AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0355 88.4 —
AFFECTED Product Versions Fixed Planyo online reservation system unspecified —
TIMELINE Mar 4 Reserved by CNA Jul 11 Published (CNA: Wordfence)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
79 CVEs published, led by MervinPraison (9).
79 CVEs published July 11, 2026: 5 critical, 23 high, 48 medium, 3 low; 0 in the KEV catalog at press time; 2 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 54 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 2398 | 14801 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
653 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 38 | 1518 | 121 | 866 | 530 | 1 | 11 | 2 | 0.1 | 7.5 | .0014 | -57 ▼ |
| 79 | 1344 | 149 | 608 | 549 | 38 | 77 | 6 | 0.4 | 7.8 | .0024 | -511 ▼ | |
| microsoft | 53 | 810 | 61 | 554 | 189 | 6 | 286 | 20 | 2.5 | 7.8 | .0046 | -154 ▼ |
| red hat | 36 | 258 | 14 | 101 | 126 | 17 | 2 | 0 | 0.0 | 6.5 | .0031 | -3 ▼ |
| apple | 0 | 104 | 2 | 28 | 72 | 2 | 88 | 7 | 6.7 | 6.5 | .0032 | -14 ▼ |
| canonical | 1 | 21 | 2 | 6 | 8 | 5 | 0 | 0 | 0.0 | 5.5 | .0011 | +1 ▲ |
| suse | 6 | 19 | 4 | 11 | 4 | 0 | 0 | 0 | 0.0 | 8.6 | .0042 | +6 ▲ |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 3 | 3 | 8.3 | 8.8 | .0049 | +25 ▲ |
| cisco | 8 | 30 | 6 | 14 | 10 | 0 | 56 | 11 | 36.7 | 7.5 | .0057 | +5 ▲ |
| palo alto networks | 14 | 25 | 1 | 3 | 14 | 7 | 13 | 2 | 8.0 | 4.7 | .0028 | +5 ▲ |
| netgear | 0 | 17 | 0 | 0 | 16 | 1 | 0 | 0 | 0.0 | 4.3 | .0024 | -17 ▼ |
| checkpoint | 0 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | -3 ▼ |
| fortinet | 0 | 9 | 4 | 3 | 2 | 0 | 28 | 3 | 33.3 | 8.3 | .0076 | -2 ▼ |
| ivanti | 0 | 9 | 4 | 5 | 0 | 0 | 25 | 5 | 55.6 | 8.8 | .5187 | -4 ▼ |
| f5 | 0 | 8 | 4 | 3 | 1 | 0 | 4 | 1 | 12.5 | 8.9 | .0225 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 61 | 216 | 41 | 84 | 79 | 11 | 33 | 1 | 0.5 | 7.3 | .0057 | +5 ▲ |
| mozilla | 3 | 59 | 12 | 18 | 29 | 0 | 9 | 0 | 0.0 | 7.3 | .0025 | -2 ▼ |
| drupal | 46 | 51 | 6 | 5 | 35 | 5 | 4 | 1 | 2.0 | 5.9 | .0026 | +46 ▲ |
| gitlab | 7 | 38 | 0 | 5 | 27 | 6 | 4 | 2 | 5.3 | 4.7 | .0032 | -4 ▼ |
| github | 1 | 7 | 1 | 1 | 5 | 0 | 0 | 0 | 0.0 | 6.0 | .0039 | +1 ▲ |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.2 | .0016 | -2 ▼ |
| wordpress | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 270 | 132 | 116 | 18 | 4 | 27 | 2 | 0.7 | 8.8 | .0040 | -1 ▼ |
| adobe | 3 | 147 | 13 | 53 | 79 | 2 | 19 | 3 | 2.0 | 6.1 | .0021 | -120 ▼ |
| ibm | 2 | 126 | 38 | 42 | 46 | 0 | 6 | 0 | 0.0 | 7.5 | .0034 | -8 ▼ |
| progress | 10 | 19 | 3 | 14 | 2 | 0 | 6 | 0 | 0.0 | 7.5 | .0037 | +5 ▲ |
| solarwinds | 0 | 7 | 2 | 3 | 2 | 0 | 10 | 4 | 57.1 | 7.5 | .4001 | -3 ▼ |
| veeam | 0 | 4 | 2 | 2 | 0 | 0 | 1 | 0 | 0.0 | 9.0 | .0052 | -1 ▼ |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -5 ▼ |
| siemens | 4 | 13 | 0 | 7 | 6 | 0 | 0 | 0 | 0.0 | 7.1 | .0023 | -3 ▼ |
| d-link | 1 | 13 | 0 | 5 | 3 | 5 | 3 | 0 | 0.0 | 6.0 | .0059 | -7 ▼ |
| rockwell automation | 0 | 7 | 1 | 5 | 1 | 0 | 0 | 0 | 0.0 | 8.7 | .0030 | 0 |
