2026 CVE Vulnerabilities

61,161 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-54192HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions.
CVE-2026-54189HIGH7.1Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
CVE-2026-54188HIGH7.1Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
CVE-2026-54187CRITICAL9.3Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.
CVE-2026-54186CRITICAL9.3Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions.
CVE-2026-54185HIGH8.5Subscriber SQL Injection in Cornerstone < 7.8.8 versions.
CVE-2026-54184HIGH8.2Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions.
CVE-2026-53876HIGH8.6RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary c...
CVE-2026-52706CRITICAL9.8Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.
CVE-2026-52705CRITICAL9Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions.
CVE-2026-52698HIGH7.4Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation &amp; Chat Widget <= 4.2...
CVE-2026-52696HIGH7.5Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions.
CVE-2026-50203CRITICAL9.1A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or...
CVE-2026-49778HIGH7.1Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions.
CVE-2026-49767CRITICAL9.8Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions.
CVE-2026-49113HIGH8.5Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.
CVE-2026-49107CRITICAL9.8Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions.
CVE-2026-49084CRITICAL9.3Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions.
CVE-2026-49081HIGH8.2Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions.
CVE-2026-49080CRITICAL9.3Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions.
CVE-2026-49079CRITICAL9.3Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions.
CVE-2026-49076CRITICAL9.3Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions.
CVE-2026-49075CRITICAL9.8Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions.
CVE-2026-49074HIGH7.1Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions.
CVE-2026-49073HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now