{
  "day": "2026-06-15",
  "boundary": "UTC calendar day",
  "published_count": 400,
  "by_severity": {
    "CRITICAL": 80,
    "HIGH": 191,
    "MEDIUM": 117,
    "LOW": 12
  },
  "kev_count": 2,
  "exploit_reference_count": 15,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-20262",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.28171,
      "epss_percentile": 0.97955,
      "kev": true,
      "kev_due_at": "2026-06-29",
      "vendor": "Cisco",
      "product": "Cisco Catalyst SD-WAN Manager",
      "cwe": "CWE-22",
      "title": "Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20262"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-54420",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01439,
      "epss_percentile": 0.71046,
      "kev": true,
      "kev_due_at": "2026-06-18",
      "vendor": "LiteSpeed Technologies",
      "product": "cPanel Plugin",
      "cwe": "CWE-61",
      "title": "LiteSpeed cPanel Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54420"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-49952",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.04194,
      "epss_percentile": 0.9013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Discuz!",
      "product": "Discuz! X5.0",
      "cwe": "CWE-323",
      "title": "Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49952"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-50871",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01571,
      "epss_percentile": 0.73388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50871"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-38065",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01345,
      "epss_percentile": 0.69159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38065"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-39468",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01221,
      "epss_percentile": 0.66274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eLightUp",
      "product": "Meta Box – WordPress Custom Fields Framework",
      "cwe": "CWE-22",
      "title": "WordPress Meta Box – WordPress Custom Fields Framework plugin <= 5.11.1 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39468"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-12223",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.01194,
      "epss_percentile": 0.65541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yealink",
      "product": "SIP-T46U",
      "cwe": "CWE-74",
      "title": "Yealink SIP-T46U Web FastCGI Service tftpuploadiperf mod_webd.TFTPUploadIperf command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12223"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-50874",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.01119,
      "epss_percentile": 0.63559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50874"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-12219",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0105,
      "epss_percentile": 0.61586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yealink",
      "product": "SIP-T46U",
      "cwe": "CWE-74",
      "title": "Yealink SIP-T46U Web FastCGI Service start mod_diagnose.CommandShellByType command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12219"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-38060",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01046,
      "epss_percentile": 0.61479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38060"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-38061",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01046,
      "epss_percentile": 0.61478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38061"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-38062",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01046,
      "epss_percentile": 0.61478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the ratMode parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38062"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-38063",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01046,
      "epss_percentile": 0.61479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38063"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-38064",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01046,
      "epss_percentile": 0.61478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38064"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-9862",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00992,
      "epss_percentile": 0.59812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortra",
      "product": "Core Privileged Access Manager (BoKS)",
      "cwe": "CWE-78",
      "title": "Core Privileged Access Manager (BoKS) autoregistration service command injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9862"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-30120",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00811,
      "epss_percentile": 0.54117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30120"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2016-20079",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00778,
      "epss_percentile": 0.53022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jamie",
      "product": "Dharma Booking",
      "cwe": "CWE-98",
      "title": "WordPress Dharma Booking 2.28.3 Local File Inclusion via proccess.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20079"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-8385",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00762,
      "epss_percentile": 0.52534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Go Maps",
      "cwe": "CWE-200",
      "title": "WP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8385"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-50869",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00718,
      "epss_percentile": 0.50999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50869"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-8386",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.007,
      "epss_percentile": 0.50349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Go Maps",
      "cwe": null,
      "title": "WP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Marker ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8386"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2016-20078",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00688,
      "epss_percentile": 0.49935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Henrique Dias",
      "product": "IMDb Profile Widget",
      "cwe": "CWE-98",
      "title": "WordPress IMDb Profile Widget 1.0.8 Local File Inclusion via pic.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20078"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-39465",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0068,
      "epss_percentile": 0.49617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MetaSlider",
      "product": "Responsive Slider by MetaSlider",
      "cwe": "CWE-94",
      "title": "WordPress Responsive Slider by MetaSlider plugin <= 3.106.0 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39465"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2018-25436",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00661,
      "epss_percentile": 0.48864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shipster",
      "product": "Baggage Freight Shipping Australia",
      "cwe": "CWE-434",
      "title": "WordPress Plugin Baggage Freight Shipping Australia 0.1.0 Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25436"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2016-20081",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00641,
      "epss_percentile": 0.47951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Husain",
      "product": "HB Audio Gallery Lite",
      "cwe": "CWE-22",
      "title": "WordPress Plugin HB Audio Gallery Lite 1.0.0 Path Traversal File Download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20081"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-52720",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00638,
      "epss_percentile": 0.47854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-122",
      "title": "Gstreamer1-plugins-bad-free: gstreamer: heap buffer overflow via crafted vnc server rectangle in librfb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52720"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-38329",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00627,
      "epss_percentile": 0.47343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-862",
      "title": "Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.php fails to perform authorization checks and lacks file extension validation. An attacker with a valid API token can upload a malicious PHP script and execute arbitrary code on the server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38329"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-49757",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00615,
      "epss_percentile": 0.468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "team-alembic",
      "product": "ash_authentication",
      "cwe": "CWE-290",
      "title": "OAuth2/OIDC account takeover in AshAuthentication via email-based user matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49757"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2016-20076",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00601,
      "epss_percentile": 0.46157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ChrisHurst",
      "product": "Simple Backup",
      "cwe": "CWE-22",
      "title": "WordPress Simple-Backup 2.7.11 Arbitrary File Deletion and Download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20076"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-9863",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00595,
      "epss_percentile": 0.45843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortra",
      "product": "Core Privileged Access Manager (BoKS)",
      "cwe": "CWE-78",
      "title": "Core Privileged Access Manager (BoKS) upgrade tooling command injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9863"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-36213",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00585,
      "epss_percentile": 0.45413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-269",
      "title": "An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.exe component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36213"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-50877",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00577,
      "epss_percentile": 0.4503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying files with names containing traversal characters.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50877"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-48853",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00573,
      "epss_percentile": 0.44841,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-grpc",
      "product": "grpc",
      "cwe": "CWE-502",
      "title": "Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48853"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-48836",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00572,
      "epss_percentile": 0.44787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MantraBrain",
      "product": "Easy Invoice",
      "cwe": "CWE-94",
      "title": "WordPress Easy Invoice plugin <= 2.1.19 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48836"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-50872",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0056,
      "epss_percentile": 0.44179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtain sensitive information via supplying a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50872"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-48723",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00533,
      "epss_percentile": 0.42763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "browserstack",
      "product": "browserstack-cypress-cli",
      "cwe": "CWE-78",
      "title": "BrowserStack Cypress CL: Command Injection via cypress_config_file leads to arbitrary code execution through malicious browserstack.json",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48723"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-49954",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00525,
      "epss_percentile": 0.42294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Discuz!",
      "product": "Discuz! X5.0",
      "cwe": "CWE-98",
      "title": "Discuz! X5.0 Local File Inclusion via enable_disable.php Plugin Directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49954"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-12198",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00525,
      "epss_percentile": 0.42296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Microweber",
      "cwe": "CWE-22",
      "title": "Microweber API Endpoint thumbnail_img userfiles_path path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12198"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-39006",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00515,
      "epss_percentile": 0.41686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-73",
      "title": "An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39006"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-36537",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00511,
      "epss_percentile": 0.41438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-290",
      "title": "ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The application improperly trusts user-supplied identity data within the user parameter of the /login/oauth2/code/ endpoint. By manipulating the email address in this JSON object, a remote attacker can bypass authentication and gain full access to any existing user account on the platform without possessing the target user's credentials. This results in a complete account takeover.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36537"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-48017",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00511,
      "epss_percentile": 0.41429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dbgate",
      "product": "dbgate",
      "cwe": "CWE-94",
      "title": "DbGate: Remote Code Execution via functionName injection in loadReader endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48017"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-49766",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00506,
      "epss_percentile": 0.41132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP User Manager",
      "product": "WP User Manager",
      "cwe": "CWE-22",
      "title": "WordPress WP User Manager plugin <= 2.9.16 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49766"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-49781",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.005,
      "epss_percentile": 0.40763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brainstorm Force",
      "product": "OttoKit",
      "cwe": "CWE-502",
      "title": "WordPress OttoKit plugin <= 1.1.27 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49781"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2025-55642",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.005,
      "epss_percentile": 0.4079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-369",
      "title": "GPAC MP4Box v2.4 was discovered to contain a floating point exception in the avidmx_process function (isomedia/isom_write.c).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55642"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-50889",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00482,
      "epss_percentile": 0.39686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (DoS) via sending a crafted refresh-token header.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50889"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-9691",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00476,
      "epss_percentile": 0.39298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CRM Perks",
      "product": "Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms",
      "cwe": "CWE-502",
      "title": "WordPress Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms plugin <= 1.1.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9691"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-49085",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00476,
      "epss_percentile": 0.39298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CRM Perks",
      "product": "WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms",
      "cwe": "CWE-502",
      "title": "WordPress WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin <= 1.1.4 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49085"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-49104",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00476,
      "epss_percentile": 0.39299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CRM Perks",
      "product": "Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms",
      "cwe": "CWE-502",
      "title": "WordPress Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin <= 1.2.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49104"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-49105",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00476,