| abb | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -5 ▼ |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0042 | -1 ▼ |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | 0 |
| dahua | 0 | 3 | 0 | 1 | 1 | 1 | 0 | 0 | 0.0 | 6.9 | .0036 | -3 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 28 | 99 | 0 | 0 | 53 | 46 | 0 | 0 | 0.0 | 5.5 | .0029 | -7 ▼ |
| dell | 33 | 89 | 5 | 41 | 40 | 3 | 2 | 1 | 1.1 | 7.0 | .0021 | +26 ▲ |
| capgo | 15 | 76 | 2 | 38 | 35 | 1 | 0 | 0 | 0.0 | 7.0 | .0038 | +15 ▲ |
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -68 ▼ |
| openclaw | 1 | 68 | 0 | 36 | 22 | 10 | 0 | 0 | 0.0 | 7.0 | .0021 | -13 ▼ |
| edimax | 0 | 65 | 0 | 39 | 0 | 26 | 1 | 0 | 0.0 | 7.4 | .0080 | 0 |
| itsourcecode | 10 | 63 | 0 | 0 | 19 | 44 | 0 | 0 | 0.0 | 2.1 | .0033 | -12 ▼ |
| themerex | 2 | 60 | 5 | 54 | 1 | 0 | 0 | 0 | 0.0 | 8.1 | .0043 | +2 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-20230 | .8820 | 99.8 | 8.6 |
| CVE-2026-34910 | .8747 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-48907 | .7810 | 99.5 | 10.0 |
| CVE-2026-45659 | .7608 | 99.5 | 8.8 |
| CVE-2026-34909 | .6390 | 99.2 | 10.0 |
| CVE-2026-48282 | .4239 | 98.6 | 10.0 |
| CVE-2026-12569 | .4059 | 98.5 | 9.3 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-34910 | 10.0 | .8747 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-48907 | 10.0 | .7810 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-48282 | 10.0 | .4239 | KEV |
| CVE-2026-56290 | 10.0 | .3038 | KEV |
| CVE-2026-48939 | 10.0 | .1973 | KEV |
| CVE-2026-48908 | 10.0 | .1482 | KEV |
| CVE-2026-56291 | 10.0 | .1459 | KEV |
| CVE-2026-59726 | 10.0 | .0688 |
| Vendor | CVEs |
|---|---|
| 579 | |
| linux | 456 |
| oracle | 241 |
| apache | 126 |
| red hat | 125 |
| capgo | 76 |
| ibm | 67 |
| microsoft | 67 |
| dell | 64 |
| themerex | 60 |
| Vendor | KEV |
|---|---|
| microsoft | 20 |
| cisco | 11 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| fortinet | 3 |
| smartertools | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 71 |
| npm | 6 |
| PyPI | 5 |
| NuGet | 3 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE-2026-20262 | Cisco | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE-2026-34909 | Ubiquiti Inc | 0 |
| CVE-2026-34910 | Ubiquiti Inc | 0 |
| CVE-2026-35273 | Oracle Corporation | 0 |
| CVE-2026-45659 | Microsoft | 0 |
| CVE-2026-48282 | Adobe | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1697 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1697 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1697 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1697 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1697 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1697 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1697 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1697 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1697 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1697 |
EXPLOIT PUBLISHED — CVE-2026-57827 (rsjoomla.com RSFiles extension for Joomla). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-57828 (phoca.cz Phoca Download extension for Joomla). Public exploit reference added.
