2026 CVE Vulnerabilities

43,253 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-21059MEDIUM6.9Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attac...
CVE-2026-21058MEDIUM6.9Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with...
CVE-2026-19077MEDIUM6.5The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and d...
CVE-2026-19075MEDIUM5All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any ...
CVE-2026-19074MEDIUM5.3The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) i...
CVE-2026-18960MEDIUM5.4The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, al...
CVE-2026-18934MEDIUM5.5The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed ...
CVE-2026-18666MEDIUM4.3The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter befor...
CVE-2026-18200MEDIUM4.3The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user ...
CVE-2026-17023MEDIUM4.8The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth s...
CVE-2026-17021MEDIUM5.3The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-mod...
CVE-2026-17020MEDIUM4.3The Salon Booking System WordPress plugin through 10.30.33 does not verify that a requested booking belongs to the call...
CVE-2026-17019MEDIUM6.1The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and...
CVE-2026-17018MEDIUM4.9The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restric...
CVE-2026-17012MEDIUM5.3The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the Pa...
CVE-2026-17010MEDIUM5.4The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before o...
CVE-2026-16949MEDIUM5.8The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL ...
CVE-2026-15238MEDIUM5.4The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer reco...
CVE-2026-15237MEDIUM5.3The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a RES...
CVE-2026-15229MEDIUM5.3The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side, ...
CVE-2026-15047MEDIUM6.8The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside ...
CVE-2026-14941MEDIUM5.4The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on seve...
CVE-2026-14860MEDIUM5.3The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from ...
CVE-2026-14238MEDIUM4.1The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body...
CVE-2026-13701MEDIUM4.8The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it o...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now