{
  "day": "2026-06-27",
  "boundary": "UTC calendar day",
  "published_count": 33,
  "by_severity": {
    "CRITICAL": 1,
    "HIGH": 10,
    "MEDIUM": 22,
    "LOW": 0
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-12415",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00662,
      "epss_percentile": 0.48912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pravel",
      "product": "Invoice Generator",
      "cwe": "CWE-269",
      "title": "Invoice Generator <= 1.0.0 - Unauthenticated Privilege Escalation via Account Takeover via 'user_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12415"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-12432",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00539,
      "epss_percentile": 0.4308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeisle",
      "product": "Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions",
      "cwe": "CWE-862",
      "title": "Stripe Payment Forms by WP Full Pay <= 8.4.3 - Missing Authorization to Unauthenticated Payment Record Manipulation via 'paymentIntentId' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12432"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-8095",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00405,
      "epss_percentile": 0.33903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nmedia",
      "product": "Frontend File Manager Plugin",
      "cwe": "CWE-73",
      "title": "Frontend File Manager Plugin <= 23.6 - Authenticated (Subscriber+) Arbitrary File Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8095"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-11356",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00344,
      "epss_percentile": 0.27494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vinod-dalvi",
      "product": "Ivory Search – WordPress Search Plugin",
      "cwe": "CWE-79",
      "title": "Ivory Search <= 5.5.15 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11356"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-13295",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00342,
      "epss_percentile": 0.27384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gpriday",
      "product": "Page Builder by SiteOrigin",
      "cwe": "CWE-79",
      "title": "Page Builder by SiteOrigin <= 2.34.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via panels_data Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13295"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-13333",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00334,
      "epss_percentile": 0.26379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "trainingbusinesspros",
      "product": "Groundhogg — CRM, Newsletters, and Marketing Automation",
      "cwe": "CWE-89",
      "title": "Groundhogg <= 4.5.5 - Authenticated (Sales Rep+) SQL Injection via 'query[select]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13333"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-13245",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00333,
      "epss_percentile": 0.26326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "maxfoundry",
      "product": "MaxButtons – Create buttons",
      "cwe": "CWE-79",
      "title": "MaxButtons <= 9.8.5 - Reflected Cross-Site Scripting via 'view' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13245"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-12404",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.24214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webaways",
      "product": "NEX-Forms – Ultimate Forms Plugin for WordPress",
      "cwe": "CWE-862",
      "title": "NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via CSVExport Class",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12404"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-3462",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.1983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "reepaydenmark",
      "product": "Frisbii Pay",
      "cwe": "CWE-862",
      "title": "Frisbii Pay <= 1.8.9 - Missing Authorization to Authenticated (Subscriber+) Payment Token Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3462"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-13331",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "trainingbusinesspros",
      "product": "Groundhogg — CRM, Newsletters, and Marketing Automation",
      "cwe": "CWE-89",
      "title": "Groundhogg <= 4.5.5 - Authenticated (Marketer+) SQL Injection via 'search' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13331"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-9233",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "expresstech",
      "product": "Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker",
      "cwe": "CWE-862",
      "title": "Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via qsm_insert_quiz_template AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9233"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-11987",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.1918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dokaninc",
      "product": "Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy",
      "cwe": "CWE-639",
      "title": "Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11987"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-12399",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jegstudio",
      "product": "Gutenverse – WordPress Blocks, Page Builder & Site Editor",
      "cwe": "CWE-79",
      "title": "Gutenverse <= 3.8.0 - Authenticated (Editor+) Stored Cross-Site Scripting via 'fonts[].font.font.value' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12399"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-11783",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dokaninc",
      "product": "Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy",
      "cwe": "CWE-79",
      "title": "Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Custom+) Stored Cross-Site Scripting via Product SKU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11783"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-9242",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "metagauss",
      "product": "RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login",
      "cwe": "CWE-345",
      "title": "RegistrationMagic <= 6.0.8.6 - Authenticated (Subscriber+) Authentication Bypass via Forged PayPal IPN Request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9242"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-10820",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content",
