2026 CVE Vulnerabilities

43,769 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-13755MEDIUM6.4The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_...
CVE-2026-13754MEDIUM6.5The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' param...
CVE-2026-12979MEDIUM5.5The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a t...
CVE-2026-12869MEDIUM6.1The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for ...
CVE-2026-12684MEDIUM6.5The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or non...
CVE-2026-12510MEDIUM5.9The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a c...
CVE-2026-12395MEDIUM6.5The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a ...
CVE-2026-11866MEDIUM5.4The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing a...
CVE-2026-11371MEDIUM6.1The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and...
CVE-2026-15458MEDIUM4.9The SEO Booster plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_field' parameter in all versio...
CVE-2026-15445MEDIUM4.9The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versio...
CVE-2026-15306MEDIUM6.1The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflec...
CVE-2026-15652MEDIUM6.4The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2026-15336MEDIUM4.3The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and includin...
CVE-2026-14987MEDIUM6.4The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2026-13005MEDIUM4.4The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2026-12941MEDIUM6.5The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to generi...
CVE-2026-12434MEDIUM4.3The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and ...
CVE-2026-12409MEDIUM4.3The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress i...
CVE-2026-15909MEDIUM6.3A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is a...
CVE-2026-62314MEDIUM5.8Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scrap...
CVE-2026-53447MEDIUM6.5Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js use...
CVE-2026-53446MEDIUM6.2Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan webhook integration URLs in models/integrations.js a...
CVE-2026-52892MEDIUM6.5Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use r...
CVE-2026-50183MEDIUM4.7WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerabilit...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now