ARCHIVE

CVEs published in September 2026 (page 3)

Vulnerabilities added to CVE Radar in September 2026, newest first.

  1. CVE-2026-77263
    Iubenda plugin stored cross-site scripting via comment content iubenda iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more ·
    HIGH 7.2
  2. CVE-2026-77233
    Iubenda plugin stored cross-site scripting via AdSense regex rewrite iubenda iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more ·
    HIGH 7.2
  3. CVE-2026-19769
    Ninja Forms stored cross-site scripting via file upload kstover Ninja Forms – The Contact Form Builder That Grows With You ·
    HIGH 7.2
  4. CVE-2026-18406
    SureForms stored cross-site scripting vulnerability brainstormforce SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz ·
    HIGH 7.2
  5. CVE-2026-77830
    Spam protection, Honeypot, Anti-Spam by CleanTalk stored XSS in comments cleantalk Spam protection, Honeypot, Anti-Spam by CleanTalk ·
    HIGH 7.2
  6. CVE-2026-78438 HIGH 7.2
  7. CVE-2026-18405
    Jeg Kit for Elementor stored cross-site scripting via comments jegtheme Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress ·
    HIGH 7.2
  8. CVE-2026-87915
    Popup Maker stored cross-site scripting in values[Name] parameter danieliser Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder ·
    • PoC PUBLIC
    HIGH 7.2
  9. CVE-2026-13354
    Asset CleanUp: Page Speed Booster stored cross-site scripting via comments gabelivan Asset CleanUp: Page Speed Booster ·
    HIGH 7.2
  10. CVE-2026-89412
    TranslatePress Stored cross-site scripting in suggestion panel cozmoslabs TranslatePress – Translate Multilingual sites with AI Translation ·
    HIGH 7.2
  11. CVE-2026-94504
    Ninja Forms stored cross-site scripting in submission editor kstover Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder ·
    • PoC PUBLIC
    HIGH 7.2
  12. CVE-2026-18561
    Unlimited Elements For Elementor unauthenticated SQL injection unitecms Unlimited Elements For Elementor ·
    HIGH 7.5
  13. CVE-2026-89406
    Modula Image Gallery disclosure of private galleries and media wpchill Modula Image Gallery – Photo Grid & Video Gallery ·
    HIGH 7.5
  14. CVE-2026-66047
    ProfilePress unauthenticated remote code execution Proper Fraction ProfilePress ·
    • PATCH AVAILABLE
    HIGH 8.1
  15. CVE-2025-39964
    Linux Kernel AF_ALG concurrent-write race condition in af_alg_sendmsg Linux Kernel ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  16. CVE-2026-84324
    Chrome Proxy use-after-free allows remote code execution Google Chrome ·
    • PATCH AVAILABLE
    CRITICAL 9
  17. CVE-2026-87613 CRITICAL 9
  18. CVE-2026-73475
    Commerce PayPal forceful browsing lets unauthenticated users access Drupal Commerce PayPal ·
    • PATCH AVAILABLE
    CRITICAL 9.1
  19. CVE-2026-85043
    Chrome network cleanup bypass allows remote system access bypass Google Chrome ·
    • PATCH AVAILABLE
    CRITICAL 9.1
  20. CVE-2026-88056 CRITICAL 9.1
20 CVEs · page 3 of 23