2026 CVE Vulnerabilities
65,537 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92411 | MEDIUM | 6.8 | — | Sep 26, 2026 | The WP Delicious WordPress plugin before 1.10.8 does not validate or escape the HTML tag name taken from user-supplied ... |
| CVE-2026-89237 | MEDIUM | 6.8 | — | Sep 26, 2026 | The Bluff Post WordPress plugin through 1.1.1 does not sanitise and escape parameters before using them as identifiers i... |
| CVE-2026-85081 | HIGH | 7.5 | — | Sep 26, 2026 | The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPres... |
| CVE-2026-84097 | MEDIUM | 6.5 | — | Sep 26, 2026 | The wp-review-slider-pro WordPress plugin before 12.7.12 does not sanitize a value stored through one of its AJAX handle... |
| CVE-2026-84096 | HIGH | 8 | — | Sep 26, 2026 | The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on the AJAX handler that sa... |
| CVE-2026-84095 | HIGH | 8 | — | Sep 26, 2026 | The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one of its AJAX handlers... |
| CVE-2026-19708 | MEDIUM | 5.9 | — | Sep 26, 2026 | The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database back... |
| CVE-2026-18143 | CRITICAL | 9.8 | — | Sep 26, 2026 | The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, a... |
| CVE-2026-16591 | HIGH | 7.2 | 0.2% | Sep 26, 2026 | The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and escape some of its category and location fields... |
| CVE-2026-11871 | MEDIUM | 5.3 | — | Sep 26, 2026 | The Team Members WordPress plugin before 9.3 does not perform any authorization or visibility check in an unauthenticate... |
| CVE-2026-15273 | MEDIUM | 6.4 | — | Sep 26, 2026 | The Automatic.css plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI in all version 4.0.0... |
| CVE-2026-100599 | HIGH | 8.8 | — | Sep 26, 2026 | OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands... |
| CVE-2026-100598 | HIGH | 7.1 | — | Sep 26, 2026 | OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Signal approval reactions. In affected versions, a rea... |
| CVE-2026-100597 | HIGH | 7.8 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShe... |
| CVE-2026-100596 | HIGH | 8.8 | — | Sep 26, 2026 | OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through... |
| CVE-2026-100595 | MEDIUM | 6.5 | — | Sep 26, 2026 | OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the diagnostics export command that a... |
| CVE-2026-100594 | MEDIUM | 6.5 | — | Sep 26, 2026 | OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the /export-trajectory endpoint that ... |
| CVE-2026-100593 | MEDIUM | 5.4 | — | Sep 26, 2026 | OpenClaw (npm package `openclaw`) before 2026.7.1 does not enforce the documented owner-only requirement for persistent ... |
| CVE-2026-100592 | MEDIUM | 6.3 | — | Sep 26, 2026 | OpenClaw is an agent gateway distributed via npm. In versions >= 2026.4.10 and < 2026.7.1, persistent memory dreaming mu... |
| CVE-2026-100591 | MEDIUM | 6.3 | — | Sep 26, 2026 | OpenClaw is an npm-distributed agent gateway. In versions before 2026.7.1, the global Active Memory toggle mutations cou... |
| CVE-2026-100590 | MEDIUM | 4.3 | — | Sep 26, 2026 | OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner ... |
| CVE-2026-100589 | HIGH | 8.3 | — | Sep 26, 2026 | OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessi... |
| CVE-2026-100588 | HIGH | 8.3 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser contro... |
| CVE-2026-100587 | HIGH | 8.8 | — | Sep 26, 2026 | OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation c... |
| CVE-2026-100586 | HIGH | 8.8 | — | Sep 26, 2026 | OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now