2026 CVE Vulnerabilities
67,200 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-94680 | MEDIUM | 6.5 | — | Sep 23, 2026 | Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions. |
| CVE-2026-94679 | MEDIUM | 5.4 | — | Sep 23, 2026 | Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions. |
| CVE-2026-94671 | MEDIUM | 6.5 | — | Sep 23, 2026 | Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions. |
| CVE-2026-94500 | MEDIUM | 6.5 | — | Sep 23, 2026 | Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions. |
| CVE-2026-94498 | MEDIUM | 6.5 | — | Sep 23, 2026 | Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions. |
| CVE-2026-94487 | HIGH | 8.1 | — | Sep 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Capabilities <= 2.50.1 versions. |
| CVE-2026-94461 | MEDIUM | 6.5 | — | Sep 23, 2026 | Contributor Cross Site Scripting (XSS) in Ditty <= 3.1.69 versions. |
| CVE-2026-94457 | MEDIUM | 4.8 | — | Sep 23, 2026 | Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions. |
| CVE-2026-94391 | MEDIUM | 6.5 | — | Sep 23, 2026 | Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions. |
| CVE-2026-94181 | HIGH | 7.4 | 0.3% | Sep 23, 2026 | An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a... |
| CVE-2026-94179 | HIGH | 7.1 | — | Sep 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button <= 2.4.9 versions. |
| CVE-2026-94176 | HIGH | 7.1 | — | Sep 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions. |
| CVE-2026-94174 | HIGH | 7.6 | — | Sep 23, 2026 | Administrator SQL Injection in Email Log <= 2.63 versions. |
| CVE-2026-94168 | MEDIUM | 6.5 | — | Sep 23, 2026 | Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions. |
| CVE-2026-94124 | HIGH | 8.5 | — | Sep 23, 2026 | Contributor SQL Injection in WP EasyCart <= 5.9.4 versions. |
| CVE-2026-94118 | MEDIUM | 6.5 | — | Sep 23, 2026 | Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions. |
| CVE-2026-94080 | MEDIUM | 5.3 | — | Sep 23, 2026 | Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions. |
| CVE-2026-94079 | MEDIUM | 5.3 | — | Sep 23, 2026 | Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions. |
| CVE-2026-93774 | HIGH | 7.1 | — | Sep 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions. |
| CVE-2026-93773 | HIGH | 8.5 | — | Sep 23, 2026 | Contributor SQL Injection in Mollie Forms <= 2.11.0 versions. |
| CVE-2026-93772 | MEDIUM | 6.5 | — | Sep 23, 2026 | Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions. |
| CVE-2026-93623 | MEDIUM | 5.3 | — | Sep 23, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in AI Engine <= 3.7.8 versions. |
| CVE-2026-93622 | HIGH | 7.1 | — | Sep 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login <= 1.5.9.3 versions. |
| CVE-2026-93620 | MEDIUM | 6.5 | — | Sep 23, 2026 | Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions. |
| CVE-2026-93618 | MEDIUM | 6.5 | — | Sep 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimp... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now