2026 CVE Vulnerabilities

60,395 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40746CRITICAL9.9Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.
CVE-2026-40739HIGH8.1Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.
CVE-2026-40736HIGH8.1Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.
CVE-2026-40735HIGH8.1Unauthenticated PHP Object Injection in Reina <= 2.1 versions.
CVE-2026-40731HIGH8.1Unauthenticated Local File Inclusion in ChapterOne <= 1.7 versions.
CVE-2026-40726HIGH8.2Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions.
CVE-2026-40725CRITICAL9.8Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions.
CVE-2026-40724MEDIUM6.5CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions.
CVE-2026-40723MEDIUM4.3Subscriber Broken Access Control in Bricks Builder <= 2.1.4 versions.
CVE-2026-40722MEDIUM5.5Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Contro...
CVE-2026-40721HIGH7.5Contributor Local File Inclusion in Element Pack Pro <= 9.0.6 versions.
CVE-2026-39598HIGH8Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell t...
CVE-2026-39597HIGH7.1Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor <= 1.3.4 versions.
CVE-2026-39596CRITICAL9.3Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions.
CVE-2026-39595MEDIUM4.7Author Broken Access Control in W3 Total Cache <= 2.9.1 versions.
CVE-2026-39589CRITICAL9.9Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions.
CVE-2026-39582HIGH8.1Unauthenticated Local File Inclusion in Hitek < 1.8.3 versions.
CVE-2026-39580HIGH8.1Unauthenticated PHP Object Injection in Micdrop <= 1.3.1 versions.
CVE-2026-39578MEDIUM5.5Unauthenticated PHP Object Injection in Valiance <= 1.2 versions.
CVE-2026-39577MEDIUM5.5Unauthenticated PHP Object Injection in Playroom <= 1.4.1 versions.
CVE-2026-39573HIGH8.1Unauthenticated PHP Object Injection in Mildhill <= 1.5 versions.
CVE-2026-39568HIGH8.1Unauthenticated Local File Inclusion in Mr. SEO <= 2.0 versions.
CVE-2026-39567HIGH8.1Unauthenticated PHP Object Injection in Santé <= 1.5.1 versions.
CVE-2026-39558HIGH8.1Unauthenticated Local File Inclusion in Malmö <= 2.2 versions.
CVE-2026-39557HIGH8.1Unauthenticated PHP Object Injection in NeoBeat <= 1.7 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now