      "epss_percentile": 0.39299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CRM Perks",
      "product": "WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms",
      "cwe": "CWE-502",
      "title": "WordPress WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin <= 1.1.4 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49105"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-50880",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00476,
      "epss_percentile": 0.39322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50880"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-39591",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00465,
      "epss_percentile": 0.38566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CMSJunkie – WordPress Business Directory Plugins",
      "product": "WP-BusinessDirectory",
      "cwe": "CWE-434",
      "title": "WordPress WP-BusinessDirectory plugin <= 4.0.0 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39591"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-39434",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.37292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebAppick",
      "product": "CTX Feed",
      "cwe": "CWE-502",
      "title": "WordPress CTX Feed plugin <= 6.6.26 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39434"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-39471",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.37293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ShortPixel",
      "product": "ShortPixel Image Optimizer",
      "cwe": "CWE-502",
      "title": "WordPress ShortPixel Image Optimizer plugin <= 6.4.3 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39471"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-39472",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.37293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Overnight",
      "product": "WooCommerce PDF Invoices & Packing Slips",
      "cwe": "CWE-502",
      "title": "WordPress WooCommerce PDF Invoices & Packing Slips plugin < 5.9.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39472"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-39481",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.37292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Chill",
      "product": "Modula Image Gallery",
      "cwe": "CWE-502",
      "title": "WordPress Modula Image Gallery plugin <= 2.14.18 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39481"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-39499",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.37292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wombat Plugins",
      "product": "Advanced Product Fields (Product Addons) for WooCommerce",
      "cwe": "CWE-502",
      "title": "WordPress Advanced Product Fields (Product Addons) for WooCommerce plugin <= 1.6.19 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39499"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-5482",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00445,
      "epss_percentile": 0.37173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tecrail",
      "product": "Responsive FileManager",
      "cwe": "CWE-434",
      "title": "Remote Code Execution via Unrestricted File Upload in Responsive FileManager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5482"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-40769",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00442,
      "epss_percentile": 0.36956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Satinder Singh",
      "product": "Contact Form Extender for Divi &#8211; Save Entries, File Upload &amp; Country Code Field",
      "cwe": "CWE-22",
      "title": "WordPress Contact Form Extender for Divi – Save Entries, File Upload & Country Code Field plugin <= 1.0.6 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40769"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-50873",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00441,
      "epss_percentile": 0.3688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-434",
      "title": "An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or SVG file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50873"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-50878",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50878"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-12161",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.36645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Remote Desktop Manager",
      "cwe": "CWE-78",
      "title": "Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted alternate username and user interaction with the Elevate Shell action. This affects : - Remote Desktop Manager 2026.2.5.0 through 2026.2.7.0 - Remote Desktop Manager 2026.1.23.0 and earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12161"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-52703",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00436,
      "epss_percentile": 0.3651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ninja Team",
      "product": "FastDup",
      "cwe": "CWE-35",
      "title": "WordPress FastDup plugin <= 2.7.2 - Path Traversal vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52703"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-39474",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00428,
      "epss_percentile": 0.35877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "metaphorcreations",
      "product": "Post Duplicator",
      "cwe": "CWE-502",
      "title": "WordPress Post Duplicator plugin <= 3.0.10 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39474"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-39478",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00428,
      "epss_percentile": 0.35876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eli Scheetz",
      "product": "Anti-Malware Security and Brute-Force Firewall",
      "cwe": "CWE-502",
      "title": "WordPress Anti-Malware Security and Brute-Force Firewall plugin <= 4.23.87 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39478"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-42668",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00427,
      "epss_percentile": 0.35769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Omnisend",
      "product": "Email Marketing for WooCommerce by Omnisend",
      "cwe": "CWE-288",
      "title": "WordPress Email Marketing for WooCommerce by Omnisend plugin <= 1.18.0 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42668"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-48713",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00419,
      "epss_percentile": 0.3514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "i18next",
      "product": "i18next-fs-backend",
      "cwe": "CWE-1321",
      "title": "i18next-fs-backend: Prototype pollution via crafted missing-key string",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48713"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-48714",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00419,
      "epss_percentile": 0.3514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "i18next",
      "product": "i18next-http-middleware",
      "cwe": "CWE-1321",
      "title": "i18next-http-middleware missingKeyHandler does not reject keys whose segments contain prototype-polluting names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48714"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-40776",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00414,
      "epss_percentile": 0.34659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arraytics",
      "product": "WP Event SOlution",
      "cwe": "CWE-862",
      "title": "WordPress Eventin plugin <= 4.1.8 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40776"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-48889",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00412,
      "epss_percentile": 0.34498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TMS",
      "product": "Amelia",
      "cwe": "CWE-266",
      "title": "WordPress Amelia plugin <= 2.3 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48889"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-42411",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00405,
      "epss_percentile": 0.33877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XServer",
      "product": "CloudSecure WP Security",
      "cwe": "CWE-288",
      "title": "WordPress CloudSecure WP Security plugin <= 1.4.7 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42411"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-48708",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OliveTin",
      "product": "OliveTin",
      "cwe": "CWE-362",
      "title": "OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48708"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-12203",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00402,
      "epss_percentile": 0.33616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "AI-Trader",
      "cwe": "CWE-200",
      "title": "HKUDS AI-Trader Research Export agents.csv information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12203"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-49764",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.004,
      "epss_percentile": 0.33425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Metagauss",
      "product": "RegistrationMagic",
      "cwe": "CWE-288",
      "title": "WordPress RegistrationMagic plugin <= 6.0.8.6 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49764"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-34028",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00397,
      "epss_percentile": 0.33075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wertheim GmbH",
      "product": "Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)",
      "cwe": "CWE-425",
      "title": "Unauthenticated direct access to web data in Wertheim SafeController Software exposes files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34028"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-34026",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.32786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wertheim GmbH",
      "product": "Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)",
      "cwe": "CWE-23",
      "title": "Path traversal in Wertheim SafeController Software allows authenticated users to download arbitrary files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34026"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-38812",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00393,
      "epss_percentile": 0.32614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an authenticated attacker with administrative privileges to access sensitive database information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38812"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-48970",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Really Simple Plugins",
      "product": "Really Simple SSL",
      "cwe": "CWE-288",
      "title": "WordPress Really Simple SSL plugin <= 9.5.10 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48970"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-27407",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.3267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Meow Apps",
      "product": "AI Engine",
      "cwe": "CWE-266",
      "title": "WordPress AI Engine plugin <= 3.4.9 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27407"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-52722",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.3256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-190",
      "title": "Gstreamer1-plugins-bad-free: gstreamer: signed integer overflow in vmnc decoder cursor payload handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52722"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2016-20080",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0039,
      "epss_percentile": 0.32289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brandfolder",
      "product": "Brandfolder",
      "cwe": "CWE-98",
      "title": "WordPress Brandfolder Plugin 3.0 Local File Inclusion via callback.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20080"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-42378",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0039,
      "epss_percentile": 0.32292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeisle",
      "product": "WP Full Stripe Free",
      "cwe": "CWE-288",
      "title": "WordPress WP Full Stripe Free plugin <= 8.4.1 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42378"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-27053",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00386,
      "epss_percentile": 0.31969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VideoWhisper.com",
      "product": "Broadcast Live Video",
      "cwe": "CWE-502",
      "title": "WordPress Broadcast Live Video plugin < 7.1.3 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27053"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-49068",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RelyWP",
      "product": "Coupon Affiliates",
      "cwe": "CWE-497",
      "title": "WordPress Coupon Affiliates plugin <= 7.8.1 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49068"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-52718",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00386,
      "epss_percentile": 0.3194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-617",
      "title": "Gstreamer1-plugins-bad-free: gstreamer: denial of service via av1 tile_list_obu parser byte/bit confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52718"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-39450",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00385,
      "epss_percentile": 0.31873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aman",
      "product": "FunnelKit Automations",
      "cwe": "CWE-288",
      "title": "WordPress FunnelKit Automations plugin <= 3.7.3 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39450"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-40785",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00385,
      "epss_percentile": 0.31873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ruben Garcia",
      "product": "AutomatorWP",
      "cwe": "CWE-288",
      "title": "WordPress AutomatorWP plugin <= 5.6.7 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40785"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-42661",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aguilatechnologies",
      "product": "WP Customer Area",
      "cwe": "CWE-35",
      "title": "WordPress WP Customer Area plugin <= 8.3.4 - Path Traversal vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42661"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-49106",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CRM Perks",
      "product": "Integration for Contact Form 7 and Constant Contact",
      "cwe": "CWE-502",
      "title": "WordPress Integration for Contact Form 7 and Constant Contact plugin <= 1.1.6 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49106"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-49109",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.3162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "crm perks",
      "product": "Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms",
      "cwe": "CWE-502",
      "title": "WordPress Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin <= 1.4.3 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49109"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-49763",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CRM Perks",
      "product": "Integration for Contact Form 7 HubSpot",
      "cwe": "CWE-502",
      "title": "WordPress Integration for Contact Form 7 HubSpot plugin <= 1.3.7 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49763"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-49765",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CRM Perks",
      "product": "Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms",
      "cwe": "CWE-502",
      "title": "WordPress Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms plugin <= 1.1.8 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49765"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-49768",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Happyforms",
      "product": "Happyforms",
      "cwe": "CWE-502",
      "title": "WordPress Happyforms plugin <= 1.26.13 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49768"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-49769",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tomdever",
      "product": "wpForo Forum",
      "cwe": "CWE-502",
      "title": "WordPress wpForo Forum plugin <= 3.1.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49769"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-49770",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Travel Engine",
      "product": "WP Travel Engine",
      "cwe": "CWE-502",
      "title": "WordPress WP Travel Engine plugin <= 6.7.12 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49770"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-39470",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00382,
