2026 CVE Vulnerabilities
67,696 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92622 | MEDIUM | 6.4 | — | Sep 18, 2026 | The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lightbox_class' Shortcode... |
| CVE-2026-92554 | MEDIUM | 6.1 | 0.3% | Sep 18, 2026 | The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Reflecte... |
| CVE-2026-92249 | MEDIUM | 6.1 | 0.3% | Sep 18, 2026 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter i... |
| CVE-2026-90981 | MEDIUM | 6.1 | — | Sep 18, 2026 | The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting... |
| CVE-2026-89059 | HIGH | 7.5 | — | Sep 18, 2026 | A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing ... |
| CVE-2026-89058 | HIGH | 7.4 | 0.5% | Sep 18, 2026 | A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Ori... |
| CVE-2026-85705 | HIGH | 7.5 | — | Sep 18, 2026 | The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and 'longitude' REST API... |
| CVE-2026-85652 | MEDIUM | 6.5 | — | Sep 18, 2026 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injectio... |
| CVE-2026-75961 | MEDIUM | 4.9 | 0.4% | Sep 18, 2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the ... |
| CVE-2026-75157 | HIGH | 7.5 | 0.2% | Sep 18, 2026 | Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `E... |
| CVE-2026-67103 | HIGH | 7.6 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to ... |
| CVE-2026-67102 | HIGH | 8.1 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a lo... |
| CVE-2026-67101 | CRITICAL | 9.3 | 0.3% | Sep 18, 2026 | HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functional... |
| CVE-2026-67100 | CRITICAL | 9.8 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. w... |
| CVE-2026-18442 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injecti... |
| CVE-2026-17607 | MEDIUM | 6.5 | — | Sep 18, 2026 | The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the ... |
| CVE-2026-17586 | MEDIUM | 6.4 | — | Sep 18, 2026 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vkExUnit_cta_img... |
| CVE-2026-16777 | MEDIUM | 4.9 | — | Sep 18, 2026 | The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to... |
| CVE-2026-15275 | HIGH | 7.5 | 0.4% | Sep 18, 2026 | The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_searc... |
| CVE-2026-15004 | MEDIUM | 5.4 | 0.2% | Sep 18, 2026 | The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2026-14472 | MEDIUM | 6.4 | — | Sep 18, 2026 | The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kubio/copyright Block Co... |
| CVE-2026-14323 | HIGH | 7.5 | — | Sep 18, 2026 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in... |
| CVE-2026-13471 | MEDIUM | 4.3 | — | Sep 18, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direc... |
| CVE-2026-12954 | HIGH | 8.8 | 0.5% | Sep 18, 2026 | The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including... |
| CVE-2026-12739 | MEDIUM | 4.3 | 0.3% | Sep 18, 2026 | The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypas... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now