2026 CVE Vulnerabilities

61,215 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-52693CRITICAL9.3Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.
CVE-2026-52692HIGH7.5Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions.
CVE-2026-49781CRITICAL9.8Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.
CVE-2026-49780HIGH8.8Customer Privilege Escalation in Dokan <= 5.0.2 versions.
CVE-2026-49776CRITICAL9.3Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websit...
CVE-2026-49775MEDIUM6.5Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.
CVE-2026-49773MEDIUM6.5Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions.
CVE-2026-49770CRITICAL9.8Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.
CVE-2026-49769CRITICAL9.8Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.
CVE-2026-49768CRITICAL9.8Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.
CVE-2026-49766CRITICAL9.9Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.
CVE-2026-49765CRITICAL9.8Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <=...
CVE-2026-49764CRITICAL9.8Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.
CVE-2026-49763CRITICAL9.8Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.
CVE-2026-49112HIGH7.5Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.
CVE-2026-49110HIGH7.5Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.
CVE-2026-49109CRITICAL9.8Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, N...
CVE-2026-49106CRITICAL9.8Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions.
CVE-2026-49105CRITICAL9.8Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <=...
CVE-2026-49104CRITICAL9.8Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formid...
CVE-2026-49085CRITICAL9.8Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms ...
CVE-2026-49083HIGH7.5Contributor Privilege Escalation in LatePoint <= 5.5.1 versions.
CVE-2026-49082HIGH7.4Subscriber Sensitive Data Exposure in Chatway Live Chat &#8211; AI Chatbot, Customer Support, FAQ &amp; Helpdesk Custome...
CVE-2026-49078HIGH7.5Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions.
CVE-2026-49070HIGH7.5Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now