      "epss_percentile": 0.31499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brainstorm Force",
      "product": "WooCommerce Cart Abandonment Recovery",
      "cwe": "CWE-266",
      "title": "WordPress WooCommerce Cart Abandonment Recovery plugin < 2.1.0 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39470"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-39480",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Inisev",
      "product": "Backup Migration",
      "cwe": "CWE-201",
      "title": "WordPress Backup Migration plugin <= 2.1.1 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39480"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-53705",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.30791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-190",
      "title": "Gstreamer1-plugins-good: gstreamer: heap buffer overflow in wavpack decoder via integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53705"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-39007",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.30769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitive information via the CSV Log export component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39007"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-50883",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00374,
      "epss_percentile": 0.30664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a crafted payload.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50883"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-12087",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00374,
      "epss_percentile": 0.30704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PEVANS",
      "product": "Socket",
      "cwe": "CWE-125",
      "title": "Socket versions before 2.041 for Perl have an out-of-bounds heap read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12087"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2016-20077",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00374,
      "epss_percentile": 0.30709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KaymeePhotography",
      "product": "Photocart Link",
      "cwe": "CWE-98",
      "title": "WordPress Plugin Photocart Link 1.6 Local File Inclusion via decode.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20077"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-45390",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00373,
      "epss_percentile": 0.3057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. This is not desired behavior, and tar(1) rejects such extractions, but ocaml-tar decompresses it anyway. The impact is that it allows arbitrary file writes outside of the desired extraction directory (to an attacker that can reach a tar decompression endpoint).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45390"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-25425",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.30522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeGrill",
      "product": "User Registration",
      "cwe": "CWE-862",
      "title": "WordPress User Registration plugin <= 5.1.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25425"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-12211",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00372,
      "epss_percentile": 0.30508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Intelbras",
      "product": "iNVU 7016 FT",
      "cwe": "CWE-22",
      "title": "Intelbras iNVU 7016 FT Web syslog path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12211"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-12218",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yealink",
      "product": "SIP-T46U",
      "cwe": "CWE-119",
      "title": "Yealink SIP-T46U Web FastCGI Service beforewifitest StartReportInformation stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12218"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-12220",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yealink",
      "product": "SIP-T46U",
      "cwe": "CWE-119",
      "title": "Yealink SIP-T46U Firmware Chunk Upload handler accupgradebychunk mod_upgrade.SparePartsUpload stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12220"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-12221",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yealink",
      "product": "SIP-T46U",
      "cwe": "CWE-119",
      "title": "Yealink SIP-T46U Firmware Chunk Upload upgrade sprintf stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12221"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-12222",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yealink",
      "product": "SIP-T46U",
      "cwe": "CWE-119",
      "title": "Yealink SIP-T46U Web FastCGI Service bttest mod_webd.BlueToothTest stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12222"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-48114",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0037,
      "epss_percentile": 0.30278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NCEAS",
      "product": "metacat",
      "cwe": "CWE-89",
      "title": "Metacat has an unauthenticated SQL injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48114"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-52697",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Taskbuilder",
      "product": "Taskbuilder",
      "cwe": "CWE-89",
      "title": "WordPress Taskbuilder plugin <= 5.0.7 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52697"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-52700",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WcMultishipping – Mondial Relay & Chronopost for Wooommerce",
      "product": "WCMultiShipping",
      "cwe": "CWE-89",
      "title": "WordPress WCMultiShipping plugin <= 3.0.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52700"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-49056",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebToffee",
      "product": "WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels",
      "cwe": "CWE-497",
      "title": "WordPress WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin <= 4.9.4 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49056"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-39492",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00363,
      "epss_percentile": 0.29582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flipper Code – WordPress Development Company",
      "product": "WP Maps",
      "cwe": "CWE-89",
      "title": "WordPress WP Maps plugin <= 4.9.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39492"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-39493",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00363,
      "epss_percentile": 0.29582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NSquared",
      "product": "Simply Schedule Appointments",
      "cwe": "CWE-89",
      "title": "WordPress Simply Schedule Appointments plugin <= 1.6.9.27 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39493"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-49061",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPClever",
      "product": "WPC Product Options for WooCommerce",
      "cwe": "CWE-22",
      "title": "WordPress WPC Product Options for WooCommerce plugin <= 3.2.1 - Arbitrary File Download vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49061"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-36670",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29312,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows authenticated attackers to execute arbitrary SQL commands via the 'table' GET parameter in alias_management.php.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36670"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-40772",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00359,
      "epss_percentile": 0.29134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ahmad",
      "product": "GeekyBot",
      "cwe": "CWE-434",
      "title": "WordPress GeekyBot plugin <= 1.2.2 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40772"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-39498",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00359,
      "epss_percentile": 0.29135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yeeaddons",
      "product": "YayMail",
      "cwe": "CWE-502",
      "title": "WordPress YayMail plugin <= 4.3.3 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39498"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-49953",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00359,
      "epss_percentile": 0.29148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Discuz!",
      "product": "Discuz! X5.0",
      "cwe": "CWE-804",
      "title": "Discuz! X5.0 CAPTCHA Bypass via Predictable Character Set",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49953"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-39583",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00357,
      "epss_percentile": 0.2891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Datalogics",
      "product": "Datalogics Ecommerce Delivery",
      "cwe": "CWE-266",
      "title": "WordPress Datalogics Ecommerce Delivery plugin <= 2.6.62 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39583"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-47261",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00357,
      "epss_percentile": 0.28969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bytecodealliance",
      "product": "wasmtime",
      "cwe": "CWE-284",
      "title": "Wasmtime: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47261"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-42686",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EventPrime",
      "product": "EventPrime",
      "cwe": "CWE-79",
      "title": "WordPress EventPrime plugin <= 4.3.2.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42686"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-39515",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00352,
      "epss_percentile": 0.28421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StylemixThemes",
      "product": "Motors",
      "cwe": "CWE-862",
      "title": "WordPress Motors plugin < 1.4.107 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39515"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-53430",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-grpc",
      "product": "grpc",
      "cwe": "CWE-409",
      "title": "grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53430"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-48872",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPDeveloper",
      "product": "EmbedPress",
      "cwe": "CWE-639",
      "title": "WordPress EmbedPress plugin <= 4.5.2 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48872"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-40796",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.2766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ollybach",
      "product": "WPPizza",
      "cwe": "CWE-497",
      "title": "WordPress WPPizza plugin <= 3.19.9 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40796"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-42660",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.2766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wasiliy Strecker",
      "product": "Contest Gallery",
      "cwe": "CWE-497",
      "title": "WordPress Contest Gallery plugin <= 28.1.7 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42660"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-48878",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.2766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bootstrapped Ventures",
      "product": "Visual Link Preview",
      "cwe": "CWE-497",
      "title": "WordPress Visual Link Preview plugin <= 2.4.1 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48878"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-39532",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stiofan",
      "product": "Events Calendar for GeoDirectory",
      "cwe": "CWE-502",
      "title": "WordPress Events Calendar for GeoDirectory plugin <= 2.3.25 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39532"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-48854",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-grpc",
      "product": "grpc",
      "cwe": "CWE-770",
      "title": "Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48854"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-49083",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.2758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LatePoint",
      "product": "LatePoint",
      "cwe": "CWE-266",
      "title": "WordPress LatePoint plugin <= 5.5.1 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49083"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-40727",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Groundhogg",
      "product": "Groundhogg",
      "cwe": "CWE-22",
      "title": "WordPress Groundhogg plugin <= 4.4 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40727"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-52719",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Gstreamer1-plugins-bad-free: gstreamer: out-of-bounds read via jpeg segment length validation in va decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52719"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-39489",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00337,
      "epss_percentile": 0.268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Chill",
      "product": "Download Monitor",
      "cwe": "CWE-22",
      "title": "WordPress Download Monitor plugin <= 5.1.9 - Non-Arbitrary File Download vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39489"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-34023",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wertheim GmbH",
      "product": "Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)",
      "cwe": "CWE-863",
      "title": "Broken WebSocket authorization in Wertheim SafeController Software allows cross-branch access to restricted functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34023"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-40766",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.26233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StylemixThemes",
      "product": "MasterStudy LMS",
      "cwe": "CWE-89",
      "title": "WordPress MasterStudy LMS plugin <= 3.7.25 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40766"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-48874",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.26231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ruben Garcia",
      "product": "GamiPress",
      "cwe": "CWE-89",
      "title": "WordPress GamiPress plugin <= 7.8.7 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48874"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-48882",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.26232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codepeople",
      "product": "WP Time Slots Booking Form",
      "cwe": "CWE-89",
      "title": "WordPress WP Time Slots Booking Form plugin <= 1.2.50 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48882"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-48964",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.26232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ELEXtensions",
      "product": "ELEX WordPress HelpDesk & Customer Ticketing System",
      "cwe": "CWE-89",
      "title": "WordPress ELEX WordPress HelpDesk & Customer Ticketing System plugin <= 3.3.6 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48964"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-48709",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00329,
      "epss_percentile": 0.25862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OliveTin",
      "product": "OliveTin",
      "cwe": "CWE-862",
      "title": "OliveTin: ValidateArgumentType API Endpoint Missing Authentication Allows Action and Argument Enumeration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48709"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-11832",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00327,
      "epss_percentile": 0.25673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BIAFRA",
      "product": "Dancer2::Plugin::Auth::OAuth",
      "cwe": "CWE-338",
      "title": "Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11832"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2016-20075",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Etoilewebdesign",
      "product": "Ultimate Product Catalog",
      "cwe": "CWE-863",
      "title": "WordPress Ultimate Product Catalog 3.8.6 Arbitrary File Upload RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20075"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-40779",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yannick Lefebvre",
      "product": "Link Library",
      "cwe": "CWE-22",
      "title": "WordPress Link Library plugin <= 7.8.8 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40779"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-34030",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00327,
      "epss_percentile": 0.25628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wertheim GmbH",
