CVE-2026-86196: Product identification pending
- Severity
- 8.7 (HIGH)
- Affected versions
- Before 1.0.20
- Fixed version
- 1.0.20
- Patch status
- Patched
- Published
- 2026-09-05T13:18:14.980
- Modified
- 2026-09-05T13:18:14.980
Why it matters
This matters because the affected product may be exposed on public websites. A vulnerable plugin can create a direct path to site compromise, malicious code deployment, or data theft.
Recommended admin actions
- Review and patch based on exposure, asset criticality, and business impact.
- Check whether the affected WordPress plugin or theme is installed.
- Update, disable, or remove the affected component if present.
- Compare installed versions against the affected version range in the advisory.
- Treat internet-facing systems as higher priority.
Technical summary
Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can send password reset requests for any account with a malicious Host header, intercept the reset token from victim emails, and complete account takeover including super-admin accounts.
View the official NVD record for CVE-2026-86196
CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.
VULNERABILITY PULSE
| AFFECTED PRODUCT | ACTION | ||
|---|---|---|---|
| CVE-2026-13447 |
MStore API – Create Native Android & iOS Apps On The Cloud
Reporter: SECURITY
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-83627 |
Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN
Reporter: SECURITY
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2024-11080 |
Post Grid
Reporter: SECURITY
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-10196 |
Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails PATCH
Reporter: SECURITY
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-52777 |
yeswiki PATCH
Reporter: SECURITY-ADVISORIES
|
9.4
CRITICAL
|
VIEW RECORD |
| CVE-2026-86123 |
sqlchat
Reporter: DISCLOSURE
|
9.4
CRITICAL
|
VIEW RECORD |
| CVE-2026-86148 |
CP3
Reporter: CNA
|
9.4
CRITICAL
|
VIEW RECORD |
| CVE-2026-86149 |
CP3
Reporter: CNA
|
9.4
CRITICAL
|
VIEW RECORD |
| CVE-2026-86121 |
cua-computer-server PATCH
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-86124 |
AutoAgent
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-86184 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-86189 |
AVideo
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-86190 |
AVideo
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-86117 |
coolify
Reporter: DISCLOSURE
|
9.2
CRITICAL
|
VIEW RECORD |
| CVE-2026-86119 |
webstudio
Reporter: DISCLOSURE
|
9.2
CRITICAL
|
VIEW RECORD |
| CVE-2026-67276 |
RouterOS PATCH
Reporter: CVD
|
9.2
CRITICAL
|
VIEW RECORD |
| CVE-2026-86060 |
RouterOS PATCH
Reporter: CVD
|
9.2
CRITICAL
|
VIEW RECORD |
| CVE-2026-52766 |
yeswiki PATCH
Reporter: SECURITY-ADVISORIES
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-52775 |
yeswiki PATCH
Reporter: SECURITY-ADVISORIES
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-19887 |
Welcart e-Commerce
Reporter: SECURITY
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-81543 |
Abandoned Cart Pro for WooCommerce
Reporter: SECURITY
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2025-9049 |
Nokri – Job Board WordPress Theme
Reporter: SECURITY
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-67277 |
RouterOS PATCH
Reporter: CVD
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-86169 |
Product identification pending
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-86173 |
Product identification pending
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-86177 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-86193 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-86195 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-86196 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-0799 |
Product identification pending
Reporter: SECURITY
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-67281 |
RouterOS PATCH
Reporter: CVD
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-86185 |
Bilibili Desktop
Reporter: DISCLOSURE
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-52769 |
yeswiki PATCH
Reporter: SECURITY-ADVISORIES
|
8.3
HIGH
|
VIEW RECORD |
| CVE-2026-52771 |
yeswiki PATCH
Reporter: SECURITY-ADVISORIES
|
8.3
HIGH
|
VIEW RECORD |
| CVE-2026-52767 |
yeswiki PATCH
Reporter: SECURITY-ADVISORIES
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-86145 |
Product identification pending PATCH
Reporter: CVE
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-86140 |
Product identification pending PATCH
Reporter: CVE
|
8
HIGH
|
VIEW RECORD |
| CVE-2026-86207 |
N-central
Reporter: A5532A13-C4DD-4202-BEF1-E0B8F2F8D12B
|
7.7
HIGH
|
VIEW RECORD |
| CVE-2026-52770 |
yeswiki PATCH
Reporter: SECURITY-ADVISORIES
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-86187 |
AVideo
Reporter: DISCLOSURE
|
7.4
HIGH
|
VIEW RECORD |
| CVE-2026-77233 |
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-77263 |
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-15984 |
QuickCal
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-16649 |
Gravity Forms
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-18406 |
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-19769 |
Ninja Forms – The Contact Form Builder That Grows With You
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-77830 |
Spam protection, Honeypot, Anti-Spam by CleanTalk
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-78438 |
W3 Total Cache
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-83625 |
Contact Form by Supsystic
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-52762 |
yeswiki PATCH
Reporter: SECURITY-ADVISORIES
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-86111 |
bookwyrm
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-86113 |
Product identification pending
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-86114 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-86116 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-86175 |
netbox
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-86192 |
siyuan PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-86138 |
Product identification pending PATCH
Reporter: CVE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-86139 |
Product identification pending PATCH
Reporter: CVE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-86142 |
Product identification pending PATCH
Reporter: CVE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-86143 |
Product identification pending PATCH
Reporter: CVE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-86188 |
AVideo
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-86194 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-67279 |
RouterOS PATCH
Reporter: CVD
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-86206 |
N-central PATCH
Reporter: A5532A13-C4DD-4202-BEF1-E0B8F2F8D12B
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2025-15647 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-52763 |
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-14975 |
WP File Download
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-18404 |
Social Chat – Click To Chat App Button
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-8623 |
DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-8625 |
DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-3853 |
Divi
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-85414 |
Gallery : FooGallery
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-76573 |
Pods – Custom Content Types and Fields
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-86186 |
AVideo
Reporter: DISCLOSURE
|
6.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-67278 |
RouterOS PATCH
Reporter: CVD
|
6.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-52773 |
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-52774 |
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-18843 |
Beaver Builder Plugin (Starter Version)
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-75586 |
Unlimited Elements For Elementor
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-82752 |
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
|
5.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-86144 |
Product identification pending PATCH
Reporter: CVE
|
5.6
MEDIUM
|
VIEW RECORD |
| CVE-2026-52772 |
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-31911 |
Product identification pending
Reporter: SECURITY
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-31912 |
Product identification pending
Reporter: SECURITY
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-6244 |
Product identification pending
Reporter: SECURITY
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-6554 |
Product identification pending
Reporter: SECURITY
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2025-14945 |
Events Manager – Calendar, Bookings, Tickets, and more!
Reporter: SECURITY
|
5.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-12843 |
LearnDash LMS
Reporter: SECURITY
|
5.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-86100 |
Product identification pending
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-86112 |
Product identification pending
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-86115 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-86118 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-86120 |
Product identification pending
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-86122 |
Product identification pending
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-86174 |
Product identification pending
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-86176 |
Product identification pending
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-86178 |
Product identification pending
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-86191 |
siyuan PATCH
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-86197 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
5.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-4361 |
Divi
Reporter: SECURITY
|
5
MEDIUM
|
VIEW RECORD |
About the Vulnerability Pulse CVE Feed
The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.
How to Use the CVE Advisory Tracker
Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.
What Is a CVE Advisory?
A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.
CVE Analysis & Writeups
For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.