2026 CVE Vulnerabilities
50,987 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16062 | MEDIUM | 6.6 | 0.3% | Aug 2, 2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-co... |
| CVE-2026-16042 | MEDIUM | 4.3 | 0.2% | Aug 2, 2026 | The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowin... |
| CVE-2026-15939 | LOW | 2.7 | 0.2% | Aug 2, 2026 | The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST ... |
| CVE-2026-15385 | MEDIUM | 5.4 | 0.1% | Aug 2, 2026 | The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-m... |
| CVE-2026-15248 | MEDIUM | 5.5 | 0.3% | Aug 2, 2026 | The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment ... |
| CVE-2026-15241 | HIGH | 7.5 | 0.3% | Aug 2, 2026 | The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one o... |
| CVE-2026-15236 | HIGH | 7.5 | 0.3% | Aug 2, 2026 | The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party... |
| CVE-2026-15206 | HIGH | 7.5 | 0.3% | Aug 2, 2026 | The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that w... |
| CVE-2026-15151 | HIGH | 7.5 | 0.2% | Aug 2, 2026 | The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its ... |
| CVE-2026-14938 | MEDIUM | 4.3 | 0.2% | Aug 2, 2026 | The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation be... |
| CVE-2026-14920 | HIGH | 8.2 | 0.3% | Aug 2, 2026 | ## Summary |
| CVE-2026-14864 | MEDIUM | 5.4 | 0.1% | Aug 2, 2026 | The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its s... |
| CVE-2026-14841 | MEDIUM | 6.1 | 0.2% | Aug 2, 2026 | The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before refle... |
| CVE-2026-14817 | MEDIUM | 6.8 | 0.3% | Aug 2, 2026 | The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through cer... |
| CVE-2026-13389 | MEDIUM | 6.5 | 0.3% | Aug 2, 2026 | The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST ... |
| CVE-2026-12586 | HIGH | 8.1 | 0.2% | Aug 2, 2026 | The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset... |
| CVE-2026-11872 | MEDIUM | 4.3 | 0.2% | Aug 2, 2026 | The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in ... |
| CVE-2026-9335 | MEDIUM | 6.5 | 0.6% | Aug 2, 2026 | A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improp... |
| CVE-2026-8457 | CRITICAL | 9.8 | 0.4% | Aug 2, 2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and inc... |
| CVE-2026-18352 | HIGH | 7.5 | 0.7% | Aug 2, 2026 | The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, ... |
| CVE-2026-13339 | HIGH | 7.5 | 0.6% | Aug 2, 2026 | The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1... |
| CVE-2026-17002 | — | — | — | Aug 1, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-18556 | HIGH | 7.4 | 0.3% | Aug 1, 2026 | Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.... |
| CVE-2026-55735 | HIGH | 7.5 | 0.2% | Aug 1, 2026 | Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a vi... |
| CVE-2026-55734 | HIGH | 7.5 | 0.1% | Aug 1, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now