DUE DATE PASSED — CVE-2026-48282 (Adobe ColdFusion). CISA remediation deadline was July 10, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-48908 (joomshaper.net SP Page Builder extension for Joomla). CISA remediation deadline was July 10, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-55255 (langflow-ai langflow). CISA remediation deadline was July 10, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-56290 (JoomlaCK.fr Page Builder CK extension for Joomla). CISA remediation deadline was July 10, 2026; still in catalog.
How to read these box scores · glossary
79 CVEs published. 25 box scores, 54 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0355 88.4 —
AFFECTED Product Versions Fixed Planyo online reservation system unspecified —
TIMELINE Mar 4 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0286 85.7 —
AFFECTED Product Versions Fixed W3 Total Cache unspecified —
TIMELINE May 22 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0249 83.4 —
AFFECTED Product Versions Fixed PraisonAI unspecified 1.6.78
TIMELINE Jul 9 Reserved by CNA Jul 11 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0233 82.2 —
AFFECTED Product Versions Fixed rsjoomla.com RSFiles extension for Joomla 1.0-1.17.11 – —
TIMELINE Jun 25 Reserved by CNA Jul 11 Public exploit reference published Jul 11 Published (CNA: Joomla)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0111 63.4 —
AFFECTED Product Versions Fixed WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel unspecified —
TIMELINE Jun 25 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0100 60.1 —
AFFECTED Product Versions Fixed Swiss Toolkit For WP unspecified —
TIMELINE Feb 11 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H H H 7.5 .0096 58.8 —
AFFECTED Product Versions Fixed LA-Studio Element Kit for Elementor unspecified —
TIMELINE Jul 9 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N R C H H H 8.3 .0096 58.8 —
AFFECTED Product Versions Fixed Microsoft Edge (Chromium-based) 1.0.0.0 – —
TIMELINE Jun 29 Reserved by CNA Jul 11 Published (CNA: microsoft)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 9.4 .0088 56.4 —
AFFECTED Product Versions Fixed PraisonAI unspecified 4.6.78
TIMELINE Jul 9 Reserved by CNA Jul 11 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0085 55.4 —
AFFECTED Product Versions Fixed Code Engine – PHP Snippets, AI Functions & Automation for WordPress unspecified —
TIMELINE Jun 27 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0076 52.6 —
AFFECTED Product Versions Fixed Booking Package unspecified —
TIMELINE Jul 9 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0074 52.0 —
AFFECTED Product Versions Fixed Simple JWT Login – Allows you to use JWT on REST endpoints. unspecified —
TIMELINE Jun 30 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0070 50.5 —
AFFECTED Product Versions Fixed PraisonAI unspecified 4.6.78
TIMELINE Jul 8 Reserved by CNA Jul 11 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0067 49.3 —
AFFECTED Product Versions Fixed Essential Addons for Elementor – Popular Elementor Templates & Widgets unspecified —
TIMELINE Jul 8 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0059 45.6 —
AFFECTED Product Versions Fixed Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin unspecified —
TIMELINE Jun 24 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N L N 4.3 .0058 45.2 —
AFFECTED Product Versions Fixed Points and Rewards for WooCommerce unspecified —
