2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-95523 | MEDIUM | 6.5 | — | Sep 23, 2026 | Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. |
| CVE-2026-95514 | MEDIUM | 5.3 | — | Sep 23, 2026 | Unauthenticated Bypass Vulnerability in Netgsm <= 2.10.0 versions. |
| CVE-2026-94684 | MEDIUM | 6.5 | — | Sep 23, 2026 | Contributor Cross Site Scripting (XSS) in Ocean Extra <= 2.6.1 versions. |
| CVE-2026-94682 | MEDIUM | 6.5 | — | Sep 23, 2026 | Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine <= 1.5.6 versions. |
| CVE-2026-94680 | MEDIUM | 6.5 | — | Sep 23, 2026 | Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions. |
| CVE-2026-94679 | MEDIUM | 5.4 | — | Sep 23, 2026 | Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions. |
| CVE-2026-94671 | MEDIUM | 6.5 | — | Sep 23, 2026 | Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions. |
| CVE-2026-94500 | MEDIUM | 6.5 | — | Sep 23, 2026 | Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions. |
| CVE-2026-94498 | MEDIUM | 6.5 | — | Sep 23, 2026 | Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions. |
| CVE-2026-94461 | MEDIUM | 6.5 | — | Sep 23, 2026 | Contributor Cross Site Scripting (XSS) in Ditty <= 3.1.69 versions. |
| CVE-2026-94457 | MEDIUM | 4.8 | — | Sep 23, 2026 | Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions. |
| CVE-2026-94391 | MEDIUM | 6.5 | — | Sep 23, 2026 | Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions. |
| CVE-2026-94168 | MEDIUM | 6.5 | — | Sep 23, 2026 | Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions. |
| CVE-2026-94118 | MEDIUM | 6.5 | — | Sep 23, 2026 | Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions. |
| CVE-2026-94080 | MEDIUM | 5.3 | — | Sep 23, 2026 | Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions. |
| CVE-2026-94079 | MEDIUM | 5.3 | — | Sep 23, 2026 | Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions. |
| CVE-2026-93772 | MEDIUM | 6.5 | — | Sep 23, 2026 | Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions. |
| CVE-2026-93623 | MEDIUM | 5.3 | — | Sep 23, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in AI Engine <= 3.7.8 versions. |
| CVE-2026-93620 | MEDIUM | 6.5 | — | Sep 23, 2026 | Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions. |
| CVE-2026-93618 | MEDIUM | 6.5 | — | Sep 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimp... |
| CVE-2026-93529 | MEDIUM | 6.5 | — | Sep 23, 2026 | Contributor Broken Access Control in WSP MCP – AI Agents Connector <= 2.7.0 versions. |
| CVE-2026-93513 | MEDIUM | 4.3 | — | Sep 23, 2026 | Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions. |
| CVE-2026-93421 | MEDIUM | 5.3 | — | Sep 23, 2026 | Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /_... |
| CVE-2026-92700 | MEDIUM | 6.3 | — | Sep 23, 2026 | Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/fil... |
| CVE-2026-92692 | MEDIUM | 6.9 | — | Sep 23, 2026 | Sulu is an open-source PHP content management system based on the Symfony framework. Prior to 2.6.25 and 3.0.8, the affe... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now