2026 CVE Vulnerabilities
45,449 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9629 | MEDIUM | 6.4 | 0.2% | Jun 13, 2026 | The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up ... |
| CVE-2026-3297 | MEDIUM | 6.4 | 0.2% | Jun 13, 2026 | The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2026-2470 | MEDIUM | 4.3 | 0.2% | Jun 13, 2026 | The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorizatio... |
| CVE-2026-9134 | MEDIUM | 6.4 | 0.2% | Jun 13, 2026 | The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcod... |
| CVE-2026-54231 | MEDIUM | 5.5 | 0.1% | Jun 13, 2026 | A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script... |
| CVE-2026-12089 | MEDIUM | 4.9 | 0.3% | Jun 13, 2026 | The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in v... |
| CVE-2026-11443 | MEDIUM | 4.6 | 0.2% | Jun 13, 2026 | Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote at... |
| CVE-2026-11442 | MEDIUM | 6.5 | 1.3% | Jun 13, 2026 | Allegra exportReport Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attacker... |
| CVE-2026-54398 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions t... |
| CVE-2026-53867 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remo... |
| CVE-2026-53839 | MEDIUM | 6.5 | 0.3% | Jun 12, 2026 | OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching host... |
| CVE-2026-53837 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to va... |
| CVE-2026-53835 | MEDIUM | 4.3 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu dynamic-agent bindings that... |
| CVE-2026-53834 | MEDIUM | 6.5 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allow... |
| CVE-2026-53833 | MEDIUM | 6.5 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that allows auth... |
| CVE-2026-53830 | MEDIUM | 6.5 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and ... |
| CVE-2026-53827 | MEDIUM | 6.5 | 0.3% | Jun 12, 2026 | OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding that allows model-con... |
| CVE-2026-53826 | MEDIUM | 4.3 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.4.26 contains an information disclosure vulnerability in sandboxed session spawning that exposes th... |
| CVE-2026-53824 | MEDIUM | 6.5 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing callers with revoked slash tokens to contin... |
| CVE-2026-53820 | MEDIUM | 6.9 | 0.1% | Jun 12, 2026 | OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the bundle MCP loopback session-spawn path t... |
| CVE-2026-53523 | MEDIUM | 6.8 | 0.2% | Jun 12, 2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to be... |
| CVE-2026-53522 | MEDIUM | 6.5 | 0.3% | Jun 12, 2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to be... |
| CVE-2026-53521 | MEDIUM | 6.4 | 0.2% | Jun 12, 2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to b... |
| CVE-2026-53520 | MEDIUM | 6.5 | 0.3% | Jun 12, 2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to b... |
| CVE-2026-49397 | MEDIUM | 5.3 | 0.3% | Jun 12, 2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.0 to be... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now