2026 CVE Vulnerabilities

60,395 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-54807CRITICAL9.8Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.
CVE-2026-54806CRITICAL9.8Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.
CVE-2026-54805HIGH8.8Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.
CVE-2026-54804HIGH7.6Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions.
CVE-2026-54803CRITICAL9.8Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions.
CVE-2026-54802HIGH7.5Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.
CVE-2026-54196MEDIUM6.8Incorrect Privilege Assignment vulnerability in Jetmonsters JetFormBuilder allows Privilege Escalation. This issue affe...
CVE-2026-54195HIGH7.1Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions.
CVE-2026-54194CRITICAL9.8Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions.
CVE-2026-54192HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions.
CVE-2026-54189HIGH7.1Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
CVE-2026-54188HIGH7.1Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
CVE-2026-54187CRITICAL9.3Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.
CVE-2026-54186CRITICAL9.3Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions.
CVE-2026-54185HIGH8.5Subscriber SQL Injection in Cornerstone < 7.8.8 versions.
CVE-2026-54184HIGH8.2Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions.
CVE-2026-53876HIGH8.6RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary c...
CVE-2026-52706CRITICAL9.8Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.
CVE-2026-52705CRITICAL9Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions.
CVE-2026-52698HIGH7.4Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation &amp; Chat Widget <= 4.2...
CVE-2026-52696HIGH7.5Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions.
CVE-2026-50203CRITICAL9.1A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or...
CVE-2026-49778HIGH7.1Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions.
CVE-2026-49767CRITICAL9.8Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions.
CVE-2026-49113HIGH8.5Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now