2026 CVE Vulnerabilities
64,997 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84899 | MEDIUM | 6.8 | 0.2% | Sep 5, 2026 | The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it ... |
| CVE-2026-84898 | MEDIUM | 6.6 | 0.3% | Sep 5, 2026 | The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include ... |
| CVE-2026-84896 | MEDIUM | 6.8 | 0.2% | Sep 5, 2026 | The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before out... |
| CVE-2026-84221 | MEDIUM | 6.8 | 0.2% | Sep 5, 2026 | The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allo... |
| CVE-2026-84022 | MEDIUM | 6.8 | 0.2% | Sep 5, 2026 | The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before out... |
| CVE-2026-84021 | MEDIUM | 6.8 | 0.2% | Sep 5, 2026 | The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTM... |
| CVE-2026-83544 | MEDIUM | 6.8 | 0.2% | Sep 5, 2026 | The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute before outputting it... |
| CVE-2026-83543 | MEDIUM | 4.1 | 0.2% | Sep 5, 2026 | The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, all... |
| CVE-2026-82846 | MEDIUM | 6.8 | 0.2% | Sep 5, 2026 | The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting the... |
| CVE-2026-81424 | MEDIUM | 5.3 | 0.2% | Sep 5, 2026 | The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is c... |
| CVE-2026-81423 | MEDIUM | 4.3 | 0.2% | Sep 5, 2026 | The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redi... |
| CVE-2026-78149 | MEDIUM | 5.3 | 0.3% | Sep 5, 2026 | The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its c... |
| CVE-2026-4361 | MEDIUM | 5 | 0.3% | Sep 5, 2026 | The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. ... |
| CVE-2026-3853 | MEDIUM | 6.4 | 0.2% | Sep 5, 2026 | The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the... |
| CVE-2026-19861 | MEDIUM | 4.7 | 0.2% | Sep 5, 2026 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a... |
| CVE-2026-18843 | MEDIUM | 6.1 | 0.2% | Sep 5, 2026 | The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no... |
| CVE-2026-15247 | MEDIUM | 5.4 | 0.2% | Sep 5, 2026 | The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a se... |
| CVE-2026-14975 | MEDIUM | 6.5 | 0.7% | Sep 5, 2026 | The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3... |
| CVE-2026-8625 | MEDIUM | 6.4 | 0.2% | Sep 5, 2026 | The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-... |
| CVE-2026-8623 | MEDIUM | 6.4 | 0.2% | Sep 5, 2026 | The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-... |
| CVE-2026-83628 | MEDIUM | 4.3 | 0.2% | Sep 5, 2026 | The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 ... |
| CVE-2026-18404 | MEDIUM | 6.4 | 0.2% | Sep 5, 2026 | The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consen... |
| CVE-2026-86137 | MEDIUM | 6.1 | 0.1% | Sep 5, 2026 | In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro i... |
| CVE-2026-86100 | MEDIUM | 6.4 | 0.2% | Sep 5, 2026 | Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload fro... |
| CVE-2026-52774 | MEDIUM | 6.1 | 0.5% | Sep 5, 2026 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki's Bazar widget handler reflects the id GET para... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now