2026 CVE Vulnerabilities
64,997 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15550 | MEDIUM | 4.3 | 0.2% | Sep 5, 2026 | The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and inclu... |
| CVE-2026-12843 | MEDIUM | 5.4 | 0.2% | Sep 5, 2026 | The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to ... |
| CVE-2026-86178 | MEDIUM | 5.4 | 0.2% | Sep 5, 2026 | Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowin... |
| CVE-2026-86176 | MEDIUM | 4.3 | 0.2% | Sep 5, 2026 | NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, S... |
| CVE-2026-86175 | MEDIUM | 6.5 | 0.3% | Sep 5, 2026 | NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authen... |
| CVE-2026-86174 | MEDIUM | 4.3 | 0.2% | Sep 5, 2026 | Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. A... |
| CVE-2026-86122 | MEDIUM | 5 | 0.2% | Sep 5, 2026 | Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure ar... |
| CVE-2026-86120 | MEDIUM | 4.3 | 0.2% | Sep 5, 2026 | APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to en... |
| CVE-2026-86118 | MEDIUM | 4.3 | 0.3% | Sep 5, 2026 | gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authentic... |
| CVE-2026-86116 | MEDIUM | 6.5 | 0.4% | Sep 5, 2026 | Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any a... |
| CVE-2026-86115 | MEDIUM | 5 | 0.3% | Sep 5, 2026 | Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skippi... |
| CVE-2026-86114 | MEDIUM | 6.5 | 0.2% | Sep 5, 2026 | Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to creat... |
| CVE-2026-86113 | MEDIUM | 6.5 | 0.2% | Sep 5, 2026 | BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authe... |
| CVE-2026-86112 | MEDIUM | 5.4 | 0.2% | Sep 5, 2026 | BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing auth... |
| CVE-2026-86111 | MEDIUM | 6.5 | 0.3% | Sep 5, 2026 | BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated... |
| CVE-2026-76573 | MEDIUM | 6.4 | 0.2% | Sep 5, 2026 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'not_fo... |
| CVE-2026-85414 | MEDIUM | 6.4 | 0.2% | Sep 5, 2026 | The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings' Shortco... |
| CVE-2026-75586 | MEDIUM | 6.1 | 0.2% | Sep 5, 2026 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'formData[... |
| CVE-2026-75018 | MEDIUM | 4.3 | 0.3% | Sep 5, 2026 | The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including... |
| CVE-2026-84937 | MEDIUM | 6.8 | 0.2% | Sep 5, 2026 | The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input be... |
| CVE-2026-84936 | MEDIUM | 5.3 | 0.2% | Sep 5, 2026 | The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allo... |
| CVE-2026-84931 | MEDIUM | 6.8 | 0.2% | Sep 5, 2026 | The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before ... |
| CVE-2026-84930 | MEDIUM | 6.8 | 0.2% | Sep 5, 2026 | The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute... |
| CVE-2026-84901 | MEDIUM | 4.9 | 0.2% | Sep 5, 2026 | The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management RES... |
| CVE-2026-84899 | MEDIUM | 6.8 | 0.2% | Sep 5, 2026 | The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now