2026 CVE Vulnerabilities
67,269 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1278 | MEDIUM | 4.4 | 0.2% | Mar 21, 2026 | The Mandatory Field plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions... |
| CVE-2026-1275 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Multi Post Carousel by Category plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slides' s... |
| CVE-2026-1253 | MEDIUM | 4.3 | 0.3% | Mar 21, 2026 | The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to unauthorized modification of data due to a... |
| CVE-2026-1247 | MEDIUM | 4.4 | 0.2% | Mar 21, 2026 | The Survey plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, a... |
| CVE-2026-1093 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The WPFAQBlock– FAQ & Accordion Plugin For Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2026-0609 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin plugin for WordPress is vulnerable to Stored ... |
| CVE-2026-4302 | HIGH | 7.2 | 0.3% | Mar 21, 2026 | The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up ... |
| CVE-2026-32899 | MEDIUM | 5.3 | 0.2% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.25 fail to consistently apply sender-policy checks to reaction_* and pin_* non-message... |
| CVE-2026-32898 | MEDIUM | 5.4 | 0.3% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.23 contain an authorization bypass vulnerability in the ACP client that auto-approves ... |
| CVE-2026-32897 | MEDIUM | 5.3 | 0.3% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.22 reuse gateway.auth.token as a fallback hash secret for owner-ID prompt obfuscation ... |
| CVE-2026-32896 | MEDIUM | 6.5 | 0.2% | Mar 21, 2026 | The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication ... |
| CVE-2026-32895 | MEDIUM | 5.4 | 0.2% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message subtype system event han... |
| CVE-2026-32067 | HIGH | 8.1 | 0.2% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access control f... |
| CVE-2026-32065 | MEDIUM | 6.5 | 0.3% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.25 contain an approval-integrity bypass vulnerability in system.run where rendered com... |
| CVE-2026-32064 | CRITICAL | 9.1 | 0.5% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observe... |
| CVE-2026-32058 | MEDIUM | 6.5 | 0.2% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with hos... |
| CVE-2026-32057 | HIGH | 7.1 | 0.3% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.25 contain an authentication bypass vulnerability in the trusted-proxy Control UI pair... |
| CVE-2026-32056 | CRITICAL | 9.8 | 0.6% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the system... |
| CVE-2026-32055 | HIGH | 8.2 | 0.3% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that allows... |
| CVE-2026-32054 | HIGH | 7.8 | 0.1% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in browser trace and download output path... |
| CVE-2026-32053 | MEDIUM | 6.5 | 0.3% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.23 contain a vulnerability in Twilio webhook event deduplication where normalized even... |
| CVE-2026-32052 | CRITICAL | 9.8 | 0.9% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper that allo... |
| CVE-2026-32051 | HIGH | 8.8 | 0.4% | Mar 21, 2026 | OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers wi... |
| CVE-2026-32050 | MEDIUM | 5.3 | 0.2% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.25 contain an access control vulnerability in signal reaction notification handling th... |
| CVE-2026-32049 | HIGH | 8.7 | 0.5% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buffering ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now