2026 CVE Vulnerabilities
64,889 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85132 | MEDIUM | 4.3 | 0.1% | Sep 9, 2026 | The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie ... |
| CVE-2026-85037 | MEDIUM | 5.3 | 0.1% | Sep 9, 2026 | The Sunshine Photo Cart WordPress plugin before 3.7 does not validate that a client-supplied price identifier belongs t... |
| CVE-2026-84908 | MEDIUM | 5.3 | 0.2% | Sep 9, 2026 | The WPFunnels plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.12.13. Thi... |
| CVE-2026-84222 | MEDIUM | 5.3 | 0.1% | Sep 9, 2026 | The Kirki WordPress plugin before 6.3.0 does not check whether the requester is allowed to read a post before rendering... |
| CVE-2026-84113 | MEDIUM | 4.1 | 0.2% | Sep 9, 2026 | The Quentn WP WordPress plugin before 1.2.15 does not properly sanitise and escape a parameter before using it in an SQL... |
| CVE-2026-83541 | MEDIUM | 6.8 | 0.2% | Sep 9, 2026 | The Sina Extension for Elementor WordPress plugin before 3.10.4 does not properly escape a Table widget setting before o... |
| CVE-2026-82848 | MEDIUM | 5.3 | 0.1% | Sep 9, 2026 | The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enro... |
| CVE-2026-82185 | MEDIUM | 4.3 | 0.1% | Sep 9, 2026 | The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have capability or nonce checks on some of its A/B testi... |
| CVE-2026-82184 | MEDIUM | 5.3 | 0.1% | Sep 9, 2026 | The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visit... |
| CVE-2026-81741 | MEDIUM | 4.7 | 0.1% | Sep 9, 2026 | The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.7.2 does not restrict the redirect... |
| CVE-2026-81022 | MEDIUM | 5.3 | 0.1% | Sep 9, 2026 | The SupportCandy WordPress plugin before 3.5.3 does not validate a submitted per-ticket authorization code before discl... |
| CVE-2026-81021 | MEDIUM | 5.3 | 0.1% | Sep 9, 2026 | The SupportCandy WordPress plugin before 3.5.3 does not perform an authorization check on one of its support-ticket att... |
| CVE-2026-80341 | MEDIUM | 5.9 | 0.1% | Sep 9, 2026 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not verify that a stored payment method b... |
| CVE-2026-80340 | MEDIUM | 5.3 | 0.1% | Sep 9, 2026 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not validate the order key before adding ... |
| CVE-2026-80339 | MEDIUM | 5.3 | 0.1% | Sep 9, 2026 | The Payment Plugins for Stripe WooCommerce WordPress plugin before 4.0.12 does not validate the order key before adding ... |
| CVE-2026-75905 | MEDIUM | 4.3 | 0.3% | Sep 9, 2026 | The WP Recipe Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.... |
| CVE-2026-75861 | MEDIUM | 6.5 | 0.1% | Sep 9, 2026 | The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not verify that the user redeeming a gift ca... |
| CVE-2026-19946 | MEDIUM | 4.3 | 0.2% | Sep 9, 2026 | The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9.... |
| CVE-2026-18042 | MEDIUM | 5.3 | 0.1% | Sep 9, 2026 | The WP Travel WordPress plugin before 12.0.2 does not verify that the requester is authorized to act on the booking tar... |
| CVE-2026-87737 | MEDIUM | 5.9 | 0.2% | Sep 9, 2026 | An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST ... |
| CVE-2026-87736 | MEDIUM | 4.3 | 0.2% | Sep 9, 2026 | An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds ... |
| CVE-2026-87735 | MEDIUM | 4.3 | 0.1% | Sep 9, 2026 | An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml. There is an undocumented exception for a... |
| CVE-2026-87733 | MEDIUM | 6.2 | 0.1% | Sep 9, 2026 | An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Ds... |
| CVE-2026-87732 | MEDIUM | 6.2 | 0.1% | Sep 9, 2026 | An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and C... |
| CVE-2026-21113 | MEDIUM | 5.5 | 0.1% | Sep 9, 2026 | Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now