2026 CVE Vulnerabilities
64,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27553 | MEDIUM | 6.5 | 0.5% | Sep 16, 2026 | A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_ta... |
| CVE-2026-8030 | MEDIUM | 4.3 | 0.4% | Sep 16, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 1... |
| CVE-2026-86475 | MEDIUM | 5.3 | 0.3% | Sep 16, 2026 | The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission aga... |
| CVE-2026-84906 | MEDIUM | 5.3 | 0.1% | Sep 16, 2026 | The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is appli... |
| CVE-2026-7514 | MEDIUM | 4.3 | 0.3% | Sep 16, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and 1... |
| CVE-2026-19857 | MEDIUM | 4.8 | 0.2% | Sep 16, 2026 | The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress s... |
| CVE-2026-19619 | MEDIUM | 4.7 | 0.3% | Sep 16, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 1... |
| CVE-2026-16794 | MEDIUM | 4.3 | 0.3% | Sep 16, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.11 before 19.1.8, 19.2 before 19.2.6, and 19.... |
| CVE-2026-13407 | MEDIUM | 5.4 | 0.2% | Sep 16, 2026 | The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted throu... |
| CVE-2026-92358 | MEDIUM | 6.4 | 0.3% | Sep 16, 2026 | A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a diff... |
| CVE-2026-88910 | MEDIUM | 5.3 | 0.2% | Sep 16, 2026 | The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauth... |
| CVE-2026-87959 | MEDIUM | 5.4 | 0.2% | Sep 16, 2026 | The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI... |
| CVE-2026-87907 | MEDIUM | 5.3 | 0.2% | Sep 16, 2026 | The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints tha... |
| CVE-2026-87896 | MEDIUM | 5.3 | 0.2% | Sep 16, 2026 | The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoint that... |
| CVE-2026-87860 | MEDIUM | 4.3 | 0.1% | Sep 16, 2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that c... |
| CVE-2026-87854 | MEDIUM | 5.3 | 0.2% | Sep 16, 2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret protecting... |
| CVE-2026-87828 | MEDIUM | 5.7 | 0.2% | Sep 16, 2026 | The Seraphinite Accelerator WordPress plugin before 2.29.24 does not perform a capability check on one of its state-upda... |
| CVE-2026-86823 | MEDIUM | 5.3 | 0.2% | Sep 16, 2026 | The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after a public... |
| CVE-2026-86784 | MEDIUM | 6.8 | 0.2% | Sep 16, 2026 | The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration befo... |
| CVE-2026-86449 | MEDIUM | 5.3 | 0.2% | Sep 16, 2026 | The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities before applying a user supplied pos... |
| CVE-2026-86447 | MEDIUM | 5.3 | 0.2% | Sep 16, 2026 | The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative course... |
| CVE-2026-86445 | MEDIUM | 5.3 | 0.2% | Sep 16, 2026 | The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative templa... |
| CVE-2026-85641 | MEDIUM | 4.3 | 0.1% | Sep 16, 2026 | The Formidable Forms WordPress plugin before 6.35 does not restrict who can set the identifier recording which user las... |
| CVE-2026-85572 | MEDIUM | 4.3 | 0.2% | Sep 16, 2026 | The Tutor LMS WordPress plugin before 4.0.8 does not check that a user has access to a course before returning its less... |
| CVE-2026-85349 | MEDIUM | 4.3 | 0.2% | Sep 16, 2026 | The FluentBoards WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of board... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now