2026 CVE Vulnerabilities
64,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85131 | MEDIUM | 6.5 | 0.1% | Sep 16, 2026 | The WPLP Cookie Consent WordPress plugin before 4.4.4 does not perform CSRF or capability checks when processing bulk a... |
| CVE-2026-84088 | MEDIUM | 6.8 | 0.2% | Sep 16, 2026 | The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link s... |
| CVE-2026-82125 | MEDIUM | 5.3 | 0.2% | Sep 16, 2026 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership or the mo... |
| CVE-2026-82124 | MEDIUM | 5.3 | 0.2% | Sep 16, 2026 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is password protect... |
| CVE-2026-78474 | MEDIUM | 5.3 | 0.2% | Sep 16, 2026 | The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisation checks ... |
| CVE-2026-77702 | MEDIUM | 5.3 | 0.2% | Sep 16, 2026 | The Eventin WordPress plugin before 4.1.24 does not prevent the token issued to a guest at checkout from being used to ... |
| CVE-2026-76559 | MEDIUM | 4.1 | 0.2% | Sep 16, 2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not properly validate URLs before requesting them during t... |
| CVE-2026-76558 | MEDIUM | 6.8 | 0.2% | Sep 16, 2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not escape custom field names retrieved from the database ... |
| CVE-2026-76557 | MEDIUM | 6.8 | 0.2% | Sep 16, 2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some import configuration... |
| CVE-2026-76556 | MEDIUM | 6.8 | 0.2% | Sep 16, 2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some export filter values... |
| CVE-2026-76555 | MEDIUM | 6.8 | 0.2% | Sep 16, 2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it a... |
| CVE-2026-76553 | MEDIUM | 6.5 | 0.2% | Sep 16, 2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data ... |
| CVE-2026-5920 | MEDIUM | 6.4 | 0.2% | Sep 16, 2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' para... |
| CVE-2026-18555 | MEDIUM | 6.1 | 0.2% | Sep 16, 2026 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Refl... |
| CVE-2026-16588 | MEDIUM | 6.5 | 0.3% | Sep 16, 2026 | The WP Directory Kit plugin for WordPress is vulnerable to blind SQL Injection via the 'order_by' parameter in all versi... |
| CVE-2026-11996 | MEDIUM | 6.4 | 0.2% | Sep 16, 2026 | The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' Fie... |
| CVE-2026-11984 | MEDIUM | 5.3 | 0.3% | Sep 16, 2026 | The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up... |
| CVE-2026-92247 | MEDIUM | 4.7 | 0.3% | Sep 16, 2026 | A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename o... |
| CVE-2026-92221 | MEDIUM | 4.7 | 0.3% | Sep 16, 2026 | A vulnerability was determined in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affecte... |
| CVE-2026-92220 | MEDIUM | 5.3 | 0.5% | Sep 16, 2026 | A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_... |
| CVE-2026-86109 | MEDIUM | 6.6 | 0.2% | Sep 16, 2026 | The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures becau... |
| CVE-2026-73450 | MEDIUM | 6.9 | 0.1% | Sep 16, 2026 | On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with a... |
| CVE-2026-92298 | MEDIUM | 4.8 | 0.3% | Sep 16, 2026 | EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and camp... |
| CVE-2026-92217 | MEDIUM | 6.3 | 0.3% | Sep 16, 2026 | A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file ... |
| CVE-2026-92216 | MEDIUM | 4.3 | 0.4% | Sep 16, 2026 | A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now