      "product": "Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)",
      "cwe": "CWE-73",
      "title": "Improper branch-code validation in Wertheim SafeController Software allows file path manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34030"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-50891",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.25563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafted request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50891"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-49112",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.25533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tammersoft",
      "product": "Shared Files",
      "cwe": "CWE-35",
      "title": "WordPress Shared Files plugin <= 1.7.64 - Path Traversal vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49112"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2016-20082",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00326,
      "epss_percentile": 0.25547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "abtest",
      "product": "Abtest",
      "cwe": "CWE-98",
      "title": "WordPress Plugin Abtest Local File Inclusion via abtest_admin.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20082"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2025-69332",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00326,
      "epss_percentile": 0.25561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "myCred",
      "product": "Bookify",
      "cwe": "CWE-862",
      "title": "WordPress Bookify plugin <= 1.1.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69332"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-39584",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00326,
      "epss_percentile": 0.25562,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webful Creations",
      "product": "RepairBuddy",
      "cwe": "CWE-862",
      "title": "WordPress RepairBuddy plugin <= 4.1132 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39584"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-40790",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00326,
      "epss_percentile": 0.25562,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VeronaLabs",
      "product": "WP SMS",
      "cwe": "CWE-288",
      "title": "WordPress WP SMS plugin <= 7.2.1 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40790"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-48965",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00326,
      "epss_percentile": 0.25566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "watchful",
      "product": "XCloner",
      "cwe": "CWE-201",
      "title": "WordPress XCloner plugin <= 4.8.6 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48965"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-30121",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00324,
      "epss_percentile": 0.25367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-123",
      "title": "remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30121"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-50879",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50879"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-50882",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50882"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-12200",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00324,
      "epss_percentile": 0.25342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ritlabs",
      "product": "TinyWeb Server",
      "cwe": "CWE-119",
      "title": "Ritlabs TinyWeb Server Header libeay32.dll.html stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12200"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-34901",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00321,
      "epss_percentile": 0.25015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paul",
      "product": "iControlWP",
      "cwe": "CWE-266",
      "title": "WordPress iControlWP plugin <= 5.5.3 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34901"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-39196",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00321,
      "epss_percentile": 0.2497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::partition function. This vulnerability allows attackers to access sensitive database information via crafted SQL statements.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39196"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-50890",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00321,
      "epss_percentile": 0.24969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /stockreports/spendings. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50890"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-27333",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VideoWhisper.com",
      "product": "Paid Videochat Turnkey Site",
      "cwe": "CWE-502",
      "title": "WordPress Paid Videochat Turnkey Site plugin <= 7.3.23 - Deserialization of untrusted data vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27333"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-42687",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EventPrime",
      "product": "EventPrime",
      "cwe": "CWE-502",
      "title": "WordPress EventPrime plugin <= 4.3.2.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42687"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-42662",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Liquid Web / StellarWP",
      "product": "Event Tickets",
      "cwe": "CWE-290",
      "title": "WordPress Event Tickets plugin <= 5.27.5 - Bypass Vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42662"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-12208",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.24234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jsonata-js",
      "product": "jsonata",
      "cwe": "CWE-94",
      "title": "jsonata-js jsonata Function Binding Frame System jsonata.js createFrame prototype pollution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12208"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-12209",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.24233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RubyLouvre",
      "product": "avalon",
      "cwe": "CWE-94",
      "title": "RubyLouvre avalon Template Filter index.js prototype pollution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12209"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-50886",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00312,
      "epss_percentile": 0.23977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted POST request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50886"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2016-20071",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.24051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "404-redirection-manager",
      "product": "404 Redirection Manager",
      "cwe": "CWE-89",
      "title": "WordPress 404 Redirection Manager Plugin 1.0 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20071"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-40799",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00309,
      "epss_percentile": 0.23674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RelyWP",
      "product": "Simple Cloudflare Turnstile",
      "cwe": "CWE-288",
      "title": "WordPress Simple Cloudflare Turnstile plugin <= 1.38.0 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40799"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-50870",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "An information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows attackers to obtain sensitive information via a crafted GET request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50870"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-40788",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuantumCloud",
      "product": "ChatBot",
      "cwe": "CWE-862",
      "title": "WordPress ChatBot plugin <= 7.9.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40788"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-39534",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00306,
      "epss_percentile": 0.23271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wp Directory Kit",
      "product": "WP Directory Kit",
      "cwe": "CWE-862",
      "title": "WordPress WP Directory Kit plugin <= 1.5.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39534"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-52704",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00305,
      "epss_percentile": 0.23156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edgar Rojas",
      "product": "WooCommerce PDF Invoice Builder",
      "cwe": "CWE-94",
      "title": "WordPress WooCommerce PDF Invoice Builder plugin <= 2.0.8 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52704"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-48835",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Awesomemotive",
      "product": "Contact Form by WPForms",
      "cwe": "CWE-862",
      "title": "WordPress Contact Form by WPForms plugin <= 1.10.0.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48835"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-34027",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.23195,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wertheim GmbH",
      "product": "Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)",
      "cwe": "CWE-434",
      "title": "Upload restriction bypass in Wertheim SafeController Software allows authenticated users to upload arbitrary files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34027"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-5242",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MIA Technology Inc.",
      "product": "Pizzy Library",
      "cwe": "CWE-1236",
      "title": "Code Injection in Mia Technologies' Pizzy Library",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5242"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-34024",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wertheim GmbH",
      "product": "Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)",
      "cwe": "CWE-862",
      "title": "Missing authorization checks in Wertheim SafeController Software allow low-privileged users to access restricted functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34024"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-39533",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPTasty",
      "product": "AWP Classifieds",
      "cwe": "CWE-862",
      "title": "WordPress AWP Classifieds plugin <= 4.4.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39533"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-47835",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring AI",
      "cwe": "CWE-943",
      "title": "Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47835"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-34891",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IDPay",
      "product": "IDPay Payment Gateway for Woocommerce",
      "cwe": "CWE-497",
      "title": "WordPress IDPay Payment Gateway for Woocommerce plugin <= 2.2.5 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34891"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2016-20068",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dwbooster",
      "product": "Booking Calendar Contact Form",
      "cwe": "CWE-89",
      "title": "WordPress Booking Calendar Contact Form 1.0.23 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20068"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-39530",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00296,
      "epss_percentile": 0.22196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SpeakOut!",
      "product": "SpeakOut! Email Petitions",
      "cwe": "CWE-89",
      "title": "WordPress SpeakOut! Email Petitions plugin <= 4.6.5 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39530"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-39511",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00295,
      "epss_percentile": 0.22109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jacob N. Breetvelt",
      "product": "WP Photo Album Plus",
      "cwe": "CWE-89",
      "title": "WordPress WP Photo Album Plus plugin <= 9.1.08.001 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39511"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-34892",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rank Math SEO",
      "product": "Rank Math SEO",
      "cwe": "CWE-862",
      "title": "WordPress Rank Math SEO plugin <= 1.0.271 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34892"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-40781",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.22,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ReviewX",
      "product": "ReviewX",
      "cwe": "CWE-288",
      "title": "WordPress ReviewX plugin <= 2.3.6 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40781"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-40789",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.21979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TMS",
      "product": "Amelia",
      "cwe": "CWE-201",
      "title": "WordPress Amelia plugin <= 2.2 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40789"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-42384",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.2198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NSquared",
      "product": "Simply Schedule Appointments",
      "cwe": "CWE-201",
      "title": "WordPress Simply Schedule Appointments plugin < 1.6.11.2 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42384"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-42667",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.2198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bookly",
      "product": "Bookly",
      "cwe": "CWE-201",
      "title": "WordPress Bookly plugin <= 27.4 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42667"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-49066",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.21979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Conekta Group",
      "product": "Conekta Payment Gateway",
      "cwe": "CWE-497",
      "title": "WordPress Conekta Payment Gateway plugin <= 6.0.0 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49066"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-39502",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00292,
      "epss_percentile": 0.21838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10Web",
      "product": "Form Maker by 10Web",
      "cwe": "CWE-89",
      "title": "WordPress Form Maker by 10Web plugin <= 1.15.38 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39502"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-12204",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "ShopXO",
      "cwe": "CWE-285",
      "title": "ShopXO Scheduled Task Endpoint Crontab.php GoodsGiveIntegral authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12204"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-45439",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Realtyna",
      "product": "Realtyna Organic IDX plugin",
      "cwe": "CWE-89",
      "title": "WordPress Realtyna Organic IDX plugin plugin <= 5.1.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45439"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-39527",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21698,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sc Internet Vivoo",
      "product": "WpStream",
      "cwe": "CWE-434",
      "title": "WordPress WpStream plugin < 4.11.2 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39527"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-49062",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.21616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Engine",
      "product": "Faust.js",
      "cwe": "CWE-288",
      "title": "WordPress Faust.js plugin <= 1.8.7 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49062"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-49067",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00289,
      "epss_percentile": 0.21468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yydevelopment",
      "product": "Advanced 301 and 302 Redirect",
      "cwe": "CWE-89",
      "title": "WordPress Advanced 301 and 302 Redirect plugin <= 1.6.9 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49067"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-49776",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00289,
      "epss_percentile": 0.21467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JExtensions Store",
      "product": "GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites",
      "cwe": "CWE-89",
      "title": "WordPress GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin <= 2.32.6 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49776"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-52693",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00289,
      "epss_percentile": 0.21467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "impleCode",
      "product": "eCommerce Product Catalog",
      "cwe": "CWE-89",
