2026 CVE Vulnerabilities

67,269 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-1278MEDIUM4.4The Mandatory Field plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions...
CVE-2026-1275MEDIUM6.4The Multi Post Carousel by Category plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slides' s...
CVE-2026-1253MEDIUM4.3The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to unauthorized modification of data due to a...
CVE-2026-1247MEDIUM4.4The Survey plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, a...
CVE-2026-1093MEDIUM6.4The WPFAQBlock– FAQ & Accordion Plugin For Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2026-0609MEDIUM6.4The Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin plugin for WordPress is vulnerable to Stored ...
CVE-2026-4302HIGH7.2The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up ...
CVE-2026-32899MEDIUM5.3OpenClaw versions prior to 2026.2.25 fail to consistently apply sender-policy checks to reaction_* and pin_* non-message...
CVE-2026-32898MEDIUM5.4OpenClaw versions prior to 2026.2.23 contain an authorization bypass vulnerability in the ACP client that auto-approves ...
CVE-2026-32897MEDIUM5.3OpenClaw versions prior to 2026.2.22 reuse gateway.auth.token as a fallback hash secret for owner-ID prompt obfuscation ...
CVE-2026-32896MEDIUM6.5The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication ...
CVE-2026-32895MEDIUM5.4OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message subtype system event han...
CVE-2026-32067HIGH8.1OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access control f...
CVE-2026-32065MEDIUM6.5OpenClaw versions prior to 2026.2.25 contain an approval-integrity bypass vulnerability in system.run where rendered com...
CVE-2026-32064CRITICAL9.1OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observe...
CVE-2026-32058MEDIUM6.5OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with hos...
CVE-2026-32057HIGH7.1OpenClaw versions prior to 2026.2.25 contain an authentication bypass vulnerability in the trusted-proxy Control UI pair...
CVE-2026-32056CRITICAL9.8OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the system...
CVE-2026-32055HIGH8.2OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that allows...
CVE-2026-32054HIGH7.8OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in browser trace and download output path...
CVE-2026-32053MEDIUM6.5OpenClaw versions prior to 2026.2.23 contain a vulnerability in Twilio webhook event deduplication where normalized even...
CVE-2026-32052CRITICAL9.8OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper that allo...
CVE-2026-32051HIGH8.8OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers wi...
CVE-2026-32050MEDIUM5.3OpenClaw versions prior to 2026.2.25 contain an access control vulnerability in signal reaction notification handling th...
CVE-2026-32049HIGH8.7OpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buffering ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now