2026 CVE Vulnerabilities

50,987 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-16062MEDIUM6.6The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-co...
CVE-2026-16042MEDIUM4.3The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowin...
CVE-2026-15939LOW2.7The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST ...
CVE-2026-15385MEDIUM5.4The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-m...
CVE-2026-15248MEDIUM5.5The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment ...
CVE-2026-15241HIGH7.5The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one o...
CVE-2026-15236HIGH7.5The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party...
CVE-2026-15206HIGH7.5The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that w...
CVE-2026-15151HIGH7.5The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its ...
CVE-2026-14938MEDIUM4.3The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation be...
CVE-2026-14920HIGH8.2## Summary
CVE-2026-14864MEDIUM5.4The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its s...
CVE-2026-14841MEDIUM6.1The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before refle...
CVE-2026-14817MEDIUM6.8The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through cer...
CVE-2026-13389MEDIUM6.5The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST ...
CVE-2026-12586HIGH8.1The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset...
CVE-2026-11872MEDIUM4.3The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in ...
CVE-2026-9335MEDIUM6.5A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improp...
CVE-2026-8457CRITICAL9.8The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and inc...
CVE-2026-18352HIGH7.5The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, ...
CVE-2026-13339HIGH7.5The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1...
CVE-2026-17002Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-18556HIGH7.4Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass....
CVE-2026-55735HIGH7.5Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a vi...
CVE-2026-55734HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now