boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Saturday, July 11, 2026 · all times UTC← 2026-07-10 · archive · 2026-07-12 →

Security Box Score — July 11, 2026

79 CVEs published, led by MervinPraison (9).

79 CVEs published July 11, 2026: 5 critical, 23 high, 48 medium, 3 low; 0 in the KEV catalog at press time; 2 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 54 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published239814801——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

653 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux38151812186653011120.17.5.0014-57 ▼
google791344149608549387760.47.8.0024-511 ▼
microsoft53810615541896286202.57.8.0046-154 ▼
red hat362581410112617200.06.5.0031-3 ▼
apple01042287228876.76.5.0032-14 ▼
canonical1212685000.05.5.0011+1 ▲
suse61941140000.08.6.0042+6 ▲
freebsd01601240000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ubiquiti2536142110338.38.8.0049+25 ▲
cisco830614100561136.77.5.0057+5 ▲
palo alto networks1425131471328.04.7.0028+5 ▲
netgear01700161000.04.3.0024-17 ▼
checkpoint0915303111.17.5.0410-3 ▼
fortinet09432028333.38.3.0076-2 ▼
ivanti09450025555.68.8.5187-4 ▼
f50843104112.58.9.02250
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache61216418479113310.57.3.0057+5 ▲
mozilla3591218290900.07.3.0025-2 ▼
drupal465165355412.05.9.0026+46 ▲
gitlab73805276425.34.7.0032-4 ▼
github171150000.06.0.0039+1 ▲
docker070520000.08.2.0016-2 ▼
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle02701321161842720.78.8.0040-1 ▼
adobe314713537921932.06.1.0021-120 ▼
ibm21263842460600.07.5.0034-8 ▼
progress101931420600.07.5.0037+5 ▲
solarwinds07232010457.17.5.4001-3 ▼
veeam042200100.09.0.0052-1 ▼
zohocorp031110000.08.4.01700
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology02325133000.05.6.0025-5 ▼
siemens4130760000.07.1.0023-3 ▼
d-link1130535300.06.0.0059-7 ▼
rockwell automation071510000.08.7.00300
abb060420000.07.2.0018-5 ▼
schneider electric060420000.07.8.0042-1 ▼
moxa050320000.07.0.00290
dahua030111000.06.9.0036-3 ▼
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester2899005346000.05.5.0029-7 ▼
dell3389541403211.17.0.0021+26 ▲
capgo1576238351000.07.0.0038+15 ▲
spring073231391000.06.5.0024-68 ▼
openclaw1680362210000.07.0.0021-13 ▼
edimax065039026100.07.4.00800
itsourcecode1063001944000.02.1.0033-12 ▼
themerex26055410000.08.1.0043+2 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-20230.882099.88.6
CVE-2026-34910.874799.710.0
CVE-2026-34908.851999.710.0
CVE-2026-48907.781099.510.0
CVE-2026-45659.760899.58.8
CVE-2026-34909.639099.210.0
CVE-2026-48282.423998.610.0
CVE-2026-12569.405998.59.3
Highest CVSS
CVECVSSEPSSNote
CVE-2026-3491010.0.8747KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.7810KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-4828210.0.4239KEV
CVE-2026-5629010.0.3038KEV
CVE-2026-4893910.0.1973KEV
CVE-2026-4890810.0.1482KEV
CVE-2026-5629110.0.1459KEV
CVE-2026-5972610.0.0688
Most disclosures (vendor)
VendorCVEs
google579
linux456
oracle241
apache126
red hat125
capgo76
ibm67
microsoft67
dell64
themerex60
Most KEV additions (YTD)
VendorKEV
microsoft20
cisco11
apple7
google6
ivanti5
solarwinds4
adobe3
berriai3
fortinet3
smartertools3
Most-affected ecosystems
EcosystemAdvisories
Maven71
npm6
PyPI5
NuGet3
Fastest to KEV
CVEVendorDays
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
CVE-2026-34910Ubiquiti Inc0
CVE-2026-35273Oracle Corporation0
CVE-2026-45659Microsoft0
CVE-2026-48282Adobe0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171697
CVE-2021-27102n/a2021-11-171697
CVE-2021-27101n/a2021-11-171697
CVE-2021-27103n/a2021-11-171697
CVE-2021-21017Adobe2021-11-171697
CVE-2021-28550Adobe2021-11-171697
CVE-2021-42013Apache Software Foundation2021-11-171697
CVE-2021-41773Apache Software Foundation2021-11-171697
CVE-2021-30858Apple2021-11-171697
CVE-2021-30860Apple2021-11-171697

Transactions

EXPLOIT PUBLISHED — CVE-2026-57827 (rsjoomla.com RSFiles extension for Joomla). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-57828 (phoca.cz Phoca Download extension for Joomla). Public exploit reference added.

