2026 CVE Vulnerabilities
64,705 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100626 | MEDIUM | 4.3 | — | Sep 26, 2026 | capgo through 12.128.2 contains an insecure direct object reference vulnerability in the PUT /app/:appId endpoint that a... |
| CVE-2026-100624 | MEDIUM | 5.4 | — | Sep 26, 2026 | Capgo.app before 12.264.5 does not enforce upload expiry or build lifecycle state in the /build/upload/:jobId TUS proxy ... |
| CVE-2026-100621 | MEDIUM | 4.3 | — | Sep 26, 2026 | Capgo (capgo.app) contains an incomplete access-control/content-lock enforcement issue affecting all versions; no patch ... |
| CVE-2026-100616 | MEDIUM | 5.5 | — | Sep 26, 2026 | capgo.app is an over-the-air update platform for Capacitor apps. In all versions prior to a fix, the row-level security ... |
| CVE-2026-100613 | MEDIUM | 5.3 | — | Sep 26, 2026 | capgo.app is an over-the-air (OTA) update platform for Capacitor apps. In all versions up to and including the current r... |
| CVE-2026-100611 | MEDIUM | 6.5 | — | Sep 26, 2026 | Capgo (capgo.app backend, versions ≤ 12.261.0) improperly restricts which roles the apikey_manager organization role may... |
| CVE-2026-100609 | MEDIUM | 6.8 | — | Sep 26, 2026 | Flowise (npm packages `flowise` and `flowise-components`) through 3.1.4 looks up credentials by ID without filtering on ... |
| CVE-2026-100604 | MEDIUM | 5.4 | — | Sep 26, 2026 | ClawHub (openclaw/clawhub) contains an incorrect authorization vulnerability in the ClawHub application/backend: an orga... |
| CVE-2026-100603 | MEDIUM | 5.4 | — | Sep 26, 2026 | ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordina... |
| CVE-2026-100602 | MEDIUM | 6.5 | — | Sep 26, 2026 | ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature. ... |
| CVE-2026-100601 | MEDIUM | 5.3 | — | Sep 26, 2026 | ClawHub (openclaw/clawhub) application/backend contains a server-side request forgery vulnerability in the public profil... |
| CVE-2026-100600 | MEDIUM | 5.3 | — | Sep 26, 2026 | ClawHub (the openclaw/clawhub application/backend) does not bind anonymous HTTP API requests to a trusted caller identit... |
| CVE-2026-100313 | MEDIUM | 4.3 | — | Sep 26, 2026 | A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be... |
| CVE-2026-100312 | MEDIUM | 6.3 | — | Sep 26, 2026 | A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b6... |
| CVE-2026-96533 | MEDIUM | 5.8 | 0.1% | Sep 26, 2026 | The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-s... |
| CVE-2026-96531 | MEDIUM | 6.8 | 0.2% | Sep 26, 2026 | The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before re... |
| CVE-2026-92411 | MEDIUM | 6.8 | 0.2% | Sep 26, 2026 | The WP Delicious WordPress plugin before 1.10.8 does not validate or escape the HTML tag name taken from user-supplied ... |
| CVE-2026-89237 | MEDIUM | 6.8 | 0.2% | Sep 26, 2026 | The Bluff Post WordPress plugin through 1.1.1 does not sanitise and escape parameters before using them as identifiers i... |
| CVE-2026-84097 | MEDIUM | 6.5 | 0.2% | Sep 26, 2026 | The wp-review-slider-pro WordPress plugin before 12.7.12 does not sanitize a value stored through one of its AJAX handle... |
| CVE-2026-19708 | MEDIUM | 5.9 | 0.1% | Sep 26, 2026 | The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database back... |
| CVE-2026-11871 | MEDIUM | 5.3 | 0.1% | Sep 26, 2026 | The Team Members WordPress plugin through 9.2 does not perform any authorization or visibility check in an unauthentica... |
| CVE-2026-15273 | MEDIUM | 6.4 | 0.2% | Sep 26, 2026 | The Automatic.css plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI in all version 4.0.0... |
| CVE-2026-100595 | MEDIUM | 6.5 | — | Sep 26, 2026 | OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the diagnostics export command that a... |
| CVE-2026-100594 | MEDIUM | 6.5 | — | Sep 26, 2026 | OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the /export-trajectory endpoint that ... |
| CVE-2026-100593 | MEDIUM | 5.4 | — | Sep 26, 2026 | OpenClaw (npm package `openclaw`) before 2026.7.1 does not enforce the documented owner-only requirement for persistent ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now