2026 CVE Vulnerabilities
65,063 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84780 | MEDIUM | 5.3 | 0.3% | Sep 2, 2026 | Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions. |
| CVE-2026-84775 | MEDIUM | 5.3 | — | Sep 2, 2026 | Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions. |
| CVE-2026-84772 | MEDIUM | 5.5 | — | Sep 2, 2026 | Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions. |
| CVE-2026-84771 | MEDIUM | 5.3 | — | Sep 2, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions. |
| CVE-2026-84760 | MEDIUM | 5.3 | — | Sep 2, 2026 | Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions. |
| CVE-2026-84217 | MEDIUM | 5.4 | 0.3% | Sep 2, 2026 | Missing Authorization vulnerability in Mamunur Rashid Classified Listing classified-listing allows Accessing Functionali... |
| CVE-2026-83562 | MEDIUM | 6.5 | — | Sep 2, 2026 | Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions. |
| CVE-2026-82223 | MEDIUM | 6.5 | — | Sep 2, 2026 | Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions. |
| CVE-2026-66652 | MEDIUM | 5.4 | — | Sep 2, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forgery. This issue ... |
| CVE-2026-32773 | MEDIUM | 6.1 | 0.3% | Sep 2, 2026 | There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generat... |
| CVE-2026-84175 | MEDIUM | 5.3 | 0.3% | Sep 2, 2026 | In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (Web of Things) ThingModels over HTTP from URLs... |
| CVE-2026-53683 | MEDIUM | 4.3 | 0.2% | Sep 2, 2026 | reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location... |
| CVE-2026-3850 | MEDIUM | 6.4 | 0.2% | Sep 2, 2026 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of the `et_pb... |
| CVE-2026-82182 | MEDIUM | 4.1 | 0.2% | Sep 2, 2026 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied list of iden... |
| CVE-2026-81583 | MEDIUM | 5.4 | 0.2% | Sep 2, 2026 | The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site sig... |
| CVE-2026-81432 | MEDIUM | 4.3 | 0.1% | Sep 2, 2026 | The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does not have CSRF protection on some of its AJAX action... |
| CVE-2026-81428 | MEDIUM | 6.5 | 0.2% | Sep 2, 2026 | The WC Vendors WordPress plugin before 2.7.2.1 does not verify ownership or the object type of user-supplied IDs when s... |
| CVE-2026-81427 | MEDIUM | 4.3 | 0.2% | Sep 2, 2026 | The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order shipment st... |
| CVE-2026-81426 | MEDIUM | 4.3 | 0.1% | Sep 2, 2026 | The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its front-end order shipment st... |
| CVE-2026-81199 | MEDIUM | 5.3 | 0.1% | Sep 2, 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before retu... |
| CVE-2026-81197 | MEDIUM | 5.3 | 0.2% | Sep 2, 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not restrict access to a REST route that lists... |
| CVE-2026-81195 | MEDIUM | 5.3 | 0.2% | Sep 2, 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before retu... |
| CVE-2026-81194 | MEDIUM | 4.3 | 0.2% | Sep 2, 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization when retriev... |
| CVE-2026-79621 | MEDIUM | 4.3 | 0.1% | Sep 2, 2026 | The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user can store b... |
| CVE-2026-78151 | MEDIUM | 5.3 | 0.2% | Sep 2, 2026 | The FormLayer WordPress plugin before 1.0.9 does not perform any authorization check before returning a form's full stor... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now