2026 CVE Vulnerabilities

64,788 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-85131MEDIUM6.5The WPLP Cookie Consent WordPress plugin before 4.4.4 does not perform CSRF or capability checks when processing bulk a...
CVE-2026-84088MEDIUM6.8The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link s...
CVE-2026-82125MEDIUM5.3The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership or the mo...
CVE-2026-82124MEDIUM5.3The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is password protect...
CVE-2026-78474MEDIUM5.3The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisation checks ...
CVE-2026-77702MEDIUM5.3The Eventin WordPress plugin before 4.1.24 does not prevent the token issued to a guest at checkout from being used to ...
CVE-2026-76559MEDIUM4.1The WP Import Export Lite WordPress plugin before 3.9.33 does not properly validate URLs before requesting them during t...
CVE-2026-76558MEDIUM6.8The WP Import Export Lite WordPress plugin before 3.9.33 does not escape custom field names retrieved from the database ...
CVE-2026-76557MEDIUM6.8The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some import configuration...
CVE-2026-76556MEDIUM6.8The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some export filter values...
CVE-2026-76555MEDIUM6.8The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it a...
CVE-2026-76553MEDIUM6.5The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data ...
CVE-2026-5920MEDIUM6.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' para...
CVE-2026-18555MEDIUM6.1The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Refl...
CVE-2026-16588MEDIUM6.5The WP Directory Kit plugin for WordPress is vulnerable to blind SQL Injection via the 'order_by' parameter in all versi...
CVE-2026-11996MEDIUM6.4The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' Fie...
CVE-2026-11984MEDIUM5.3The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up...
CVE-2026-92247MEDIUM4.7A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename o...
CVE-2026-92221MEDIUM4.7A vulnerability was determined in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affecte...
CVE-2026-92220MEDIUM5.3A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_...
CVE-2026-86109MEDIUM6.6The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures becau...
CVE-2026-73450MEDIUM6.9On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with a...
CVE-2026-92298MEDIUM4.8EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and camp...
CVE-2026-92217MEDIUM6.3A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file ...
CVE-2026-92216MEDIUM4.3A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now