2026 CVE Vulnerabilities
51,071 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14862 | LOW | 3.7 | 0.2% | Jul 31, 2026 | The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downlo... |
| CVE-2026-14849 | LOW | 3.7 | 0.2% | Jul 31, 2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it... |
| CVE-2026-14847 | MEDIUM | 4.3 | 0.2% | Jul 31, 2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of i... |
| CVE-2026-14845 | MEDIUM | 6.1 | 0.2% | Jul 31, 2026 | The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor re... |
| CVE-2026-14843 | MEDIUM | 5.3 | 0.2% | Jul 31, 2026 | The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the target... |
| CVE-2026-14834 | MEDIUM | 6.5 | 0.2% | Jul 31, 2026 | The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX ... |
| CVE-2026-14833 | MEDIUM | 6.8 | 0.2% | Jul 31, 2026 | The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rend... |
| CVE-2026-14830 | HIGH | 7.5 | 0.2% | Jul 31, 2026 | The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually... |
| CVE-2026-14554 | MEDIUM | 6.5 | 0.2% | Jul 31, 2026 | The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them... |
| CVE-2026-14483 | CRITICAL | 9.8 | 0.6% | Jul 31, 2026 | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all ver... |
| CVE-2026-14333 | HIGH | 7.5 | 0.3% | Jul 31, 2026 | The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a p... |
| CVE-2026-14319 | HIGH | 7.5 | 0.3% | Jul 31, 2026 | The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurri... |
| CVE-2026-14317 | MEDIUM | 5.3 | 0.2% | Jul 31, 2026 | The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by t... |
| CVE-2026-13609 | HIGH | 8.8 | 0.2% | Jul 31, 2026 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value af... |
| CVE-2026-13393 | LOW | 3.5 | 0.1% | Jul 31, 2026 | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item... |
| CVE-2026-13392 | HIGH | 7.2 | 0.4% | Jul 31, 2026 | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a... |
| CVE-2026-12721 | HIGH | 8.6 | 0.3% | Jul 31, 2026 | The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before us... |
| CVE-2026-12720 | HIGH | 7.5 | 0.4% | Jul 31, 2026 | The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data ... |
| CVE-2026-12697 | MEDIUM | 5.4 | 0.2% | Jul 31, 2026 | The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting us... |
| CVE-2026-12695 | HIGH | 8.1 | 0.3% | Jul 31, 2026 | The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted... |
| CVE-2026-12376 | MEDIUM | 4.3 | 0.2% | Jul 31, 2026 | The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing... |
| CVE-2026-12251 | HIGH | 8.1 | 0.2% | Jul 31, 2026 | The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it m... |
| CVE-2026-63223 | CRITICAL | 9.8 | 0.5% | Jul 31, 2026 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not i... |
| CVE-2026-63222 | HIGH | 7.5 | 0.4% | Jul 31, 2026 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument us... |
| CVE-2026-63221 | CRITICAL | 9.4 | — | Jul 31, 2026 | CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound v... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now