Vulnfeed

Archives
Log in
Subscribe
September 19, 2026

[vulnfeed] 3 critical CVEs — 2026-09-19 04:00 UTC

vulnfeed Critical alert — 2026-09-19 04:53 UTC
3 new critical CVEs in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-84434CRITICAL
The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and inclu
The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field va
CVSS 9.8
CVE-2026-89274CRITICAL
The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to,
The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata
CVSS 9.1
CVE-2026-92229CRITICAL
The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable
The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is du
CVSS 9.1

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 2 critical CVEs — 2026-09-20 04:00 UTC Older → [vulnfeed] 27 critical CVEs — 2026-09-18 20:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.