2026 CVE Vulnerabilities

64,997 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-15550MEDIUM4.3The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and inclu...
CVE-2026-12843MEDIUM5.4The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to ...
CVE-2026-86178MEDIUM5.4Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowin...
CVE-2026-86176MEDIUM4.3NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, S...
CVE-2026-86175MEDIUM6.5NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authen...
CVE-2026-86174MEDIUM4.3Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. A...
CVE-2026-86122MEDIUM5Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure ar...
CVE-2026-86120MEDIUM4.3APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to en...
CVE-2026-86118MEDIUM4.3gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authentic...
CVE-2026-86116MEDIUM6.5Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any a...
CVE-2026-86115MEDIUM5Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skippi...
CVE-2026-86114MEDIUM6.5Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to creat...
CVE-2026-86113MEDIUM6.5BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authe...
CVE-2026-86112MEDIUM5.4BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing auth...
CVE-2026-86111MEDIUM6.5BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated...
CVE-2026-76573MEDIUM6.4The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'not_fo...
CVE-2026-85414MEDIUM6.4The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings' Shortco...
CVE-2026-75586MEDIUM6.1The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'formData[...
CVE-2026-75018MEDIUM4.3The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including...
CVE-2026-84937MEDIUM6.8The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input be...
CVE-2026-84936MEDIUM5.3The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allo...
CVE-2026-84931MEDIUM6.8The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before ...
CVE-2026-84930MEDIUM6.8The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute...
CVE-2026-84901MEDIUM4.9The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management RES...
CVE-2026-84899MEDIUM6.8The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now