2026 CVE Vulnerabilities
68,738 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-87775 | HIGH | 8.6 | — | Sep 18, 2026 | The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to ... |
| CVE-2026-87774 | HIGH | 8.6 | — | Sep 18, 2026 | The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to ... |
| CVE-2026-87771 | HIGH | 8.6 | — | Sep 18, 2026 | The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them... |
| CVE-2026-87770 | HIGH | 8.6 | — | Sep 18, 2026 | The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using ... |
| CVE-2026-87767 | HIGH | 8.6 | — | Sep 18, 2026 | The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter bef... |
| CVE-2026-85350 | MEDIUM | 5.3 | — | Sep 18, 2026 | The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought ... |
| CVE-2026-85127 | HIGH | 8.8 | — | Sep 18, 2026 | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthentic... |
| CVE-2026-85123 | MEDIUM | 5.3 | — | Sep 18, 2026 | The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stor... |
| CVE-2026-85122 | HIGH | 8.8 | — | Sep 18, 2026 | The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stor... |
| CVE-2026-85009 | MEDIUM | 6.5 | — | Sep 18, 2026 | The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on ... |
| CVE-2026-84904 | LOW | 3.8 | — | Sep 18, 2026 | The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a gro... |
| CVE-2026-84903 | LOW | 2.7 | — | Sep 18, 2026 | The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password... |
| CVE-2026-84902 | MEDIUM | 6.8 | — | Sep 18, 2026 | The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when... |
| CVE-2026-84738 | CRITICAL | 9.1 | — | Sep 18, 2026 | The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import f... |
| CVE-2026-81810 | HIGH | 7.2 | — | Sep 18, 2026 | The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of... |
| CVE-2026-81340 | LOW | 3.8 | — | Sep 18, 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability... |
| CVE-2026-18912 | HIGH | 7.7 | — | Sep 18, 2026 | ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allo... |
| CVE-2026-18911 | HIGH | 7.5 | — | Sep 18, 2026 | ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolle... |
| CVE-2026-17086 | HIGH | 8.8 | — | Sep 18, 2026 | The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object I... |
| CVE-2026-93468 | HIGH | 7.5 | — | Sep 18, 2026 | The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit R... |
| CVE-2026-93467 | CRITICAL | 9.8 | — | Sep 18, 2026 | The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execu... |
| CVE-2026-93371 | HIGH | 8.3 | 1.4% | Sep 18, 2026 | A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function Ne... |
| CVE-2026-92991 | MEDIUM | 5.4 | — | Sep 18, 2026 | The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in variou... |
| CVE-2026-15650 | MEDIUM | 6.4 | — | Sep 18, 2026 | The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2026-14855 | MEDIUM | 6.4 | — | Sep 18, 2026 | The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now