      "title": "WordPress eCommerce Product Catalog plugin <= 3.5.5 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52693"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-12205",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00289,
      "epss_percentile": 0.21453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TIMLEGGE",
      "product": "Crypt::DSA",
      "cwe": "CWE-323",
      "title": "Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12205"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-39197",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Service (DoS) via a crafted request or payload.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39197"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-50887",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00287,
      "epss_percentile": 0.21247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-918",
      "title": "A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a crafted longUrl.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50887"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2018-25437",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cherryframework",
      "product": "Cherry Framework Themes",
      "cwe": "CWE-306",
      "title": "WordPress CherryFramework Themes 3.1.4 Backup File Download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2018-25437"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2025-59133",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Projectopia",
      "product": "Projectopia",
      "cwe": "CWE-639",
      "title": "WordPress Projectopia plugin <= 5.1.25.2 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59133"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-39513",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Easy Appointments",
      "product": "Easy Appointments",
      "cwe": "CWE-862",
      "title": "WordPress Easy Appointments plugin <= 3.12.21 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39513"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-40767",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tomdever",
      "product": "wpForo Forum",
      "cwe": "CWE-281",
      "title": "WordPress wpForo Forum plugin < 3.0.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40767"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-50885",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to access sensitive endpoints via a crafted request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50885"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-39594",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.21294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themefic",
      "product": "Ultra Addons for WPForms",
      "cwe": "CWE-862",
      "title": "WordPress Ultra Addons for WPForms plugin <= 1.0.11 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39594"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-50884",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administrator and access sensitive components.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50884"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2025-55645",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.21143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "A heap buffer overflow in the gf_cenc_set_pssh function (isomedia/drm_sample.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55645"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2025-55648",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.21143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "A heap buffer overflow in the gf_opus_parse_packet_header function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55648"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2025-68713",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.20944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-926",
      "title": "An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows untrusted applications (with no permissions) to force arbitrary file downloads into the app's scoped storage. The resulting files appear in the application's trusted Received interface. These conditions establish a vector for arbitrary code execution if the payload is an APK file, or a denial-of-service condition through resource exhaustion from oversized transfers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68713"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-44188",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00284,
      "epss_percentile": 0.20988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.7",
      "cwe": "CWE-613",
      "title": "Ansible-lightspeed: ansible lightspeed: session hijacking and unauthorized data access due to insufficient session expiration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44188"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-39441",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Naked Cat Plugins (by Webdados)",
      "product": "Feed KuantoKusta for WooCommerce – Free",
      "cwe": "CWE-89",
      "title": "WordPress Feed KuantoKusta for WooCommerce – Free plugin <= 5.3 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39441"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-39512",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paolo",
      "product": "GeoDirectory",
      "cwe": "CWE-89",
      "title": "WordPress GeoDirectory plugin <= 2.8.152 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39512"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-39519",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ahmad",
      "product": "GeekyBot",
      "cwe": "CWE-89",
      "title": "WordPress GeekyBot plugin <= 1.2.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39519"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-40771",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.2087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wasiliy Strecker",
      "product": "Contest Gallery",
      "cwe": "CWE-89",
      "title": "WordPress Contest Gallery plugin <= 28.1.6 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40771"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-40798",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tomdever",
      "product": "wpForo Forum",
      "cwe": "CWE-89",
      "title": "WordPress wpForo Forum plugin <= 3.0.4 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40798"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-42381",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FunnelKit",
      "product": "Funnel Builder by FunnelKit",
      "cwe": "CWE-89",
      "title": "WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42381"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-42386",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tychesoftwares",
      "product": "Order Delivery Date for WooCommerce",
      "cwe": "CWE-89",
      "title": "WordPress Order Delivery Date for WooCommerce plugin <= 4.5.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42386"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-42639",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dev4Press",
      "product": "GD Rating System",
      "cwe": "CWE-89",
      "title": "WordPress GD Rating System plugin <= 3.6.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42639"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-42665",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Passionate Programmer Peter",
      "product": "WP Data Access",
      "cwe": "CWE-89",
      "title": "WordPress WP Data Access plugin <= 5.5.70 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42665"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-48886",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ahmad",
      "product": "JS Help Desk",
      "cwe": "CWE-89",
      "title": "WordPress JS Help Desk plugin <= 3.0.9 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48886"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-49780",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.2093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokan, Inc.",
      "product": "Dokan",
      "cwe": "CWE-266",
      "title": "WordPress Dokan plugin <= 5.0.2 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49780"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-39587",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hakan Ozevin",
      "product": "WP BASE Booking",
      "cwe": "CWE-266",
      "title": "WordPress WP BASE Booking plugin <= 5.9.0 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39587"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-34025",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00283,
      "epss_percentile": 0.20908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wertheim GmbH",
      "product": "Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)",
      "cwe": "CWE-290",
      "title": "IP restriction bypass in Wertheim SafeController Software allows logins from unauthorized network locations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34025"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-50875",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers to arbitrarily modify or delete another tenant's webhook via a crafted request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50875"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-40773",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00279,
      "epss_percentile": 0.20474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rtCamp Inc.",
      "product": "rtMedia for WordPress, BuddyPress and bbPress",
      "cwe": "CWE-862",
      "title": "WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.9 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40773"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-40793",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00279,
      "epss_percentile": 0.20473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Groundhogg",
      "product": "Groundhogg",
      "cwe": "CWE-862",
      "title": "WordPress Groundhogg plugin < 4.4.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40793"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-40794",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00279,
      "epss_percentile": 0.20473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "myCred",
      "product": "myCred",
      "cwe": "CWE-862",
      "title": "WordPress myCred plugin <= 3.0.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40794"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-48881",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00278,
      "epss_percentile": 0.20374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themetechmount",
      "product": "TrueBooker",
      "cwe": "CWE-862",
      "title": "WordPress TrueBooker plugin <= 1.1.9 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48881"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-39579",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.2029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bPlugins",
      "product": "B Blocks",
      "cwe": "CWE-266",
      "title": "WordPress B Blocks plugin <= 2.0.31 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39579"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-5038",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "multer",
      "product": "multer",
      "cwe": "CWE-459",
      "title": "multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5038"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-5079",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "multer",
      "product": "multer",
      "cwe": "CWE-400",
      "title": "multer vulnerable to Denial of Service via deeply nested field names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5079"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-41708",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Cloud Sleuth",
      "cwe": "CWE-400",
      "title": "Spring Cloud Sleuth instrumentation of Spring TX DoS vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41708"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-42666",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dimitri Grassi",
      "product": "Salon booking system",
      "cwe": "CWE-862",
      "title": "WordPress Salon booking system plugin <= 10.30.25 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42666"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-48868",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mra13 / Team Tips and Tricks HQ",
      "product": "Simple Shopping Cart",
      "cwe": "CWE-639",
      "title": "WordPress Simple Shopping Cart plugin <= 5.2.9 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48868"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-39518",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EventPrime",
      "product": "EventPrime",
      "cwe": "CWE-639",
      "title": "WordPress EventPrime plugin <= 4.3.0.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39518"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-10634",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.19865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-416",
      "title": "Use-after-free in Zephyr native TCP `net_tcp_foreach()` due to dropping `tcp_lock` during the callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10634"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-48599",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-grpc",
      "product": "grpc",
      "cwe": "CWE-639",
      "title": "Authorization bypass via path binding override in elixir-grpc/grpc HTTP transcoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48599"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-40795",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00271,
      "epss_percentile": 0.1941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TMS",
      "product": "Amelia",
      "cwe": "CWE-862",
      "title": "WordPress Amelia plugin <= 2.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40795"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-42659",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00271,
      "epss_percentile": 0.1941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nasir Ahmed",
      "product": "Advanced Form Integration",
      "cwe": "CWE-862",
      "title": "WordPress Advanced Form Integration plugin <= 1.126.12 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42659"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2016-20072",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bbsetheme",
      "product": "BBS e-Franchise",
      "cwe": "CWE-89",
      "title": "BBS e-Franchise 1.1.1 WordPress Plugin SQL Injection via uid",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20072"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2016-20073",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mattkaye",
      "product": "Answer My Question",
      "cwe": "CWE-89",
      "title": "Answer My Question 1.3 Plugin WordPress SQL Injection via modal.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20073"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-8935",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00268,
      "epss_percentile": 0.19086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP MAPS PRO",
      "cwe": null,
      "title": "Advanced Google Maps < 6.1.1 - Unauthenticated Administrator Account Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8935"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-27089",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Magepeople inc.",
      "product": "WpTravelly",
      "cwe": "CWE-290",
      "title": "WordPress WpTravelly plugin <= 2.1.7 - Bypass Vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27089"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-9258",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.1895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canon Inc.",
      "product": "EOS Network Setting Tool for Windows",
      "cwe": "CWE-295",
      "title": "Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9258"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-49082",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.18394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chatway Live Chat",
      "product": "Chatway Live Chat &#8211; AI Chatbot, Customer Support, FAQ &amp; Helpdesk Customer Service &amp; Chat Buttons",
      "cwe": "CWE-201",
      "title": "WordPress Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons plugin <= 1.4.8 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49082"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-9262",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.18403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canon Inc.",
      "product": "EOS Network Setting Tool for Windows",
      "cwe": "CWE-1188",
      "title": "Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9262"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-45441",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.1779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Magepeople inc.",
      "product": "WpEvently",
      "cwe": "CWE-1284",
      "title": "WordPress WpEvently plugin <= 5.3.3 - Other Vulnerability Type vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45441"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-48969",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Really Simple Plugins B.V.",
      "product": "Really Simple SSL",
      "cwe": "CWE-862",