TIMELINE Jun 2 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L N N 5.3 .0058 44.9 —
AFFECTED Product Versions Fixed Cost Calculator Builder unspecified —
TIMELINE Jun 4 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0056 44.2 —
AFFECTED Product Versions Fixed CorvusPay WooCommerce Payment Gateway unspecified —
TIMELINE Apr 23 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N L N 5.3 .0056 44.1 —
AFFECTED Product Versions Fixed AI Copilot – Content Generator unspecified —
TIMELINE Apr 21 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N L N 5.3 .0056 44.1 —
AFFECTED Product Versions Fixed WCFM – Frontend Manager for WooCommerce unspecified —
TIMELINE Jun 23 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P L N H H H 9.0 .0054 43.1 —
AFFECTED Product Versions Fixed phoca.cz Phoca Download extension for Joomla 1.0-6.1.2 – —
TIMELINE Jun 25 Reserved by CNA Jul 11 Public exploit reference published Jul 11 Published (CNA: Joomla)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N L N 4.3 .0053 42.7 —
AFFECTED Product Versions Fixed Affiliate Program & Referral Tracking for WooCommerce & WordPress – Affilia unspecified —
TIMELINE Apr 30 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N L N 5.3 .0052 41.6 —
AFFECTED Product Versions Fixed AI Copilot – Content Generator unspecified —
TIMELINE Apr 21 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0050 40.8 —
AFFECTED Product Versions Fixed WP CTA – Call Now Button, Sticky Button & Call to Action Builder unspecified —
TIMELINE Mar 23 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U L N N 4.3 .0049 39.7 —
AFFECTED Product Versions Fixed Wallet for WooCommerce unspecified —
TIMELINE Jun 12 Reserved by CNA Jul 11 Published (CNA: Wordfence)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-61426 | 8.8 | 39.1 | MervinPraison | PraisonAI | CWE-200 | PraisonAI before 1.7.3 Unauthenticated Agent Access via Insecure Defaults |
| CVE-2026-12426 | 5.3 | 38.9 | supercleanse | Members – Membership & User Role Editor Plugin | CWE-200 | Members <= 3.2.22 - Unauthenticated Sensitive Information Disclosure via REST… |
| CVE-2026-9017 | 5.3 | 38.8 | webaways | NEX-Forms – Ultimate Forms Plugin for WordPress | CWE-862 | NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Arbitrary Form … |
| CVE-2026-13250 | 5.3 | 38.8 | solacewp | Solace Extra | CWE-862 | Solace Extra <= 1.5.3 - Missing Authorization to Unauthenticated Arbitrary Co… |
| CVE-2026-7620 | 4.3 | 38.7 | rainafarai | Notification for Telegram | CWE-862 | Notification for Telegram <= 3.5.1 - Missing Authorization to Authenticated (… |
| CVE-2026-15072 | 6.5 | 38.7 | iqonicdesign | KiviCare – Clinic & Patient Management System (EHR) | CWE-89 | KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Param… |
| CVE-2026-7655 | 8.1 | 38.5 | surecart | SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments | CWE-640 | SureCart <= 4.2.3 - Unauthenticated Linked WordPress Account Takeover via For… |
| CVE-2026-11426 | 6.5 | 37.9 | WebFactory | Under Construction Page (Pro) | CWE-22 | UnderConstructionPage PRO <= 5.76 - Authenticated (Subscriber+) Arbitrary Fil… |
| CVE-2026-56303 | 8.7 | 37.8 | Capgo | Capgo | CWE-200 | Capgo - Unauthenticated API Key Metadata Disclosure via SECURITY DEFINER RPC … |
| CVE-2026-61442 | 7.1 | 37.7 | MervinPraison | PraisonAI | CWE-862 | PraisonAI Platform before 0.1.9 Authorization Bypass via PATCH |
