39 CVEs published June 6, 2026: 0 critical, 7 high, 26 medium, 6 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 14 in the results table.
Yesterday's Results
How to read these box scores · glossary
39 CVEs published. 25 box scores, 14 table rows — nothing truncated.
wpdevteam Essential Addons for Elementor – Popular Elementor Templates & Widgets — Essential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX Handler
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U L N N 5.3 .0724 93.8 —
AFFECTED
Product Versions Fixed
Essential Addons for Elementor – Popular Elementor Templates & Widgets unspecified —
TIMELINE
May 1 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
GL.iNet MT3000 OpenVPN Client Import Workflow ovpnclient.sh command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0123 66.6 —
AFFECTED
Product Versions Fixed
MT3000 4.4.0 – 4.9.0_beta3-1012-0513-1778656146
TIMELINE
Jun 5 Reserved by CNA
Jun 6 Published (CNA: VulDB)
vertex-app vertex Log Viewer Endpoint LogMod.js os command injection
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0111 63.5 —
AFFECTED
Product Versions Fixed
vertex 2026.02.0 – —
TIMELINE
Jun 5 Reserved by CNA
Jun 6 Published (CNA: VulDB)
chrisvrichardson MapPress Maps for WordPress — MapPress Maps for WordPress <= 2.96.6 - Unauthenticated Insecure Direct Object Reference via REST API Endpoints
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N L N 5.3 .0102 60.7 —
AFFECTED
Product Versions Fixed
MapPress Maps for WordPress unspecified —
TIMELINE
May 18 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L H N U H H H 7.2 .0066 48.8 —
AFFECTED
Product Versions Fixed
MDJM Event Management unspecified —
TIMELINE
Apr 30 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
thimpress LearnPress – Backup & Migration Tool — LearnPress <= 4.1.4 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'import-user-file' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L H N U H N N 4.9 .0065 48.2 —
AFFECTED
Product Versions Fixed
LearnPress – Backup & Migration Tool unspecified —
TIMELINE
Apr 30 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
nextendweb Smart Slider 3 — Smart Slider 3 <= 3.5.1.36 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'src'/'srcset' Attribute in HTML Export
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L H N U H N N 4.9 .0060 46.1 —
AFFECTED
Product Versions Fixed
Smart Slider 3 unspecified —
TIMELINE
May 21 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
thimpress LearnPress – WordPress LMS Plugin for Create and Sell Online Courses — LearnPress <= 4.3.6 - Unauthenticated Sensitive Information Exposure via 'c_status' and 'return_type' Parameters
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U L N N 5.3 .0053 42.3 —
AFFECTED
Product Versions Fixed
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses unspecified —
TIMELINE
May 13 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
davidanderson All-In-One Security (AIOS) – Security and Firewall — All-In-One Security (AIOS) <= 5.4.7 - Unauthenticated Stored Cross-Site Scripting via REST API Request Path
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C L L N 7.2 .0049 39.6 —
AFFECTED
Product Versions Fixed
All-In-One Security (AIOS) – Security and Firewall unspecified —
TIMELINE
May 12 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
JingDong JD Cloud Box AX6600 jdcweb_rpc set_macfilter stack-based overflow
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H H H 7.4 .0048 39.3 —
AFFECTED
Product Versions Fixed
JD Cloud Box AX6600 4.5.3.r4546 – —
TIMELINE
Jun 5 Reserved by CNA
Jun 6 Published (CNA: VulDB)
10web Photo Gallery by 10Web – Mobile-Friendly Image Gallery — Photo Gallery by 10Web <= 1.8.41 - Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U H N N 6.5 .0047 38.5 —
AFFECTED
Product Versions Fixed
Photo Gallery by 10Web – Mobile-Friendly Image Gallery unspecified —
TIMELINE
May 28 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
thimpress LearnPress – Backup & Migration Tool — LearnPress – Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object Injection via WXR XML File Upload
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H H N U H H H 6.6 .0045 37.2 —
AFFECTED
Product Versions Fixed
LearnPress – Backup & Migration Tool unspecified —
TIMELINE
Apr 30 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
CRUX Protocol::HTTP2 — Protocol::HTTP2 versions before 1.13 for Perl is vulnerable to a HTTP/2 Bomb
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N N H 7.5 .0041 34.2 —
AFFECTED
Product Versions Fixed
Protocol::HTTP2 unspecified —
TIMELINE
Jun 3 Reserved by CNA
Jun 6 Published (CNA: CPANSec)
perfree go-fastdfs-web Installation Endpoint checkServer server-side request forgery
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N L L L 5.5 .0041 33.7 —
AFFECTED
Product Versions Fixed
go-fastdfs-web 1.3.0 – —
TIMELINE
Jun 5 Reserved by CNA
Jun 6 Published (CNA: VulDB)
holithemes Click to Chat – HoliThemes — Click to Chat <= 4.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'num' Shortcode Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N C L L N 6.4 .0041 33.6 —
AFFECTED
Product Versions Fixed
Click to Chat – HoliThemes unspecified —
TIMELINE
May 4 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
spacetime Ad Inserter – Ad Manager & AdSense Ads — Ad Inserter <= 2.8.15 - Reflected Cross-Site Scripting via URL Parameters in iframe Mode
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N R C L L N 6.1 .0036 28.7 —
AFFECTED
Product Versions Fixed
Ad Inserter – Ad Manager & AdSense Ads unspecified —