      "cwe": null,
      "title": "ProfilePress < 4.16.17 - Subscriber+ Subscription Cancellation via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10820"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-11364",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dornaweb",
      "product": "Product Specifications for Woocommerce",
      "cwe": "CWE-862",
      "title": "Product Specifications for Woocommerce <= 0.8.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attribute/Group Creation, Modification, and Deletion via 'dwps_modify_groups' and 'dwps_modify_attributes' AJAX Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11364"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-13335",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codepeople",
      "product": "CodePeople Post Map for Google Maps",
      "cwe": "CWE-79",
      "title": "CodePeople Post Map for Google Maps <= 1.2.6 - Authenticated (Contributor +) Stored Cross-Site Scripting via 'cpm_point' Post Meta",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13335"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-12471",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "templatescoderthemes",
      "product": "Spexo",
      "cwe": "CWE-862",
      "title": "Spexo <= 2.0.11 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Activation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12471"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-11597",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surbma",
      "product": "Surbma | Infusionsoft Shortcode",
      "cwe": "CWE-79",
      "title": "Surbma | Infusionsoft Shortcode <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11597"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-13422",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "harmonic_design",
      "product": "HD Quiz",
      "cwe": "CWE-352",
      "title": "HD Quiz 2.2.0 - 2.2.1 - Cross-Site Request Forgery via Multiple AJAX Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13422"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-45258",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-125",
      "title": "Multiple vulnerabilities in the sound(4) mmap path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45258"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-49413",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-266",
      "title": "Flaw in Linuxulator execution of setugid binaries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49413"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-11773",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "masteriyo",
      "product": "Masteriyo LMS – LMS Course Builder, Quizzes & Certificates",
      "cwe": "CWE-862",
      "title": "Masteriyo LMS <= 2.2.1 - Missing Authorization to Authenticated (Student+) Arbitrary Course Announcement Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11773"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-9677",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Shariff for WordPress",
      "cwe": null,
      "title": "Shariff for WordPress <= 1.0.11 - Admin+ Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9677"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-49417",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-416",
      "title": "Multiple vulnerabilities in the sound(4) mmap path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49417"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-10643",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_pktinfo` undersizes the control-buffer capacity check)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10643"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2025-59868",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Traveler for Microsoft Outlook",
      "cwe": "CWE-532",
      "title": "HCL Traveler for Microsoft Outlook (HTMO) is susceptible to sensitive data exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59868"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-49416",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.01292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-190",
      "title": "Integer overflow in vt(4) CONS_HISTORY ioctl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49416"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-49414",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00106,
      "epss_percentile": 0.01278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-179",
      "title": "ASLR bypass for setuid executables via procctl(2)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49414"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-49412",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00104,
      "epss_percentile": 0.01184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-416",
      "title": "Use-after-free bug in the IPV6_MSFILTER socket option handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49412"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2023-37524",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.001,
      "epss_percentile": 0.00967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Traveler for Microsoft Outlook",
      "cwe": "CWE-1104",
      "title": "HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-37524"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-45259",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.00698,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-266",
      "title": "sigqueue(2) missing capability mode restriction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45259"
    }
  ],
  "transactions": [
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2025-67038",
      "detail": "DUE DATE PASSED — CVE-2025-67038 (Lantronix EDS5000). CISA remediation deadline was June 26, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-34908",
      "detail": "DUE DATE PASSED — CVE-2026-34908 (Ubiquiti Inc UniFi OS Server). CISA remediation deadline was June 26, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-34909",
      "detail": "DUE DATE PASSED — CVE-2026-34909 (Ubiquiti Inc UniFi OS Server). CISA remediation deadline was June 26, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-34910",
      "detail": "DUE DATE PASSED — CVE-2026-34910 (Ubiquiti Inc UniFi OS Server). CISA remediation deadline was June 26, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
