2026 CVE Vulnerabilities
64,858 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-17585 | MEDIUM | 5.3 | 0.3% | Sep 12, 2026 | The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive ... |
| CVE-2026-11355 | MEDIUM | 5.3 | 0.2% | Sep 12, 2026 | The DT LMS – elearning, WordPress LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a m... |
| CVE-2026-87919 | MEDIUM | 4.9 | 0.2% | Sep 12, 2026 | The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its pr... |
| CVE-2026-87918 | MEDIUM | 5.3 | 0.2% | Sep 12, 2026 | The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that ... |
| CVE-2026-87916 | MEDIUM | 5.3 | 0.2% | Sep 12, 2026 | The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists st... |
| CVE-2026-87894 | MEDIUM | 5.3 | 0.2% | Sep 12, 2026 | The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that... |
| CVE-2026-87892 | MEDIUM | 5.3 | 0.2% | Sep 12, 2026 | The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment metho... |
| CVE-2026-87891 | MEDIUM | 6.5 | 0.2% | Sep 12, 2026 | The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when s... |
| CVE-2026-87797 | MEDIUM | 4.3 | 0.2% | Sep 12, 2026 | The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a ... |
| CVE-2026-86790 | MEDIUM | 6.8 | 0.2% | Sep 12, 2026 | The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a ... |
| CVE-2026-84024 | MEDIUM | 4.3 | 0.1% | Sep 12, 2026 | The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowin... |
| CVE-2026-84023 | MEDIUM | 6.5 | 0.1% | Sep 12, 2026 | The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy... |
| CVE-2026-83532 | MEDIUM | 6.8 | 0.2% | Sep 12, 2026 | The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes b... |
| CVE-2026-82847 | MEDIUM | 6.8 | 0.2% | Sep 12, 2026 | The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting... |
| CVE-2026-78152 | MEDIUM | 5.3 | 0.2% | Sep 12, 2026 | The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the str... |
| CVE-2026-77753 | MEDIUM | 5.5 | 0.2% | Sep 12, 2026 | The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Ap... |
| CVE-2026-77689 | MEDIUM | 5.3 | 0.2% | Sep 12, 2026 | The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actua... |
| CVE-2026-90467 | MEDIUM | 4 | 0.2% | Sep 12, 2026 | aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESM... |
| CVE-2026-89268 | MEDIUM | 5.4 | 0.2% | Sep 12, 2026 | QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping ... |
| CVE-2026-89267 | MEDIUM | 4.3 | 0.2% | Sep 12, 2026 | starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an emp... |
| CVE-2026-90461 | MEDIUM | 6.3 | 0.2% | Sep 11, 2026 | OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is conf... |
| CVE-2026-90457 | MEDIUM | 6.9 | 0.1% | Sep 11, 2026 | The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one au... |
| CVE-2026-90455 | MEDIUM | 6.3 | 0.2% | Sep 11, 2026 | A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later revert... |
| CVE-2026-90454 | MEDIUM | 5.3 | 0.2% | Sep 11, 2026 | A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list o... |
| CVE-2026-90453 | MEDIUM | 5.1 | 0.2% | Sep 11, 2026 | A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Refe... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now