2026 CVE Vulnerabilities
61,215 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-52693 | CRITICAL | 9.3 | 0.3% | Jun 15, 2026 | Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions. |
| CVE-2026-52692 | HIGH | 7.5 | 0.2% | Jun 15, 2026 | Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions. |
| CVE-2026-49781 | CRITICAL | 9.8 | 0.4% | Jun 15, 2026 | Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions. |
| CVE-2026-49780 | HIGH | 8.8 | 0.3% | Jun 15, 2026 | Customer Privilege Escalation in Dokan <= 5.0.2 versions. |
| CVE-2026-49776 | CRITICAL | 9.3 | 0.3% | Jun 15, 2026 | Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websit... |
| CVE-2026-49775 | MEDIUM | 6.5 | 0.2% | Jun 15, 2026 | Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions. |
| CVE-2026-49773 | MEDIUM | 6.5 | 0.2% | Jun 15, 2026 | Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions. |
| CVE-2026-49770 | CRITICAL | 9.8 | 0.4% | Jun 15, 2026 | Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions. |
| CVE-2026-49769 | CRITICAL | 9.8 | 0.4% | Jun 15, 2026 | Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions. |
| CVE-2026-49768 | CRITICAL | 9.8 | 0.4% | Jun 15, 2026 | Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions. |
| CVE-2026-49766 | CRITICAL | 9.9 | 0.5% | Jun 15, 2026 | Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions. |
| CVE-2026-49765 | CRITICAL | 9.8 | 0.4% | Jun 15, 2026 | Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <=... |
| CVE-2026-49764 | CRITICAL | 9.8 | 0.4% | Jun 15, 2026 | Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions. |
| CVE-2026-49763 | CRITICAL | 9.8 | 0.4% | Jun 15, 2026 | Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions. |
| CVE-2026-49112 | HIGH | 7.5 | 0.3% | Jun 15, 2026 | Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions. |
| CVE-2026-49110 | HIGH | 7.5 | 0.2% | Jun 15, 2026 | Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions. |
| CVE-2026-49109 | CRITICAL | 9.8 | 0.4% | Jun 15, 2026 | Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, N... |
| CVE-2026-49106 | CRITICAL | 9.8 | 0.4% | Jun 15, 2026 | Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions. |
| CVE-2026-49105 | CRITICAL | 9.8 | 0.5% | Jun 15, 2026 | Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <=... |
| CVE-2026-49104 | CRITICAL | 9.8 | 0.5% | Jun 15, 2026 | Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formid... |
| CVE-2026-49085 | CRITICAL | 9.8 | 0.5% | Jun 15, 2026 | Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms ... |
| CVE-2026-49083 | HIGH | 7.5 | 0.3% | Jun 15, 2026 | Contributor Privilege Escalation in LatePoint <= 5.5.1 versions. |
| CVE-2026-49082 | HIGH | 7.4 | 0.3% | Jun 15, 2026 | Subscriber Sensitive Data Exposure in Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Custome... |
| CVE-2026-49078 | HIGH | 7.5 | 0.3% | Jun 15, 2026 | Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions. |
| CVE-2026-49070 | HIGH | 7.5 | 0.2% | Jun 15, 2026 | Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now