2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-86842MEDIUM6.8The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flip...
CVE-2026-86785MEDIUM5.3The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its RES...
CVE-2026-86783MEDIUM5.3The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility chec...
CVE-2026-86603MEDIUM4.3The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, all...
CVE-2026-86602MEDIUM4.3The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, all...
CVE-2026-85006MEDIUM6.8The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets...
CVE-2026-84741MEDIUM5.3The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding the...
CVE-2026-84168MEDIUM5.3The Easy Hide Login WordPress plugin before 1.7 does not fully enforce its hidden-login protection, allowing an unauthen...
CVE-2026-84150MEDIUM5.4The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not verify ...
CVE-2026-84098MEDIUM6.5The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properl...
CVE-2026-84046MEDIUM5The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not validat...
CVE-2026-84027MEDIUM4.3The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check u...
CVE-2026-84026MEDIUM5.3The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not restric...
CVE-2026-83555MEDIUM5.3The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token ...
CVE-2026-81339MEDIUM4.3The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when ...
CVE-2026-81338MEDIUM4.6The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HTML in use...
CVE-2026-80342MEDIUM6.5The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied i...
CVE-2026-77766MEDIUM4.3The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope o...
CVE-2026-77765MEDIUM5.3The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the...
CVE-2026-18365MEDIUM4.3The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on one of its AJAX actions, al...
CVE-2026-18364MEDIUM4.3The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on several of its AJAX actions...
CVE-2026-16264MEDIUM6.5The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management ...
CVE-2026-96258MEDIUM4.3A vulnerability has been found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722. This affects an unkno...
CVE-2026-95957MEDIUM4.3A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0. This issue affects the fun...
CVE-2026-95930MEDIUM6.3A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the fu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now