DUE DATE PASSED — CVE-2026-48282 (Adobe ColdFusion). CISA remediation deadline was July 10, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-48908 (joomshaper.net SP Page Builder extension for Joomla). CISA remediation deadline was July 10, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-55255 (langflow-ai langflow). CISA remediation deadline was July 10, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-56290 (JoomlaCK.fr Page Builder CK extension for Joomla). CISA remediation deadline was July 10, 2026; still in catalog.

Yesterday's Results

How to read these box scores · glossary

79 CVEs published. 25 box scores, 54 table rows — nothing truncated.

xtreeme Planyo online reservation system — Planyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0355   88.4     —
AFFECTED
  Product                           Versions     Fixed
  Planyo online reservation system  unspecified  —
TIMELINE
  Mar 4   Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-20 · CNA: Wordfence · CVSS v3.1 · 12 references · NVD status: Deferred
boldgrid W3 Total Cache — W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0286   85.7     —
AFFECTED
  Product         Versions     Fixed
  W3 Total Cache  unspecified  —
TIMELINE
  May 22  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
MervinPraison PraisonAI — PraisonAI before 1.6.78 Remote Code Execution via CodeAgent
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0249   83.4     —
AFFECTED
  Product    Versions     Fixed
  PraisonAI  unspecified  1.6.78
TIMELINE
  Jul 9   Reserved by CNA
  Jul 11  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
rsjoomla.com rsjoomla.com RSFiles extension for Joomla — Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0233   82.2     —
AFFECTED
  Product                                    Versions       Fixed
  rsjoomla.com RSFiles extension for Joomla  1.0-1.17.11 –  —
TIMELINE
  Jun 25  Reserved by CNA
  Jul 11  Public exploit reference published
  Jul 11  Published (CNA: Joomla)
CWE-434 · CNA: Joomla · CVSS v4.0 · 2 references · NVD status: Modified
smackcoders WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel — WP Ultimate CSV Importer <= 8.0.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'MappedFields' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0111   63.4     —
AFFECTED
  Product                                                                    Versions     Fixed
  WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel  unspecified  —
TIMELINE
  Jun 25  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
wpmessiah Swiss Toolkit For WP — Swiss Toolkit For WP <= 1.4.6 - Authenticated (Author+) Arbitrary File Upload via upload_extension_files()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0100   60.1     —
AFFECTED
  Product               Versions     Fixed
  Swiss Toolkit For WP  unspecified  —
TIMELINE
  Feb 11  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
choijun LA-Studio Element Kit for Elementor — LA-Studio Element Kit for Elementor <= 1.6.1 - Authenticated (Contributor+) Local File Inclusion via 'progress_type' Widget Setting
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0096   58.8     —
AFFECTED
  Product                              Versions     Fixed
  LA-Studio Element Kit for Elementor  unspecified  —
TIMELINE
  Jul 9   Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   R  C  H  H  H    8.3   .0096   58.8     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 11  Published (CNA: microsoft)
CWE-502 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
MervinPraison PraisonAI — PraisonAI before 4.6.78 Arbitrary File Write and Command Execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0088   56.4     —
AFFECTED
  Product    Versions     Fixed
  PraisonAI  unspecified  4.6.78
TIMELINE
  Jul 9   Reserved by CNA
  Jul 11  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
tigroumeow Code Engine – PHP Snippets, AI Functions & Automation for WordPress — Code Engine <= 0.3.5 - Authenticated (Contributor+) Remote Code Execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0085   55.4     —
AFFECTED
  Product                                                              Versions     Fixed
  Code Engine – PHP Snippets, AI Functions & Automation for WordPress  unspecified  —
TIMELINE
  Jun 27  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-77 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
masaakitanaka Booking Package — Booking Package <= 1.7.20 - Unauthenticated SQL Injection via 'email' Form Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0076   52.6     —
AFFECTED
  Product          Versions     Fixed
  Booking Package  unspecified  —
TIMELINE
  Jul 9   Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
nicu_m Simple JWT Login – Allows you to use JWT on REST endpoints. — Simple JWT Login <= 3.6.6 - Authenticated (Subscriber+) Authentication Bypass to Privilege Escalation via 'payload' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0074   52.0     —
AFFECTED
  Product                                                      Versions     Fixed