| CVE-2026-5743 | 6.4 | 37.2 | gallerycreator | SimpLy Gallery | CWE-79 | Mixed Media Gallery Blocks <= 3.3.3.1 - Authenticated (Author+) Stored Cross-… |
| CVE-2026-1359 | 8.8 | 36.6 | genolve | Genolve – Genolve AI Business Graphics, AI Images | CWE-863 | Genolve – AI image AI video generation <= 5.0.5 - Authenticated (Contributor+… |
| CVE-2026-13756 | 8.8 | 36.6 | WP Grid Builder | WP Grid Builder | CWE-269 | WP Grid Builder <= 2.3.3 - Authenticated (Subscriber+) Privilege Escalation v… |
| CVE-2026-10041 | 4.3 | 36.0 | wclovers | WCFM – Frontend Manager for WooCommerce | CWE-639 | WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Authenticated (Subscriber… |
| CVE-2026-61439 | 8.7 | 35.8 | MervinPraison | PraisonAI | CWE-1188 | PraisonAI before 4.6.78 Prompt Injection Defense Bypass |
| CVE-2026-13114 | 7.2 | 35.5 | stylemix | Motors – Car Dealership & Classified Listings Plugin | CWE-79 | Motors <= 1.4.112 - Unauthenticated Stored Cross-Site Scripting via Comment C… |
| CVE-2025-5017 | 4.9 | 35.4 | catalyst2020 | Catalyst Connect Zoho CRM Client Portal | CWE-89 | Catalyst Connect Zoho CRM Client Portal <= 2.2.0 - Authenticated (Administrat… |
| CVE-2026-61448 | 2.1 | 34.2 | parse-community | parse-server | CWE-434 | Parse Server 9.0.0 Stored XSS via malformed Content-Type |
| CVE-2026-15073 | 6.5 | 34.1 | iqonicdesign | KiviCare – Clinic & Patient Management System (EHR) | CWE-89 | KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Param… |
| CVE-2026-3367 | 4.4 | 34.0 | lustmored | Lockme calendars integration | CWE-79 | Lockme OAuth2 calendars integration <= 2.11.0 - Authenticated (Administrator+… |
| CVE-2026-7544 | 4.3 | 34.0 | 2coders | Mux Video Uploader | CWE-200 | Mux Video Uploader <= 1.1.4 - Authenticated (Subscriber+) Information Exposure |
| CVE-2026-13378 | 7.2 | 33.4 | wpvibes | Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database | CWE-79 | Form Vibes <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting via Contact… |
| CVE-2026-8678 | 4.3 | 33.2 | richardperdaan | MyParcel | CWE-862 | MyParcel <= 4.25.1 - Missing Authorization to Authenticated (Subscriber+) Arb… |
| CVE-2026-11591 | 4.4 | 32.5 | trustindex | Widgets for Google Reviews | CWE-79 | Widgets for Google Reviews <= 13.3 - Authenticated (Editor+) Stored Cross-Sit… |
| CVE-2026-11898 | 4.4 | 32.5 | videousermanuals | White Label CMS | CWE-79 | White Label CMS <= 2.7.12 - Authenticated (Administrator+) Stored Cross-Site … |
| CVE-2026-13116 | 4.3 | 31.5 | wpovernight | PDF Invoices & Packing Slips for WooCommerce | CWE-639 | PDF Invoices & Packing Slips for WooCommerce <= 5.14.0 - Insecure Direct Obje… |
| CVE-2026-61428 | 6.9 | 30.0 | MervinPraison | PraisonAI | CWE-290 | PraisonAI AgentMail before 4.6.78 Message Injection via Webhook |
| CVE-2026-3552 | 4.3 | 29.8 | surflabtech | SurfLink – Link Manager & Backup Restore | CWE-862 | SurfLink < 2.6.0 - Missing Authorization to Authenticated (Subscriber+) 410 G… |
| CVE-2026-12738 | 4.3 | 29.3 | saadiqbal | WP Easy Pay – Payment and Donation form Builder for Square | CWE-862 | WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) A… |
| CVE-2026-61454 | 8.7 | 28.5 | getgrav | grav | CWE-200 | Grav before 2.0.4 Information Disclosure via __GRAV_CONFIG__ |
| CVE-2026-56296 | 6.9 | 28.5 | Cap-go | capgo | CWE-203 | Cap-go - App Existence Oracle via Unauthenticated transfer_app RPC |
