2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86842 | MEDIUM | 6.8 | 0.2% | Sep 23, 2026 | The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flip... |
| CVE-2026-86785 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its RES... |
| CVE-2026-86783 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility chec... |
| CVE-2026-86603 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, all... |
| CVE-2026-86602 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, all... |
| CVE-2026-85006 | MEDIUM | 6.8 | 0.2% | Sep 23, 2026 | The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets... |
| CVE-2026-84741 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding the... |
| CVE-2026-84168 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The Easy Hide Login WordPress plugin before 1.7 does not fully enforce its hidden-login protection, allowing an unauthen... |
| CVE-2026-84150 | MEDIUM | 5.4 | 0.2% | Sep 23, 2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not verify ... |
| CVE-2026-84098 | MEDIUM | 6.5 | 0.2% | Sep 23, 2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properl... |
| CVE-2026-84046 | MEDIUM | 5 | 0.2% | Sep 23, 2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not validat... |
| CVE-2026-84027 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check u... |
| CVE-2026-84026 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not restric... |
| CVE-2026-83555 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token ... |
| CVE-2026-81339 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when ... |
| CVE-2026-81338 | MEDIUM | 4.6 | 0.1% | Sep 23, 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HTML in use... |
| CVE-2026-80342 | MEDIUM | 6.5 | 0.2% | Sep 23, 2026 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied i... |
| CVE-2026-77766 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope o... |
| CVE-2026-77765 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the... |
| CVE-2026-18365 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on one of its AJAX actions, al... |
| CVE-2026-18364 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on several of its AJAX actions... |
| CVE-2026-16264 | MEDIUM | 6.5 | 0.2% | Sep 23, 2026 | The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management ... |
| CVE-2026-96258 | MEDIUM | 4.3 | 0.3% | Sep 23, 2026 | A vulnerability has been found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722. This affects an unkno... |
| CVE-2026-95957 | MEDIUM | 4.3 | 0.5% | Sep 23, 2026 | A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0. This issue affects the fun... |
| CVE-2026-95930 | MEDIUM | 6.3 | 0.4% | Sep 23, 2026 | A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the fu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now