  Simple JWT Login – Allows you to use JWT on REST endpoints.  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
MervinPraison PraisonAI — PraisonAI before 4.6.78 SQL/CQL Injection via vector dimension
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0070   50.5     —
AFFECTED
  Product    Versions     Fixed
  PraisonAI  unspecified  4.6.78
TIMELINE
  Jul 8   Reserved by CNA
  Jul 11  Published (CNA: VulnCheck)
CWE-89 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Deferred
wpdevteam Essential Addons for Elementor – Popular Elementor Templates & Widgets — Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeover via Email Header Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0067   49.3     —
AFFECTED
  Product                                                                 Versions     Fixed
  Essential Addons for Elementor – Popular Elementor Templates & Widgets  unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-640 · CNA: Wordfence · CVSS v3.1 · 9 references · NVD status: Deferred
ahmadmj Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin — Majestic Support <= 1.1.9 - Authenticated (Subscriber+) SQL Injection via 'val' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0059   45.6     —
AFFECTED
  Product                                                                  Versions     Fixed
  Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin  unspecified  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
wpswings Points and Rewards for WooCommerce — Points and Rewards for WooCommerce <= 2.10.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0058   45.2     —
AFFECTED
  Product                             Versions     Fixed
  Points and Rewards for WooCommerce  unspecified  —
TIMELINE
  Jun 2   Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 12 references · NVD status: Deferred
stylemix Cost Calculator Builder — Cost Calculator Builder <= 4.0.11 - Unauthenticated Sensitive Information Exposure of Payment Gateway Secret Keys
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0058   44.9     —
AFFECTED
  Product                  Versions     Fixed
  Cost Calculator Builder  unspecified  —
TIMELINE
  Jun 4   Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-200 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
corvusinfo CorvusPay WooCommerce Payment Gateway — CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Stored Cross-Site Scripting via 'approval_code' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0056   44.2     —
AFFECTED
  Product                                Versions     Fixed
  CorvusPay WooCommerce Payment Gateway  unspecified  —
TIMELINE
  Apr 23  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 11 references · NVD status: Deferred
wupsales AI Copilot – Content Generator — AI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Modification via 'publishTasks' and 'unpublishTasks' AJAX Actions
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0056   44.1     —
AFFECTED
  Product                         Versions     Fixed
  AI Copilot – Content Generator  unspecified  —
TIMELINE
  Apr 21  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
wclovers WCFM – Frontend Manager for WooCommerce — WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Missing Authorization to Unauthenticated Arbitrary Inquiry Reply Injection via wcfm-my-account-enquiry-manage Controller
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0056   44.1     —
AFFECTED
  Product                                  Versions     Fixed
  WCFM – Frontend Manager for WooCommerce  unspecified  —
TIMELINE
  Jun 23  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 12 references · NVD status: Deferred
phoca.cz phoca.cz Phoca Download extension for Joomla — Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   H   H    9.0   .0054   43.1     —
AFFECTED
  Product                                       Versions     Fixed
  phoca.cz Phoca Download extension for Joomla  1.0-6.1.2 –  —
TIMELINE
  Jun 25  Reserved by CNA
  Jul 11  Public exploit reference published
  Jul 11  Published (CNA: Joomla)
CWE-434 · CNA: Joomla · CVSS v4.0 · 2 references · NVD status: Modified
redefiningtheweb Affiliate Program & Referral Tracking for WooCommerce & WordPress – Affilia — Affilia <= 3.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Status Modification
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0053   42.7     —
AFFECTED
  Product                                                                      Versions     Fixed
  Affiliate Program & Referral Tracking for WooCommerce & WordPress – Affilia  unspecified  —
TIMELINE
  Apr 30  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 12 references · NVD status: Deferred
wupsales AI Copilot – Content Generator — AI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via AJAX Actions 'removeGroup' and 'clear'
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0052   41.6     —
AFFECTED
  Product                         Versions     Fixed
  AI Copilot – Content Generator  unspecified  —
TIMELINE