| CVE-2026-6801 | 5.3 | 28.5 | postmagthemes | Context Blog | CWE-200 | Context Blog <= 1.3.5 - Unauthenticated Sensitive Information Exposure via 'p… |
| CVE-2026-12126 | 6.4 | 28.4 | wclovers | WCFM Marketplace – Multivendor Marketplace for WooCommerce | CWE-79 | WCFM Marketplace <= 3.7.3 - Authenticated (Vendor+) Stored Cross-Site Scripti… |
| CVE-2026-1832 | 4.3 | 28.0 | thrivedesk | Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk | CWE-862 | ThriveDesk <= 2.1.7 - Missing Authorization to Authenticated (Subscriber+) Ca… |
| CVE-2025-13968 | 6.4 | 27.5 | starboardsuite | Starboard Suite Reservation Calendars | CWE-79 | Starboard Suite Reservation Calendars <= 3.1.4 - Authenticated (Contributor+)… |
| CVE-2026-15097 | 6.4 | 27.5 | themifyme | Themify Builder | CWE-79 | Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scr… |
| CVE-2026-61429 | 8.4 | 27.4 | MervinPraison | PraisonAI | CWE-918 | PraisonAI before 1.6.78 SSRF via Crawl4AI Chromium backend |
| CVE-2026-15470 | 2.1 | 27.4 | Eleveo | Call Recording Software | CWE-266 | Eleveo Call Recording Software group.jsp improper authorization |
| CVE-2026-9738 | 4.4 | 25.9 | printfriendly | Print, PDF & Email by PrintFriendly | CWE-79 | Print, PDF, Email by PrintFriendly <= 5.5.10 - Authenticated (Administrator+)… |
| CVE-2026-1382 | 6.4 | 25.5 | freshlabs | fresh Podcaster | CWE-79 | fresh Podcaster <= 1.0.7 - Authenticated (Contributor+) Stored Cross-Site Scr… |
| CVE-2026-15010 | 6.4 | 25.5 | robin-w | bbp style pack | CWE-79 | bbp style pack <= 6.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scrip… |
| CVE-2026-15096 | 6.4 | 25.5 | themifyme | Themify Builder | CWE-79 | Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scr… |
| CVE-2026-61861 | 6.3 | 24.6 | ImageMagick | ImageMagick | CWE-416 | ImageMagick before 7.1.2-26 Use-After-Free in FormatMagickCaption |
| CVE-2026-56240 | 5.3 | 22.5 | Capgo | Capgo | CWE-285 | Capgo - Billing Authorization Bypass via Exhausted Usage Credits |
| CVE-2026-12141 | 4.9 | 20.9 | leap13 | Premium Addons for Elementor – Powerful Elementor Templates & Widgets | CWE-79 | Premium Addons for Elementor <= 4.11.84 - Authenticated (Contributor+) Stored… |
| CVE-2026-56763 | 6.3 | 19.1 | Hono | Hono | CWE-1321 | Hono - Prototype Pollution via __proto__ Key in parseBody with dot Option |
| CVE-2026-61857 | 6.3 | 18.0 | ImageMagick | ImageMagick | CWE-252 | ImageMagick before 7.1.2-26 Heap Use-After-Free via XMP |
| CVE-2026-11901 | 5.3 | 17.2 | thimpress | WP Hotel Booking | CWE-345 | WP Hotel Booking <= 2.3.1 - Unauthenticated Insufficient Verification of Data… |
| CVE-2026-10660 | 6.4 | 15.6 | zephyrproject | zephyr | CWE-787 | Shared reassembly buffer in Bluetooth BAP Broadcast Assistant enables cross-c… |
| CVE-2026-61858 | 4.8 | 15.7 | ImageMagick | ImageMagick | CWE-59 | ImageMagick before 7.1.2-26 Policy Bypass via APNG encoder |
| CVE-2026-56372 | 4.8 | 9.6 | ImageMagick | ImageMagick | CWE-122 | ImageMagick - Heap Buffer Overflow Read via Unrecognized Magnify Method |
| CVE-2026-61870 | 2.1 | 8.8 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-26 Memory Leak via VIFF Encoder |
| CVE-2026-60088 | 6.8 | 7.8 | MervinPraison | PraisonAI | CWE-22 | PraisonAI before 4.6.78 Path Traversal via Custom Commands |
| CVE-2026-61465 | 4.8 | 6.7 | ImageMagick | ImageMagick | CWE-770 | ImageMagick before 7.1.2-26 Memory Allocation Policy Bypass |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-11 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.