2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-14516HIGH7.5The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injec...
CVE-2026-14171MEDIUM6.1An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick ...
CVE-2026-14170Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-14169HIGH8.1Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted in...
CVE-2026-14168HIGH8.8A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of th...
CVE-2026-14167HIGH8.8A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level inclu...
CVE-2026-13161HIGH7.5The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection vi...
CVE-2026-12800HIGH7.5The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code'...
CVE-2026-55977LOW3.3Successful exploitation of this vulnerability could allow an attacker with local network access to bypass the applicatio...
CVE-2026-15730MEDIUM6.4The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ...
CVE-2026-15673MEDIUM4.4The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera...
CVE-2026-15671MEDIUM4.9The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera...
CVE-2026-15670MEDIUM4.9The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera...
CVE-2026-15014CRITICAL9.8The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera...
CVE-2026-12741HIGH7.5The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via t...
CVE-2026-11756CRITICAL10A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3...
CVE-2026-6251MEDIUM6.5The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and i...
CVE-2026-16811MEDIUM4.9The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-bas...
CVE-2026-16797MEDIUM4.3The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure...
CVE-2026-16587MEDIUM4.3The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in...
CVE-2026-16585HIGH7.2The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbi...
CVE-2026-15136MEDIUM4.3The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery...
CVE-2026-15012MEDIUM5.3The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory C...
CVE-2026-14926MEDIUM4.2The FluentCart A New Era of eCommerce WordPress plugin before 1.4.0 does not verify that a subscription belongs to the ...
CVE-2026-14924HIGH7.5The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now