2026 CVE Vulnerabilities
64,858 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-81911 | MEDIUM | 5.4 | 0.3% | Sep 11, 2026 | Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot dialog. The custom_slot save_templ... |
| CVE-2026-79035 | MEDIUM | 6.1 | 0.2% | Sep 11, 2026 | A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0... |
| CVE-2026-78547 | MEDIUM | 4.4 | 0.2% | Sep 11, 2026 | Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. This issue affects Citrix Workspace app f... |
| CVE-2026-78546 | MEDIUM | 4.8 | 0.1% | Sep 11, 2026 | Out-of-bounds read vulnerability in Citirx Workspace app for Windows. This issue affects Workspace app for Windows: bef... |
| CVE-2026-77490 | MEDIUM | 6.1 | 0.4% | Sep 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) ... |
| CVE-2026-68526 | MEDIUM | 4.3 | 0.2% | Sep 11, 2026 | Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concret... |
| CVE-2026-49463 | MEDIUM | 6.5 | — | Sep 11, 2026 | NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, custom... |
| CVE-2026-49462 | MEDIUM | 5.3 | 0.3% | Sep 11, 2026 | NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, custom... |
| CVE-2026-89329 | MEDIUM | 6.2 | 0.1% | Sep 11, 2026 | A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this ... |
| CVE-2026-81910 | MEDIUM | 6.5 | 0.3% | Sep 11, 2026 | Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated ... |
| CVE-2026-62140 | MEDIUM | 5.3 | — | Sep 11, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions. |
| CVE-2026-62139 | MEDIUM | 4.3 | — | Sep 11, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions. |
| CVE-2026-62138 | MEDIUM | 6.5 | — | Sep 11, 2026 | Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions. |
| CVE-2026-62137 | MEDIUM | 5.3 | — | Sep 11, 2026 | Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions. |
| CVE-2026-62136 | MEDIUM | 5.3 | — | Sep 11, 2026 | Unauthenticated Broken Access Control in Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 vers... |
| CVE-2026-62135 | MEDIUM | 5.3 | — | Sep 11, 2026 | Unauthenticated Broken Access Control in Booktics <= 1.0.24 versions. |
| CVE-2026-62134 | MEDIUM | 4.3 | — | Sep 11, 2026 | Contributor Insecure Direct Object References (IDOR) in Starter Templates <= 4.7.5 versions. |
| CVE-2026-62133 | MEDIUM | 5.4 | — | Sep 11, 2026 | Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 2.1.5 versions. |
| CVE-2026-62132 | MEDIUM | 5.3 | — | Sep 11, 2026 | Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions. |
| CVE-2026-62114 | MEDIUM | 5.3 | — | Sep 11, 2026 | Unauthenticated Broken Access Control in Passster <= 4.3.13 versions. |
| CVE-2026-62113 | MEDIUM | 4.3 | — | Sep 11, 2026 | Contributor Insecure Direct Object References (IDOR) in Slim SEO <= 4.10.0 versions. |
| CVE-2026-62111 | MEDIUM | 6.5 | — | Sep 11, 2026 | Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 versions. |
| CVE-2026-62110 | MEDIUM | 6.5 | — | Sep 11, 2026 | Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions. |
| CVE-2026-62088 | MEDIUM | 5.3 | — | Sep 11, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive ... |
| CVE-2026-27378 | MEDIUM | 5.3 | — | Sep 11, 2026 | Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now