      "title": "WordPress Really Simple SSL plugin <= 9.5.9 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48969"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2025-55652",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "A heap buffer overflow in the gf_isom_vp_config_new function (isomedia/avc_ext.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55652"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2025-55660",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "A stack overflow in the gf_opus_read_length function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55660"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2025-55661",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "A heap buffer overflow in the Opus audio stream parser component of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55661"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-42664",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.17105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Motive Commerce Search",
      "product": "AI Product Search for WooCommerce &#8211; Motive Commerce Search",
      "cwe": "CWE-862",
      "title": "WordPress AI Product Search for WooCommerce – Motive Commerce Search plugin <= 1.38.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42664"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-24637",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.16982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Blubrry Podcasting",
      "product": "PowerPress Podcasting",
      "cwe": "CWE-89",
      "title": "WordPress PowerPress Podcasting plugin <= 11.15.10 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24637"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-49078",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Travel Engine",
      "product": "WP Travel Engine",
      "cwe": "CWE-1284",
      "title": "WordPress WP Travel Engine plugin <= 6.7.10 - Other Vulnerability Type vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49078"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-40743",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.16876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeum",
      "product": "Tutor LMS",
      "cwe": "CWE-862",
      "title": "WordPress Tutor LMS plugin <= 3.9.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40743"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-34886",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.16756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wp.insider",
      "product": "Simple Membership",
      "cwe": "CWE-862",
      "title": "WordPress Simple Membership plugin <= 4.7.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34886"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-40762",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.16769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPGraphQL",
      "product": "WPGraphQL",
      "cwe": "CWE-89",
      "title": "WordPress WPGraphQL plugin < 2.11.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40762"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-40792",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.1656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Iqonic Design",
      "product": "KiviCare",
      "cwe": "CWE-639",
      "title": "WordPress KiviCare plugin <= 4.2.1 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40792"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-42655",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPManageNinja",
      "product": "Best Payments Plugin for WP",
      "cwe": "CWE-472",
      "title": "WordPress Best Payments Plugin for WP plugin <= 4.6.19 - Payment Bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42655"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-50881",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate privileges to Administrator and execute unauthorized account, password, and configuration changes.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50881"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-50888",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.1638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-918",
      "title": "An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows attackers to scan internal resources via supplying a crafted URL.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50888"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-34898",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Swings",
      "product": "Event Tickets Manager for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Event Tickets Manager for WooCommerce plugin <= 1.5.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34898"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-39503",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Awesomemotive",
      "product": "Easy Digital Downloads",
      "cwe": "CWE-862",
      "title": "WordPress Easy Digital Downloads plugin <= 3.6.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39503"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-39524",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeGrill",
      "product": "Masteriyo - LMS",
      "cwe": "CWE-862",
      "title": "WordPress Masteriyo - LMS plugin <= 2.1.5 - Payment Bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39524"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-40741",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jose Conti",
      "product": "Redsys for WooCommerce Light",
      "cwe": "CWE-862",
      "title": "WordPress Redsys for WooCommerce Light plugin <= 7.0.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40741"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-53703",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.15984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Gstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demuxer audio stream header parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53703"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2016-20084",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.15964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dwbooster",
      "product": "Booking Calendar Contact",
      "cwe": "CWE-79",
      "title": "WordPress appointment-booking-calendar 1.1.24 Privilege Escalation XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20084"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-52695",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Al Monsor",
      "product": "ABC Crypto Checkout",
      "cwe": "CWE-201",
      "title": "WordPress ABC Crypto Checkout plugin <= 1.8.2 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52695"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2025-55641",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "A NULL pointer dereference in the gf_isom_copy_sample_info function (isomedia/isom_write.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55641"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2025-55643",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "A NULL pointer dereference in the TrackWriter handling component (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55643"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2025-55644",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-416",
      "title": "A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55644"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2025-55647",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-190",
      "title": "An Out-of-Memory in the mp4_mux_cenc_insert_pssh function (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55647"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2025-55649",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "A NULL pointer dereference in the gf_media_map_esd function (media_tools/isom_tools.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55649"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2025-55650",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-416",
      "title": "A heap use-after-free in the gf_node_get_tag function (scenegraph/base_scenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55650"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2025-55663",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "A segmentation violation in the Track_SetStreamDescriptor function (isomedia/track.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55663"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-39525",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.1564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Booking Activities Team",
      "product": "Booking Activities",
      "cwe": "CWE-862",
      "title": "WordPress Booking Activities plugin <= 1.16.48.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39525"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-40782",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Greg Winiarski",
      "product": "WPAdverts",
      "cwe": "CWE-862",
      "title": "WordPress WPAdverts plugin <= 2.3.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40782"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2025-68049",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bunny.net",
      "product": "bunny.net",
      "cwe": "CWE-862",
      "title": "WordPress bunny.net plugin <= 2.3.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68049"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-42651",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mamunur Rashid",
      "product": "Classified Listing",
      "cwe": "CWE-862",
      "title": "WordPress Classified Listing plugin <= 5.3.9 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42651"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2016-20069",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.1543,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dwbooster",
      "product": "Booking Calendar Contact Form",
      "cwe": "CWE-89",
      "title": "WordPress Booking Calendar Contact Form 1.0.23 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20069"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-49111",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeGrill",
      "product": "Masteriyo - LMS",
      "cwe": "CWE-266",
      "title": "WordPress Masteriyo - LMS plugin <= 2.2.0 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49111"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-40774",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SaasProject",
      "product": "Booking Package",
      "cwe": "CWE-862",
      "title": "WordPress Booking Package plugin <= 1.7.06 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40774"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-48873",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.1517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Montonio",
      "product": "Montonio for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Montonio for WooCommerce plugin <= 10.1.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48873"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-48883",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPClever",
      "product": "WPC Product Bundles for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress WPC Product Bundles for WooCommerce plugin <= 8.5.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48883"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-49064",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stiofan",
      "product": "GetPaid",
      "cwe": "CWE-201",
      "title": "WordPress GetPaid plugin <= 2.8.49 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49064"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-49070",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Knit Pay",
      "product": "Knit Pay",
      "cwe": "CWE-862",
      "title": "WordPress Knit Pay plugin <= 9.4.0.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49070"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-52692",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wp.insider",
      "product": "Affiliates Manager",
      "cwe": "CWE-201",
      "title": "WordPress Affiliates Manager plugin <= 2.9.50 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52692"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-52694",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP E-Signature",
      "product": "Signature Add-On for WooCommerce",
      "cwe": "CWE-497",
      "title": "WordPress Signature Add-On for WooCommerce plugin <= 2.0 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52694"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-49065",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hippooo",
      "product": "Hippoo Mobile App for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49065"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-23970",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeisle",
      "product": "Redirection for Contact Form 7",
      "cwe": "CWE-79",
      "title": "WordPress Redirection for Contact Form 7 plugin <= 3.2.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23970"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-39447",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NSquared",
      "product": "Simply Schedule Appointments",
      "cwe": "CWE-79",
      "title": "WordPress Simply Schedule Appointments plugin <= 1.6.10.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39447"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-48838",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPExperts",
      "product": "Post SMTP",
      "cwe": "CWE-79",
      "title": "WordPress Post SMTP plugin <= 3.6.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48838"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-49110",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Swings",
      "product": "Upsell Order Bump Offer for WooCommerce",
      "cwe": "CWE-1284",
      "title": "WordPress Upsell Order Bump Offer for WooCommerce plugin <= 3.1.4 - Price Manipulation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49110"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-42688",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Chill",
      "product": "Modula Image Gallery",
      "cwe": "CWE-79",
      "title": "WordPress Modula Image Gallery plugin <= 2.14.23 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42688"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-11860",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSolution",
      "product": "Quick.CMS",
      "cwe": "CWE-94",
      "title": "Insecure Deserialisation via Plaintext HTTP leading to Remote Code Execution in Quick.CMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11860"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-48887",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ahmad",
      "product": "JS Help Desk",
      "cwe": "CWE-862",
      "title": "WordPress JS Help Desk plugin <= 3.0.9 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48887"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-9260",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canon Inc.",
      "product": "EOS Network Setting Tool for Windows",
      "cwe": "CWE-798",
      "title": "Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9260"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2016-20070",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dwbooster",
      "product": "Booking Calendar Contact Form",
      "cwe": "CWE-79",
      "title": "WordPress Booking Calendar Contact Form 1.0.23 Privilege Escalation Stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20070"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-52699",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e4jvikwp",
      "product": "VikRentCar",
      "cwe": "CWE-639",
      "title": "WordPress VikRentCar plugin <= 1.4.5 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52699"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-39449",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IT Path Solutions",
      "product": "Contact Form to Any API",
      "cwe": "CWE-79",
      "title": "WordPress Contact Form to Any API plugin <= 3.0.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39449"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-39463",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ManageWP",
      "product": "ManageWP Worker",
      "cwe": "CWE-79",
      "title": "WordPress ManageWP Worker plugin <= 4.9.31 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39463"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-48871",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Takashi Kitajima",
      "product": "MW WP Form",
      "cwe": "CWE-79",
      "title": "WordPress MW WP Form plugin <= 5.1.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48871"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-49055",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Glen Don Mongaya",
      "product": "Drag and Drop Multiple File Upload – Contact Form 7",
      "cwe": "CWE-79",
      "title": "WordPress Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.9.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49055"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-39491",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.1401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "artbees",
      "product": "JupiterX Core",
      "cwe": "CWE-79",
      "title": "WordPress JupiterX Core plugin <= 4.14.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39491"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-53704",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10.0 Extended Update Support",
