2026 CVE Vulnerabilities
64,751 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6088 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6087 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6086 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6085 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6084 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6083 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6082 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-96448 | MEDIUM | 6.6 | 0.2% | Sep 25, 2026 | A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management ... |
| CVE-2026-93747 | MEDIUM | 6.4 | — | Sep 25, 2026 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in v... |
| CVE-2026-93656 | MEDIUM | 6.4 | — | Sep 25, 2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v... |
| CVE-2026-88996 | MEDIUM | 6.1 | — | Sep 25, 2026 | The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPres... |
| CVE-2026-17602 | MEDIUM | 4.9 | — | Sep 25, 2026 | The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Directory Traversal in a... |
| CVE-2026-17577 | MEDIUM | 6.1 | — | Sep 25, 2026 | The SSL Zen plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'uri' (and 'host') parameters i... |
| CVE-2026-13179 | MEDIUM | 6.4 | — | Sep 25, 2026 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnera... |
| CVE-2026-12037 | MEDIUM | 5.5 | — | Sep 25, 2026 | The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions ... |
| CVE-2026-97846 | MEDIUM | 6.8 | — | Sep 25, 2026 | Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client ... |
| CVE-2026-96766 | MEDIUM | 6.4 | — | Sep 25, 2026 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ... |
| CVE-2026-94376 | MEDIUM | 6.4 | — | Sep 25, 2026 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Stor... |
| CVE-2026-93899 | MEDIUM | 6.5 | — | Sep 25, 2026 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to gene... |
| CVE-2026-93897 | MEDIUM | 6.4 | — | Sep 25, 2026 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ... |
| CVE-2026-93477 | MEDIUM | 5.9 | — | Sep 25, 2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a... |
| CVE-2026-92829 | MEDIUM | 4.3 | — | Sep 25, 2026 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass in all ve... |
| CVE-2026-92799 | MEDIUM | 5.3 | — | Sep 25, 2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorization Bypass... |
| CVE-2026-92746 | MEDIUM | 6.4 | — | Sep 25, 2026 | The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2026-92212 | MEDIUM | 6.1 | — | Sep 25, 2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now