2026 CVE Vulnerabilities
67,286 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85574 | HIGH | 8 | 0.2% | Sep 19, 2026 | The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the conf... |
| CVE-2026-84750 | MEDIUM | 6.5 | 0.3% | Sep 19, 2026 | The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uplo... |
| CVE-2026-76790 | HIGH | 7.1 | 0.1% | Sep 19, 2026 | The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a ... |
| CVE-2026-76554 | HIGH | 7.2 | 0.3% | Sep 19, 2026 | The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to... |
| CVE-2026-19860 | MEDIUM | 5.5 | 0.2% | Sep 19, 2026 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PH... |
| CVE-2026-16557 | MEDIUM | 4.3 | 0.2% | Sep 19, 2026 | The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-build... |
| CVE-2026-93741 | CRITICAL | 10 | 0.6% | Sep 19, 2026 | A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the functio... |
| CVE-2026-92967 | MEDIUM | 6.1 | 0.2% | Sep 19, 2026 | The Pochipp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword' parameter in versions... |
| CVE-2026-92807 | HIGH | 8.8 | 0.3% | Sep 19, 2026 | The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions u... |
| CVE-2026-92229 | CRITICAL | 9.1 | 0.4% | Sep 19, 2026 | The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitr... |
| CVE-2026-89334 | MEDIUM | 6.5 | 0.4% | Sep 19, 2026 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to auth... |
| CVE-2026-89333 | MEDIUM | 6.5 | 0.3% | Sep 19, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere... |
| CVE-2026-89274 | CRITICAL | 9.1 | 0.4% | Sep 19, 2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and inclu... |
| CVE-2026-89093 | MEDIUM | 5.3 | 0.3% | Sep 19, 2026 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Info... |
| CVE-2026-89081 | MEDIUM | 6.1 | 0.2% | Sep 19, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin... |
| CVE-2026-88944 | MEDIUM | 4.3 | 0.3% | Sep 19, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to authorization bypass in all v... |
| CVE-2026-87909 | HIGH | 7.5 | 0.5% | Sep 19, 2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_m... |
| CVE-2026-84434 | CRITICAL | 9.8 | 0.7% | Sep 19, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.... |
| CVE-2026-15760 | MEDIUM | 6.5 | 0.2% | Sep 19, 2026 | The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in versions up to, and including... |
| CVE-2026-15660 | MEDIUM | 4.3 | 0.2% | Sep 19, 2026 | The SEO Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.4.7. Thi... |
| CVE-2026-13354 | HIGH | 7.2 | 0.2% | Sep 19, 2026 | The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Cont... |
| CVE-2026-12042 | MEDIUM | 4.4 | 0.2% | Sep 19, 2026 | The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v... |
| CVE-2026-77820 | MEDIUM | 6.4 | 0.2% | Sep 19, 2026 | The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty' Shortcode Attribute in all ... |
| CVE-2026-93923 | HIGH | 8.8 | 0.4% | Sep 19, 2026 | SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing st... |
| CVE-2026-93922 | HIGH | 8.8 | 0.5% | Sep 19, 2026 | SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing store... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now