      "cwe": "CWE-125",
      "title": "Gstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demuxer fileinfo metadata parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53704"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-12210",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00228,
      "epss_percentile": 0.13801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "universal-tool-calling-protocol",
      "product": "python-utcp",
      "cwe": "CWE-918",
      "title": "universal-tool-calling-protocol python-utcp utcp-gql/utcp-websocket server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12210"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2019-25746",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13525,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SlicedInvoices",
      "product": "Sliced Invoices",
      "cwe": "CWE-89",
      "title": "WordPress Sliced Invoices 3.8.2 SQL Injection via post Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25746"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-12207",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00226,
      "epss_percentile": 0.13579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "medkey-org",
      "product": "medkey",
      "cwe": "CWE-99",
      "title": "medkey-org medkey HTTP REST API PatientController.php actionGetPatientById resource injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12207"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-45388",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00225,
      "epss_percentile": 0.13394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-295",
      "title": "In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation with certificates that are not meant for server authentication (because of KeyUsage and ExtendedKeyUsage).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45388"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-40775",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Royal Plugins",
      "product": "Royal MCP",
      "cwe": "CWE-862",
      "title": "WordPress Royal MCP plugin <= 1.4.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40775"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-42752",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mra13 / Team Tips and Tricks HQ",
      "product": "Stripe Payments",
      "cwe": "CWE-440",
      "title": "WordPress Stripe Payments plugin <= 2.0.98 - Bypass Vulnerability vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42752"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-42657",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wasiliy Strecker",
      "product": "Contest Gallery",
      "cwe": "CWE-1284",
      "title": "WordPress Contest Gallery plugin <= 28.1.7 - Other Vulnerability Type vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42657"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-25440",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPDeveloper",
      "product": "Essential Addons for Elementor",
      "cwe": "CWE-862",
      "title": "WordPress Essential Addons for Elementor plugin < 6.6.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25440"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-12202",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00214,
      "epss_percentile": 0.12113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Intelliants",
      "product": "Subrion CMS",
      "cwe": "CWE-79",
      "title": "Intelliants Subrion CMS Blocks Endpoint cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12202"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-49063",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.1188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webilia Inc.",
      "product": "Listdom",
      "cwe": "CWE-266",
      "title": "WordPress Listdom plugin <= 5.5.0 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49063"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-40791",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codepeople",
      "product": "WP Time Slots Booking Form",
      "cwe": "CWE-79",
      "title": "WordPress WP Time Slots Booking Form plugin <= 1.2.46 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40791"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-12212",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00207,
      "epss_percentile": 0.11163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hcengineering",
      "product": "Huly Platform",
      "cwe": "CWE-266",
      "title": "hcengineering Huly Platform RPC operations.ts getMailboxSecret access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12212"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-5233",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.1079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MIA Technology Inc.",
      "product": "Pizzy Library",
      "cwe": "CWE-799",
      "title": "Missing Rate Limiting in Mia Technologies' Pizzy Library",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5233"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-39540",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Amit Mittal",
      "product": "Shipment Tracker for Woocommerce",
      "cwe": "CWE-79",
      "title": "WordPress Shipment Tracker for Woocommerce plugin <= 1.5.3.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39540"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-41556",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "properfraction",
      "product": "ProfilePress",
      "cwe": "CWE-79",
      "title": "WordPress ProfilePress plugin <= 4.16.13 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41556"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-42656",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wasiliy Strecker",
      "product": "Contest Gallery",
      "cwe": "CWE-79",
      "title": "WordPress Contest Gallery plugin <= 28.1.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42656"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-48870",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "King Addons",
      "product": "King Addons for Elementor",
      "cwe": "CWE-79",
      "title": "WordPress King Addons for Elementor plugin <= 51.1.62 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48870"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-48880",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ahmad",
      "product": "WP Job Portal",
      "cwe": "CWE-79",
      "title": "WordPress WP Job Portal plugin <= 2.5.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48880"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-12213",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00203,
      "epss_percentile": 0.10624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hcengineering",
      "product": "Huly Platform",
      "cwe": "CWE-266",
      "title": "hcengineering Huly Platform User Information operations.ts getAccountInfo improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12213"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-8683",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-770",
      "title": "Overly long URLs crash the Mattermost Desktop App",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8683"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-34021",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00196,
      "epss_percentile": 0.09696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wertheim GmbH",
      "product": "Wertheim SafeController 5400 Hardware for VAULT ROOMS (Safe Deposit Locker System - Microcontroller)",
      "cwe": "CWE-294",
      "title": "Lack of cryptographic protection in Wertheim SafeController 5400 enables RS-485 message sniffing and replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34021"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2025-64215",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StylemixThemes",
      "product": "MasterStudy LMS Pro",
      "cwe": "CWE-862",
      "title": "WordPress MasterStudy LMS Pro plugin < 4.7.16 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64215"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-12206",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00196,
      "epss_percentile": 0.09744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grit42",
      "product": "Grit",
      "cwe": "CWE-74",
      "title": "Grit42 Grit data_table_entity.rb DataTableEntity sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12206"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-42650",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00195,
      "epss_percentile": 0.09625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ruben Garcia",
      "product": "AutomatorWP",
      "cwe": "CWE-79",
      "title": "WordPress AutomatorWP plugin <= 5.6.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42650"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-9259",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00195,
      "epss_percentile": 0.09552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canon Inc.",
      "product": "EOS Network Setting Tool for Windows",
      "cwe": "CWE-295",
      "title": "Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9259"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2016-20066",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dwbooster",
      "product": "CP Polls",
      "cwe": "CWE-79",
      "title": "WordPress CP Polls 1.0.8 Persistent Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20066"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-45389",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.09095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-295",
      "title": "In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentication), which allows impersonation with certificates that are not meant for client authentication (because of KeyUsage and ExtendedKeyUsage).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45389"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-49775",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "info@welcart",
      "product": "Welcart e-Commerce",
      "cwe": "CWE-862",
      "title": "WordPress Welcart e-Commerce plugin <= 2.11.28 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49775"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-42640",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mamunur Rashid",
      "product": "Classified Listing",
      "cwe": "CWE-862",
      "title": "WordPress Classified Listing plugin <= 5.3.8 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42640"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-6517",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00187,
      "epss_percentile": 0.08613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-522",
      "title": "Mattermost Desktop App fails to restrict the allow list of domains which NTLM credentials are passed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6517"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2025-68851",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArrayHQ",
      "product": "Okay Toolkit",
      "cwe": "CWE-79",
      "title": "WordPress Okay Toolkit plugin <= 2.3 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68851"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-9261",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.0833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canon Inc.",
      "product": "EOS Network Setting Tool for Windows",
      "cwe": "CWE-327",
      "title": "Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9261"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-36521",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36521"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-37216",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37216"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2025-68840",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "markbeljaars",
      "product": "iRobots.txt SEO",
      "cwe": "CWE-79",
      "title": "WordPress iRobots.txt SEO plugin <= 1.1.2 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68840"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2025-68872",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eli",
      "product": "Eli&#039;s WordCents adSense Widget with Analytics",
      "cwe": "CWE-79",
      "title": "WordPress Eli's WordCents adSense Widget with Analytics plugin <= 1.3.03.27 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68872"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-34900",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Liquid Web / StellarWP",
      "product": "GiveWP",
      "cwe": "CWE-79",
      "title": "WordPress GiveWP plugin <= 4.14.2 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34900"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-34902",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WC Product Table",
      "product": "WooCommerce Product Table Lite",
      "cwe": "CWE-79",
      "title": "WordPress WooCommerce Product Table Lite plugin <= 4.6.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34902"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-39435",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bgermann",
      "product": "CformsII",
      "cwe": "CWE-79",
      "title": "WordPress CformsII plugin <= 15.1.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39435"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-39507",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeisle",
      "product": "Social Slider Feed",
      "cwe": "CWE-79",
      "title": "WordPress Social Slider Feed plugin <= 2.3.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39507"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-39514",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cozmoslabs",
      "product": "Paid Member Subscriptions",
      "cwe": "CWE-79",
      "title": "WordPress Paid Member Subscriptions plugin <= 2.17.3 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39514"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-40732",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rainafarai",
      "product": "Notification for Telegram",
      "cwe": "CWE-79",
      "title": "WordPress Notification for Telegram plugin <= 3.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40732"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-40770",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RelyWP",
      "product": "Coupon Affiliates",
      "cwe": "CWE-79",
      "title": "WordPress Coupon Affiliates plugin <= 7.5.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40770"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-40787",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ExpressTech",
      "product": "Quiz And Survey Master",
      "cwe": "CWE-79",
      "title": "WordPress Quiz And Survey Master plugin <= 11.0.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40787"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-42649",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Archetyped",
      "product": "Favicon Rotator",
      "cwe": "CWE-79",
      "title": "WordPress Favicon Rotator plugin <= 1.2.11 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42649"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-42658",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mamunur Rashid",
      "product": "Classified Listing",
      "cwe": "CWE-79",
      "title": "WordPress Classified Listing plugin <= 5.3.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42658"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-42775",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ruben Garcia",
      "product": "AutomatorWP",
      "cwe": "CWE-79",
      "title": "WordPress AutomatorWP plugin <= 5.7.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42775"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-45437",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bhavin Thummar",
      "product": "Product Filter Widget for Elementor",
      "cwe": "CWE-79",
      "title": "WordPress Product Filter Widget for Elementor plugin <= 1.0.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45437"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-48867",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ExpressTech",
      "product": "Quiz And Survey Master",
      "cwe": "CWE-79",
      "title": "WordPress Quiz And Survey Master plugin <= 11.1.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48867"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-48876",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Web Guy",
      "product": "Stop Spammers",
      "cwe": "CWE-79",
      "title": "WordPress Stop Spammers plugin <= 2026.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48876"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-48885",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Groundhogg",
      "product": "HollerBox",
      "cwe": "CWE-79",
      "title": "WordPress HollerBox plugin <= 2.3.10.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48885"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-48966",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FunnelKit",
      "product": "Funnel Builder by FunnelKit",
      "cwe": "CWE-79",
      "title": "WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48966"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-39451",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jgwhite33",
