2026 CVE Vulnerabilities

64,788 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-27553MEDIUM6.5A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_ta...
CVE-2026-8030MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 1...
CVE-2026-86475MEDIUM5.3The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission aga...
CVE-2026-84906MEDIUM5.3The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is appli...
CVE-2026-7514MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and 1...
CVE-2026-19857MEDIUM4.8The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress s...
CVE-2026-19619MEDIUM4.7GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 1...
CVE-2026-16794MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 18.11 before 19.1.8, 19.2 before 19.2.6, and 19....
CVE-2026-13407MEDIUM5.4The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted throu...
CVE-2026-92358MEDIUM6.4A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a diff...
CVE-2026-88910MEDIUM5.3The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauth...
CVE-2026-87959MEDIUM5.4The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI...
CVE-2026-87907MEDIUM5.3The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints tha...
CVE-2026-87896MEDIUM5.3The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoint that...
CVE-2026-87860MEDIUM4.3The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that c...
CVE-2026-87854MEDIUM5.3The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret protecting...
CVE-2026-87828MEDIUM5.7The Seraphinite Accelerator WordPress plugin before 2.29.24 does not perform a capability check on one of its state-upda...
CVE-2026-86823MEDIUM5.3The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after a public...
CVE-2026-86784MEDIUM6.8The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration befo...
CVE-2026-86449MEDIUM5.3The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities before applying a user supplied pos...
CVE-2026-86447MEDIUM5.3The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative course...
CVE-2026-86445MEDIUM5.3The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative templa...
CVE-2026-85641MEDIUM4.3The Formidable Forms WordPress plugin before 6.35 does not restrict who can set the identifier recording which user las...
CVE-2026-85572MEDIUM4.3The Tutor LMS WordPress plugin before 4.0.8 does not check that a user has access to a course before returning its less...
CVE-2026-85349MEDIUM4.3The FluentBoards WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of board...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now