2026 CVE Vulnerabilities
67,245 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93836 | HIGH | 7.2 | 0.2% | Sep 22, 2026 | The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' ... |
| CVE-2026-93778 | HIGH | 7.2 | 0.2% | Sep 22, 2026 | The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (import... |
| CVE-2026-92969 | HIGH | 8.1 | 0.7% | Sep 22, 2026 | The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Local File Inclusion in a... |
| CVE-2026-92235 | HIGH | 8.1 | 0.4% | Sep 22, 2026 | The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, an... |
| CVE-2026-91092 | MEDIUM | 4.3 | 0.2% | Sep 22, 2026 | The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5.... |
| CVE-2026-87082 | HIGH | 7.5 | 0.2% | Sep 22, 2026 | Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in... |
| CVE-2026-87081 | HIGH | 7.5 | 0.2% | Sep 22, 2026 | Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label... |
| CVE-2026-87080 | CRITICAL | 9.1 | 0.1% | Sep 22, 2026 | Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never... |
| CVE-2026-87079 | HIGH | 7.5 | 0.2% | Sep 22, 2026 | Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long... |
| CVE-2026-87078 | CRITICAL | 9.1 | 0.2% | Sep 22, 2026 | Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_pu... |
| CVE-2026-7622 | MEDIUM | 4.3 | 0.2% | Sep 22, 2026 | The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.1. This is ... |
| CVE-2026-74766 | HIGH | 8.4 | 0.2% | Sep 22, 2026 | Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that r... |
| CVE-2026-74765 | MEDIUM | 6.5 | 0.2% | Sep 22, 2026 | Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumula... |
| CVE-2026-6922 | HIGH | 7.1 | 0.3% | Sep 22, 2026 | The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Authorization in all ve... |
| CVE-2026-4123 | MEDIUM | 4.3 | 0.2% | Sep 22, 2026 | The RW Elephant Rental Inventory plugin for WordPress is vulnerable to Missing Authorization in all versions up to and i... |
| CVE-2026-1645 | MEDIUM | 4.4 | 0.2% | Sep 22, 2026 | The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_currency' parameter and the... |
| CVE-2026-18439 | MEDIUM | 4.3 | 0.3% | Sep 22, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere... |
| CVE-2026-18345 | MEDIUM | 4.3 | 0.2% | Sep 22, 2026 | The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ... |
| CVE-2026-16778 | MEDIUM | 6.4 | 0.2% | Sep 22, 2026 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2026-12995 | MEDIUM | 4.3 | 0.2% | Sep 22, 2026 | The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, ... |
| CVE-2026-94504 | HIGH | 7.2 | 0.3% | Sep 22, 2026 | Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy su... |
| CVE-2026-92438 | HIGH | 8.8 | 0.3% | Sep 22, 2026 | The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submis... |
| CVE-2026-91827 | HIGH | 7.5 | 0.3% | Sep 22, 2026 | The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when a... |
| CVE-2026-89412 | HIGH | 7.2 | 0.3% | Sep 22, 2026 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2026-93655 | MEDIUM | 6.1 | 0.2% | Sep 22, 2026 | The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill' param... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now