2026 CVE Vulnerabilities
64,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93983 | MEDIUM | 5 | 0.2% | Sep 19, 2026 | OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users ... |
| CVE-2026-93981 | MEDIUM | 4.7 | 0.1% | Sep 19, 2026 | hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a stri... |
| CVE-2026-9858 | MEDIUM | 4.3 | 0.2% | Sep 19, 2026 | The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and ... |
| CVE-2026-9766 | MEDIUM | 4.3 | 0.2% | Sep 19, 2026 | The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin... |
| CVE-2026-9613 | MEDIUM | 4.3 | 0.3% | Sep 19, 2026 | The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all version... |
| CVE-2026-9289 | MEDIUM | 5.3 | 0.4% | Sep 19, 2026 | The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi... |
| CVE-2026-8354 | MEDIUM | 6.4 | 0.2% | Sep 19, 2026 | The Gum Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pop_tag' paramete... |
| CVE-2026-76579 | MEDIUM | 4.7 | 0.2% | Sep 19, 2026 | The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all ... |
| CVE-2026-5410 | MEDIUM | 6.4 | 0.2% | Sep 19, 2026 | The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions ... |
| CVE-2026-1256 | MEDIUM | 6.4 | 0.2% | Sep 19, 2026 | The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple A... |
| CVE-2026-18346 | MEDIUM | 5.3 | 0.3% | Sep 19, 2026 | The TikTok plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.1. This ... |
| CVE-2026-9855 | MEDIUM | 6.5 | 0.3% | Sep 19, 2026 | The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the 'post_ID' parameter in all... |
| CVE-2026-9832 | MEDIUM | 5.3 | 0.2% | Sep 19, 2026 | The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptograph... |
| CVE-2026-9615 | MEDIUM | 4.3 | 0.3% | Sep 19, 2026 | The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. T... |
| CVE-2026-9232 | MEDIUM | 6.5 | 0.3% | Sep 19, 2026 | The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in... |
| CVE-2026-87917 | MEDIUM | 6.1 | 0.2% | Sep 19, 2026 | The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data' Dynam... |
| CVE-2026-7527 | MEDIUM | 4.7 | 0.2% | Sep 19, 2026 | The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all version... |
| CVE-2026-75959 | MEDIUM | 4.9 | 0.3% | Sep 19, 2026 | The GoPay for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'log_table_filter' paramet... |
| CVE-2026-6295 | MEDIUM | 4.9 | 0.3% | Sep 19, 2026 | The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and inc... |
| CVE-2026-5400 | MEDIUM | 6.4 | 0.2% | Sep 19, 2026 | The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media field filter values ... |
| CVE-2026-4792 | MEDIUM | 5.3 | 0.3% | Sep 19, 2026 | The Bread plugin for WordPress is vulnerable to information exposure in versions up to and including 2.9.12. This is due... |
| CVE-2026-2422 | MEDIUM | 6.4 | 0.2% | Sep 19, 2026 | The WP Composer – The Easiest Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pb... |
| CVE-2026-2278 | MEDIUM | 4.3 | 0.2% | Sep 19, 2026 | The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch... |
| CVE-2026-1984 | MEDIUM | 5.3 | 0.2% | Sep 19, 2026 | The Ibtana – Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a... |
| CVE-2026-1641 | MEDIUM | 6.5 | 0.3% | Sep 19, 2026 | The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now