.5 | 0.2% | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js use... |
| CVE-2026-53446 | MEDIUM | 6.2 | 0.3% | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan webhook integration URLs in models/integrations.js a... |
| CVE-2026-52892 | MEDIUM | 6.5 | 0.3% | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use r... |
| CVE-2026-50183 | MEDIUM | 4.7 | 0.2% | Jul 15, 2026 | WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerabilit... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now