      "product": "WP Google Review Slider",
      "cwe": "CWE-79",
      "title": "WordPress WP Google Review Slider plugin <= 18.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39451"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-5230",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.07236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MIA Technology Inc.",
      "product": "Pizzy Library",
      "cwe": "CWE-284",
      "title": "Improper Access Control in Mia Technologies' Pizzy Library",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5230"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-36933",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code via the factory test feature.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36933"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-48518",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "juice-shop",
      "product": "multi-juicer",
      "cwe": "CWE-352",
      "title": "MultiJuicer: Login CSRF allows attacker to force victims into their team",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48518"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-50892",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the \"Let's Encrypt\" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attackers to obtain the TLS private key material via a crafted GET request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50892"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-8358",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Document Foundation",
      "product": "LibreOffice",
      "cwe": "CWE-787",
      "title": "Heap buffer overflow in spreadsheet tracked-changes import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8358"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2025-70102",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while parsing configuration options. In parse_option() (src/if-options.c:1886), the code performs a member access on a NULL pointer of type 'struct dhcp_opt' when an unexpected/invalid option token or parsing state causes the lookup to yield NULL. The instrumented fuzzing build reports 'runtime error: member access within null pointer of type struct dhcp_opt' and aborts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-70102"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2025-60175",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vynnus",
      "product": "PopAd",
      "cwe": "CWE-918",
      "title": "WordPress PopAd Plugin <= 1.0.4 - Server Side Request Forgery (SSRF) Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60175"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-47777",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00167,
      "epss_percentile": 0.06478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mastodon",
      "product": "mastodon",
      "cwe": "CWE-345",
      "title": "Mastodon has a consent-check bypass in its remote Collections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47777"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-48157",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "slimphp",
      "product": "Slim",
      "cwe": "CWE-79",
      "title": "Slim has Reflected XSS in the HtmlErrorRenderer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48157"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-49773",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.0639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FolioVision",
      "product": "FV Flowplayer Video Player",
      "cwe": "CWE-79",
      "title": "WordPress FV Flowplayer Video Player plugin < 7.5.51.7212 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49773"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2025-56814",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "A code injection vulnerability in the wxExecute() function of OpenCPN v5.12.0 allows attackers to execute arbitrary code via embedding shell metacharacters.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-56814"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-9595",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webpack-dev-server",
      "product": "webpack-dev-server",
      "cwe": "CWE-346",
      "title": "webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9595"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-50876",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "A cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50876"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-42663",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wp.insider",
      "product": "Simple Membership",
      "cwe": "CWE-79",
      "title": "WordPress Simple Membership plugin <= 4.7.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42663"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-9278",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Form Builder CP",
      "cwe": null,
      "title": "Form Builder CP < 1.2.47 - Editor+ Stored XSS via form_structure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9278"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-6039",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Document Foundation",
      "product": "LibreOffice",
      "cwe": "CWE-197",
      "title": "Heap buffer overflow in DXF polyline import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6039"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-8357",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Document Foundation",
      "product": "LibreOffice",
      "cwe": "CWE-193",
      "title": "Heap buffer overflow in Calc formula compilation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8357"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-49043",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.04966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Engine",
      "product": "WP Migrate Lite",
      "cwe": "CWE-352",
      "title": "WordPress WP Migrate Lite plugin <= 2.7.8 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49043"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-49294",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "valhalla",
      "product": "valhalla",
      "cwe": "CWE-79",
      "title": "Valhalla has reflected XSS via unsanitized JSONP callback parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49294"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-12162",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Remote Desktop Manager",
      "cwe": "CWE-297",
      "title": "Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via a crafted web entry pointing to a provider lookalike domain.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12162"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-52702",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.04253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wp-buy",
      "product": "SEO Redirection",
      "cwe": "CWE-79",
      "title": "WordPress SEO Redirection plugin <= 9.17 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52702"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-48124",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00144,
      "epss_percentile": 0.04189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cursor",
      "product": "cursor",
      "cwe": "CWE-94",
      "title": "Cursor Desktop sandbox escape via Claude hook configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48124"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-42743",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeGrill",
      "product": "Masteriyo - LMS",
      "cwe": "CWE-347",
      "title": "WordPress Masteriyo - LMS plugin <= 2.1.8 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42743"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2025-15658",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rewish",
      "product": "WP Emmet",
      "cwe": "CWE-79",
      "title": "WordPress WP Emmet plugin <= 0.3.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15658"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-47825",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Cloud Gateway",
      "cwe": "CWE-346",
      "title": "Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies in certain situations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47825"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2016-20083",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "henrikmelin",
      "product": "More Fields",
      "cwe": "CWE-352",
      "title": "WordPress More Fields Plugin 2.1 Cross-Site Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20083"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-50100",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ricoh Company, Ltd.",
      "product": "Multiple printer drivers",
      "cwe": "CWE-427",
      "title": "Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA JAPAN, INC. contain a privilege escalation vulnerability. If this vulnerability is exploited, an attacker who can log in to a computer running an affected printer driver could elevate privileges by using a specially crafted driver.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50100"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2025-15659",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "liseperu",
      "product": "Elizaibots",
      "cwe": "CWE-79",
      "title": "WordPress Elizaibots plugin <= 1.0.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15659"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-12057",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.0298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit AI",
      "cwe": "CWE-829",
      "title": "DoS + Remote Code Execution via PDF JavaScript in Foxit AI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12057"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-12214",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qihoo",
      "product": "360 Total Security",
      "cwe": "CWE-693",
      "title": "Qihoo 360 Total Security Nucleus Engine Monitoring Logic RpcStringBindingComposeW protection mechanism",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12214"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-11931",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "Kiro IDE",
      "cwe": "CWE-276",
      "title": "Insecure Permissions on Authentication Token Cache File in Kiro IDE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11931"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-34029",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wertheim GmbH",
      "product": "Wertheim SafeController Software for VAULT ROOMS (Safe Deposit Locker System)",
      "cwe": "CWE-321",
      "title": "Hard-coded cryptographic key in Wertheim SafeController Software allows decryption of sensitive configuration data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34029"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-6045",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Document Foundation",
      "product": "LibreOffice",
      "cwe": "CWE-190",
      "title": "Heap buffer overflow in EMF+ gradient brush import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6045"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-6047",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Document Foundation",
      "product": "LibreOffice",
      "cwe": "CWE-787",
      "title": "Heap buffer overflow in OOXML text box element import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6047"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-8356",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Document Foundation",
      "product": "LibreOffice",
      "cwe": "CWE-121",
      "title": "Stack buffer overflow in PPT presentation import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8356"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-39118",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.02018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-269",
      "title": "An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client validation gap to invoke restricted agent functionality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39118"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-34022",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wertheim GmbH",
      "product": "Wertheim SafeController Family 65000 Hardware for VAULT ROOMS (Safe Deposit Locker System - Microcontroller)",
      "cwe": "CWE-321",
      "title": "Weak custom cryptography and hard-coded keys in Wertheim SafeController 65000 allow traffic decryption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34022"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2016-20067",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dwbooster",
      "product": "CP Polls",
      "cwe": "CWE-352",
      "title": "WordPress CP Polls 1.0.8 Cross-Site Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20067"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-5064",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00114,
      "epss_percentile": 0.01712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc.",
      "product": "HP One Agent Software",
      "cwe": "CWE-427",
      "title": "HP One Agent Software – Security Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5064"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-6040",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Document Foundation",
      "product": "LibreOffice",
      "cwe": "CWE-416",
      "title": "Heap use-after-free in ODF number-format blank-width parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6040"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-12216",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00112,
      "epss_percentile": 0.01567,
      "kev": false,
      "kev_due_at": null,
      "vendor": "svaarala",
      "product": "duktape",
      "cwe": "CWE-119",
      "title": "svaarala duktape duk_api_bytecode.c memory corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12216"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-12217",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00111,
      "epss_percentile": 0.01508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DVDFab",
      "product": "Virtual Drive",
      "cwe": "CWE-266",
      "title": "DVDFab Virtual Drive Signed Kernel Driver dvdfabio.sys privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12217"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-52721",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Gstreamer1-plugins-bad-free: gstreamer: multiple out-of-bounds reads in pcapparse ipv4/tcp header parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52721"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2016-20074",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.01279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "leethompson",
      "product": "Lazy Content Slider Plugin",
      "cwe": "CWE-352",
      "title": "WordPress Lazy Content Slider Plugin 3.4 CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20074"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-12201",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00103,
      "epss_percentile": 0.01123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IObit",
      "product": "Malware Fighter",
      "cwe": "CWE-266",
      "title": "IObit Malware Fighter DLL permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12201"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-55641",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-55641. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-55642",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-55642. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-55643",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-55643. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-55644",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-55644. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-55645",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-55645. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-55647",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-55647. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-55648",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-55648. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-55649",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-55649. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-55650",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-55650. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-55652",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-55652. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-55660",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-55660. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-55661",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-55661. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-55663",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-55663. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10634",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10634 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50889",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50889. Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-10520",
      "detail": "DUE DATE PASSED — CVE-2026-10520 (ivanti Sentry). CISA remediation deadline was June 14, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
