2026 CVE Vulnerabilities
67,696 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12384 | HIGH | 8.8 | — | Sep 18, 2026 | Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse. ... |
| CVE-2026-11757 | MEDIUM | 6.1 | — | Sep 18, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Tec... |
| CVE-2026-92714 | MEDIUM | 6.5 | — | Sep 18, 2026 | The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and inclu... |
| CVE-2026-92619 | HIGH | 7.2 | — | Sep 18, 2026 | The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11... |
| CVE-2026-92561 | MEDIUM | 6.1 | — | Sep 18, 2026 | The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in... |
| CVE-2026-91707 | MEDIUM | 5.3 | — | Sep 18, 2026 | The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.... |
| CVE-2026-90977 | MEDIUM | 5.3 | — | Sep 18, 2026 | The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is e... |
| CVE-2026-90976 | MEDIUM | 5.3 | — | Sep 18, 2026 | The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled before creating an acco... |
| CVE-2026-89413 | HIGH | 8.1 | — | Sep 18, 2026 | The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.... |
| CVE-2026-89330 | MEDIUM | 6.1 | — | Sep 18, 2026 | The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for ... |
| CVE-2026-89278 | MEDIUM | 5.3 | — | Sep 18, 2026 | The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is v... |
| CVE-2026-89138 | MEDIUM | 4.3 | — | Sep 18, 2026 | The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.... |
| CVE-2026-88994 | MEDIUM | 6.6 | — | Sep 18, 2026 | The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a ... |
| CVE-2026-86800 | MEDIUM | 5.3 | — | Sep 18, 2026 | The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before ... |
| CVE-2026-86796 | MEDIUM | 5.3 | — | Sep 18, 2026 | The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request befo... |
| CVE-2026-84909 | MEDIUM | 6.4 | — | Sep 18, 2026 | The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2026-79713 | MEDIUM | 6.5 | — | Sep 18, 2026 | The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page-... |
| CVE-2026-75017 | MEDIUM | 4.3 | — | Sep 18, 2026 | The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plu... |
| CVE-2026-75016 | MEDIUM | 6.4 | — | Sep 18, 2026 | The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's client... |
| CVE-2026-18317 | MEDIUM | 4.3 | — | Sep 18, 2026 | The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to a... |
| CVE-2026-17576 | MEDIUM | 6.5 | — | Sep 18, 2026 | The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to,... |
| CVE-2026-12106 | MEDIUM | 6.4 | — | Sep 18, 2026 | The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, ... |
| CVE-2026-93485 | HIGH | 7.1 | 0.2% | Sep 18, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPre... |
| CVE-2026-90984 | MEDIUM | 5.8 | — | Sep 18, 2026 | The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch... |
| CVE-2026-90978 | HIGH | 7.1 | — | Sep 18, 2026 | The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonc... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now