TIMELINE
May 22 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
masaakitanaka Booking Package — Booking Package <= 1.7.16 - Authenticated (Editor+) Privilege Escalation via Account Takeover to updateUser AJAX Action
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L H N U H H H 7.2 .0036 28.5 —
AFFECTED
Product Versions Fixed
Booking Package unspecified —
TIMELINE
May 28 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
wpdevteam EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more — EmbedPress <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block 'url' Attribute
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N C L L N 6.4 .0033 25.5 —
AFFECTED
Product Versions Fixed
EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more unspecified —
TIMELINE
May 4 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
davidfcarr Quick Playground — Quick Playground <= 1.3.4 - Authenticated (Administrator+) Arbitrary File Read via 'filename' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H H N U H N N 4.4 .0032 23.7 —
AFFECTED
Product Versions Fixed
Quick Playground unspecified —
TIMELINE
Feb 13 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
plugcrux Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More — Integration for Freshsales <= 1.0.15 - Unauthenticated Stored Cross-Site Scripting via Form Submission Data
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C L L N 7.2 .0031 23.5 —
AFFECTED
Product Versions Fixed
Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More unspecified —
TIMELINE
May 18 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
glenwpcoder Drag and Drop Multiple File Upload for Contact Form 7 — Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H H N C L L N 4.4 .0031 23.3 —
AFFECTED
Product Versions Fixed
Drag and Drop Multiple File Upload for Contact Form 7 unspecified —
TIMELINE
May 19 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
smub WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More — WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook Endpoint
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N L N 5.3 .0030 22.2 —
AFFECTED
Product Versions Fixed
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More unspecified —
TIMELINE
May 4 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
cifi SEO Plugin by Squirrly SEO — SEO Plugin by Squirrly SEO <= 12.4.16 - Missing Authorization to Authenticated (Contributor+) Privileged Cloud API Operations
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U N L N 4.3 .0030 21.6 —
AFFECTED
Product Versions Fixed
SEO Plugin by Squirrly SEO unspecified —
TIMELINE
May 1 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
flippercode WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters — WP Maps <= 4.9.4 - Authenticated (Admin+) Stored Cross-Site Scripting via 'location_messages' Parameter
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H H N C L L N 4.4 .0029 21.3 —
AFFECTED
Product Versions Fixed
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters unspecified —
TIMELINE
May 26 Reserved by CNA
Jun 6 Published (CNA: Wordfence)
n/a FluentCMS — FluentCMS Blocks Plugin blocks cross site scripting
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N H P N L N 1.9 .0027 19.3 —
AFFECTED
Product Versions Fixed
FluentCMS 0.0.5 – —
TIMELINE
Jun 5 Reserved by CNA
Jun 6 Published (CNA: VulDB)
Remainder (ranked, continued)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
| CVE-2026-11436 | 2.1 | 17.7 | n/a | Mage AI | CWE-79 | Mage AI Sign-in Flow index.tsx useMutation cross site scripting |
| CVE-2026-9016 | 5.3 | 17.5 | qriouslad | Debug Log Manager – Conveniently Monitor and Inspect Errors | CWE-117 | Debug Log Manager <= 2.5.0 - Unauthenticated Improper Output Neutralization f… |
| CVE-2026-11435 | 5.5 | 17.2 | Jinher | OA | CWE-74 | Jinher OA nextselectplan.aspx sql injection |
| CVE-2026-8978 | 4.9 | 17.2 | crafium | OptinCraft – Drag & Drop Optins & Popup Builder for WordPress | CWE-89 | OptinCraft <= 1.2.0 - Authenticated (Administrator+) SQL Injection via 'order… |
| CVE-2026-8611 | 4.3 | 14.0 | klamra22 | Klamra Paycal for Aspaclaria | CWE-639 | Klamra Paycal for Aspaclaria <= 1.1.4 - Insecure Direct Object Reference to A… |
| CVE-2026-9008 | 4.3 | 12.8 | webvitaly | Page-list | CWE-862 | Page-list <= 6.2 - Missing Authorization to Authenticated (Contributor+) Sens… |
| CVE-2026-9281 | 6.4 | 11.6 | litonice13 | Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits | CWE-79 | Master Addons For Elementor <= 3.1.0 - Authenticated (Author+) Stored Cross-S… |
| CVE-2026-11438 | 5.3 | 11.5 | theonedev | onedev | CWE-266 | theonedev projects improper authorization |
| CVE-2026-11439 | 5.3 | 11.5 | theonedev | onedev | CWE-266 | theonedev Parent Project projects improper authorization |
| CVE-2026-11440 | 5.3 | 11.5 | theonedev | onedev | CWE-266 | theonedev REST API default-branch improper authorization |
| CVE-2026-11441 | 5.3 | 11.5 | theonedev | onedev | CWE-266 | theonedev Pull Request issues canAccessIssue improper authorization |
| CVE-2026-11412 | 2.1 | 9.3 | Jinher | OA | CWE-74 | Jinher OA GetFormSn.aspx sql injection |
| CVE-2026-11411 | 1.9 | 6.5 | iAI Lab | PDF AI App | CWE-22 | iAI Lab PDF AI App chatpdf.pro getExternalCacheDir path traversal |
| CVE-2026-26422 | 8.4 | 5.7 | Clash Verge Rev | clash-verge-service-ipc | CWE-732 | clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, lead… |
Methodology
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-06 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.