2026 CVE Vulnerabilities

61,178 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40758HIGH8.1Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.
CVE-2026-40755HIGH8.1Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.
CVE-2026-40754HIGH8.1Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.
CVE-2026-40753HIGH8.1Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.
CVE-2026-40751HIGH8.1Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.
CVE-2026-40749CRITICAL9.9Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.
CVE-2026-40748CRITICAL9.9Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions.
CVE-2026-40747CRITICAL9.9Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions.
CVE-2026-40746CRITICAL9.9Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.
CVE-2026-40739HIGH8.1Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.
CVE-2026-40736HIGH8.1Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.
CVE-2026-40735HIGH8.1Unauthenticated PHP Object Injection in Reina <= 2.1 versions.
CVE-2026-40731HIGH8.1Unauthenticated Local File Inclusion in ChapterOne <= 1.7 versions.
CVE-2026-40726HIGH8.2Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions.
CVE-2026-40725CRITICAL9.8Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions.
CVE-2026-40724MEDIUM6.5CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions.
CVE-2026-40723MEDIUM4.3Subscriber Broken Access Control in Bricks Builder <= 2.1.4 versions.
CVE-2026-40722MEDIUM5.5Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Contro...
CVE-2026-40721HIGH7.5Contributor Local File Inclusion in Element Pack Pro <= 9.0.6 versions.
CVE-2026-39598HIGH8Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell t...
CVE-2026-39597HIGH7.1Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor <= 1.3.4 versions.
CVE-2026-39596CRITICAL9.3Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions.
CVE-2026-39595MEDIUM4.7Author Broken Access Control in W3 Total Cache <= 2.9.1 versions.
CVE-2026-39589CRITICAL9.9Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions.
CVE-2026-39582HIGH8.1Unauthenticated Local File Inclusion in Hitek < 1.8.3 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now