CVE WATCH / VULNERABILITY DETAIL
CVE-2026-95865
MEDIUMCVSS 6.5NVD feed
Published 3 October 2026 · tracked since 3 October 2026
Description
The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]' Parameter in all versions up to, and including, 2.11.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on t
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-105146 MEDIUM 4.7
- CVE-2026-105144 MEDIUM 5.3
- CVE-2026-105137 MEDIUM 5
- CVE-2026-86817
- CVE-2026-93549
- CVE-2026-97332
- CVE-2026-17005
- CVE-2026-104119
- CVE-2026-104118
- CVE-2026-105123 HIGH 8.8