Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 207/1469
7.5
CVE-2026-49070

Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.

7.5
CVE-2026-49068

Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.

7.5
CVE-2026-49066

Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions.

8.2
CVE-2026-49065

Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.

7.3
CVE-2026-49063

Unauthenticated Privilege Escalation in Listdom <= 5.5.0 versions.

7.5
CVE-2026-49061

Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions.

7.5
CVE-2026-49056

Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <

7.1
CVE-2026-49055

Unauthenticated Cross Site Scripting (XSS) in Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.7 versions.

8.1
CVE-2026-48970

Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions.

7.1
CVE-2026-48966

Unauthenticated Cross Site Scripting (XSS) in Funnel Builder by FunnelKit <= 3.15.0.2 versions.

8.5
CVE-2026-48964

Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions.

8.8
CVE-2026-48889

Subscriber Privilege Escalation in Amelia <= 2.3 versions.

7.1
CVE-2026-48885

Unauthenticated Cross Site Scripting (XSS) in HollerBox <= 2.3.10.1 versions.

7.5
CVE-2026-48883

Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions.

8.5
CVE-2026-48882

Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions.

7.1
CVE-2026-48876

Unauthenticated Cross Site Scripting (XSS) in Stop Spammers <= 2026.3 versions.

8.5
CVE-2026-48874

Subscriber SQL Injection in GamiPress <= 7.8.7 versions.

7.5
CVE-2026-48873

Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions.

7.5
CVE-2026-48872

Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions.

7.1
CVE-2026-48871

Unauthenticated Cross Site Scripting (XSS) in MW WP Form <= 5.1.3 versions.

7.5
CVE-2026-48868

Unauthenticated Insecure Direct Object References (IDOR) in Simple Shopping Cart <= 5.2.9 versions.

7.1
CVE-2026-48867

Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.1.2 versions.

7.1
CVE-2026-48838

Unauthenticated Cross Site Scripting (XSS) in Post SMTP <= 3.6.2 versions.

7.5
CVE-2026-48835

Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.

7.5
CVE-2026-48708

OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, the template en

8.6
CVE-2026-47825

Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configu

7.5
CVE-2026-47261

Wasmtime is a runtime for WebAssembly. In versions prior to 24.0.9, 36.0.10, and 44.0.2, when a filesystem preopen is gi

7.5
CVE-2026-45441

Unauthenticated Other Vulnerability Type in WpEvently <= 5.3.3 versions.

7.1
CVE-2026-45437

Unauthenticated Cross Site Scripting (XSS) in Product Filter Widget for Elementor <= 1.0.6 versions.

7.1
CVE-2026-42775

Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.7.2 versions.

8.1
CVE-2026-42687

Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions.

7.1
CVE-2026-42686

Subscriber Cross Site Scripting (XSS) in EventPrime <= 4.3.2.1 versions.

7.5
CVE-2026-42668

Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions.

7.5
CVE-2026-42667

Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions.

7.5
CVE-2026-42666

Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions.

8.2
CVE-2026-42664

Unauthenticated Broken Access Control in AI Product Search for WooCommerce &#8211; Motive Commerce Search <= 1.38.2 vers

8.8
CVE-2026-42661

Custom role Path Traversal in WP Customer Area <= 8.3.4 versions.

7.1
CVE-2026-42658

Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.3.8 versions.

7.2
CVE-2026-42650

Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.6.7 versions.

7.1
CVE-2026-42649

Unauthenticated Cross Site Scripting (XSS) in Favicon Rotator <= 1.2.11 versions.

8.1
CVE-2026-42411

Unauthenticated Broken Authentication in CloudSecure WP Security <= 1.4.7 versions.

7.5
CVE-2026-42384

Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions.

7.1
CVE-2026-40791

Unauthenticated Cross Site Scripting (XSS) in WP Time Slots Booking Form <= 1.2.46 versions.

7.5
CVE-2026-40789

Unauthenticated Sensitive Data Exposure in Amelia <= 2.2 versions.

7.1
CVE-2026-40788

Subscriber Broken Access Control in ChatBot <= 7.9.7 versions.

7.1
CVE-2026-40787

Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.0.0 versions.

7.1
CVE-2026-40785

Subscriber Broken Authentication in AutomatorWP <= 5.6.7 versions.

7.5
CVE-2026-40781

Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions.

7.7
CVE-2026-40779

Contributor Arbitrary File Deletion in Link Library <= 7.8.8 versions.

7.5
CVE-2026-40776

Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions.

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started