UPDATED SEP 30, 2026

CVE Radar: latest vulnerabilities, exploited CVEs and patches (page 3)

A daily, analyst-curated feed of new and actively exploited CVEs, with severity, exploitation status, affected versions and remediation steps for each.

  1. CVE-2026-77263
    Iubenda plugin stored cross-site scripting via comment content iubenda iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more ·
    HIGH 7.2
  2. CVE-2026-77233
    Iubenda plugin stored cross-site scripting via AdSense regex rewrite iubenda iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more ·
    HIGH 7.2
  3. CVE-2026-19769
    Ninja Forms stored cross-site scripting via file upload kstover Ninja Forms – The Contact Form Builder That Grows With You ·
    HIGH 7.2
  4. CVE-2026-18406
    SureForms stored cross-site scripting vulnerability brainstormforce SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz ·
    HIGH 7.2
  5. CVE-2026-77830
    Spam protection, Honeypot, Anti-Spam by CleanTalk stored XSS in comments cleantalk Spam protection, Honeypot, Anti-Spam by CleanTalk ·
    HIGH 7.2
  6. CVE-2026-78438 HIGH 7.2
  7. CVE-2026-18405
    Jeg Kit for Elementor stored cross-site scripting via comments jegtheme Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress ·
    HIGH 7.2
  8. CVE-2026-87915
    Popup Maker stored cross-site scripting in values[Name] parameter danieliser Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder ·
    • PoC PUBLIC
    HIGH 7.2
  9. CVE-2026-13354
    Asset CleanUp: Page Speed Booster stored cross-site scripting via comments gabelivan Asset CleanUp: Page Speed Booster ·
    HIGH 7.2
  10. CVE-2026-89412
    TranslatePress Stored cross-site scripting in suggestion panel cozmoslabs TranslatePress – Translate Multilingual sites with AI Translation ·
    HIGH 7.2
  11. CVE-2026-94504
    Ninja Forms stored cross-site scripting in submission editor kstover Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder ·
    • PoC PUBLIC
    HIGH 7.2
  12. CVE-2026-18561
    Unlimited Elements For Elementor unauthenticated SQL injection unitecms Unlimited Elements For Elementor ·
    HIGH 7.5
  13. CVE-2026-89406
    Modula Image Gallery disclosure of private galleries and media wpchill Modula Image Gallery – Photo Grid & Video Gallery ·
    HIGH 7.5
  14. CVE-2026-66047
    ProfilePress unauthenticated remote code execution Proper Fraction ProfilePress ·
    • PATCH AVAILABLE
    HIGH 8.1
  15. CVE-2025-39964
    Linux Kernel AF_ALG concurrent-write race condition in af_alg_sendmsg Linux Kernel ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  16. CVE-2026-84324
    Chrome Proxy use-after-free allows remote code execution Google Chrome ·
    • PATCH AVAILABLE
    CRITICAL 9
  17. CVE-2026-87613 CRITICAL 9
  18. CVE-2026-73475
    Commerce PayPal forceful browsing lets unauthenticated users access Drupal Commerce PayPal ·
    • PATCH AVAILABLE
    CRITICAL 9.1
  19. CVE-2026-85043
    Chrome network cleanup bypass allows remote system access bypass Google Chrome ·
    • PATCH AVAILABLE
    CRITICAL 9.1
  20. CVE-2026-88056 CRITICAL 9.1
20 CVEs · page 3 of 23

About CVE Radar

CVE Radar tracks newly published Common Vulnerabilities and Exposures (CVEs) from NVD, the CISA Known Exploited Vulnerabilities catalog and vendor security advisories. Each entry is reviewed by Diras Labs analysts and includes affected versions, exploitation status, remediation guidance and relevance to organizations in Saudi Arabia and the GCC.