  Apr 21  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 12 references · NVD status: Deferred
blendmedia WP CTA – Call Now Button, Sticky Button & Call to Action Builder — WP CTA <= 2.2.2 - Unauthenticated Time-Based Blind SQL Injection via 'fildname' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0050   40.8     —
AFFECTED
  Product                                                           Versions     Fixed
  WP CTA – Call Now Button, Sticky Button & Call to Action Builder  unspecified  —
TIMELINE
  Mar 23  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
subratamal Wallet for WooCommerce — Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  L  N  N    4.3   .0049   39.7     —
AFFECTED
  Product                 Versions     Fixed
  Wallet for WooCommerce  unspecified  —
TIMELINE
  Jun 12  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-614268.839.1MervinPraisonPraisonAICWE-200PraisonAI before 1.7.3 Unauthenticated Agent Access via Insecure Defaults
CVE-2026-124265.338.9supercleanseMembers – Membership & User Role Editor PluginCWE-200Members <= 3.2.22 - Unauthenticated Sensitive Information Disclosure via REST…
CVE-2026-90175.338.8webawaysNEX-Forms – Ultimate Forms Plugin for WordPressCWE-862NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Arbitrary Form …
CVE-2026-132505.338.8solacewpSolace ExtraCWE-862Solace Extra <= 1.5.3 - Missing Authorization to Unauthenticated Arbitrary Co…
CVE-2026-76204.338.7rainafaraiNotification for TelegramCWE-862Notification for Telegram <= 3.5.1 - Missing Authorization to Authenticated (…
CVE-2026-150726.538.7iqonicdesignKiviCare – Clinic & Patient Management System (EHR)CWE-89KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Param…
CVE-2026-76558.138.5surecartSureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & PaymentsCWE-640SureCart <= 4.2.3 - Unauthenticated Linked WordPress Account Takeover via For…
CVE-2026-114266.537.9WebFactoryUnder Construction Page (Pro)CWE-22UnderConstructionPage PRO <= 5.76 - Authenticated (Subscriber+) Arbitrary Fil…
CVE-2026-563038.737.8CapgoCapgoCWE-200Capgo - Unauthenticated API Key Metadata Disclosure via SECURITY DEFINER RPC …
CVE-2026-614427.137.7MervinPraisonPraisonAICWE-862PraisonAI Platform before 0.1.9 Authorization Bypass via PATCH
CVE-2026-57436.437.2gallerycreatorSimpLy GalleryCWE-79Mixed Media Gallery Blocks <= 3.3.3.1 - Authenticated (Author+) Stored Cross-…
CVE-2026-13598.836.6genolveGenolve – Genolve AI Business Graphics, AI ImagesCWE-863Genolve – AI image AI video generation <= 5.0.5 - Authenticated (Contributor+…
CVE-2026-137568.836.6WP Grid BuilderWP Grid BuilderCWE-269WP Grid Builder <= 2.3.3 - Authenticated (Subscriber+) Privilege Escalation v…
CVE-2026-100414.336.0wcloversWCFM – Frontend Manager for WooCommerceCWE-639WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Authenticated (Subscriber…
CVE-2026-614398.735.8MervinPraisonPraisonAICWE-1188PraisonAI before 4.6.78 Prompt Injection Defense Bypass
CVE-2026-131147.235.5stylemixMotors – Car Dealership & Classified Listings PluginCWE-79Motors <= 1.4.112 - Unauthenticated Stored Cross-Site Scripting via Comment C…
CVE-2025-50174.935.4catalyst2020Catalyst Connect Zoho CRM Client PortalCWE-89Catalyst Connect Zoho CRM Client Portal <= 2.2.0 - Authenticated (Administrat…
CVE-2026-614482.134.2parse-communityparse-serverCWE-434Parse Server 9.0.0 Stored XSS via malformed Content-Type
CVE-2026-150736.534.1iqonicdesignKiviCare – Clinic & Patient Management System (EHR)CWE-89KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Param…
CVE-2026-33674.434.0lustmoredLockme calendars integrationCWE-79Lockme OAuth2 calendars integration <= 2.11.0 - Authenticated (Administrator+…
CVE-2026-75444.334.02codersMux Video UploaderCWE-200Mux Video Uploader <= 1.1.4 - Authenticated (Subscriber+) Information Exposure
CVE-2026-133787.233.4wpvibesForm Vibes – Save Contact Form 7 & Elementor Form Entries to DatabaseCWE-79Form Vibes <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting via Contact…
CVE-2026-86784.333.2richardperdaanMyParcelCWE-862MyParcel <= 4.25.1 - Missing Authorization to Authenticated (Subscriber+) Arb…
CVE-2026-115914.432.5trustindexWidgets for Google ReviewsCWE-79Widgets for Google Reviews <= 13.3 - Authenticated (Editor+) Stored Cross-Sit…
CVE-2026-118984.432.5videousermanualsWhite Label CMSCWE-79White Label CMS <= 2.7.12 - Authenticated (Administrator+) Stored Cross-Site …
CVE-2026-131164.331.5wpovernightPDF Invoices & Packing Slips for WooCommerceCWE-639PDF Invoices & Packing Slips for WooCommerce <= 5.14.0 - Insecure Direct Obje…
CVE-2026-614286.930.0MervinPraisonPraisonAICWE-290PraisonAI AgentMail before 4.6.78 Message Injection via Webhook
CVE-2026-35524.329.8surflabtechSurfLink – Link Manager & Backup RestoreCWE-862SurfLink < 2.6.0 - Missing Authorization to Authenticated (Subscriber+) 410 G…
CVE-2026-127384.329.3saadiqbalWP Easy Pay – Payment and Donation form Builder for SquareCWE-862WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) A…
CVE-2026-614548.728.5getgravgravCWE-200Grav before 2.0.4 Information Disclosure via __GRAV_CONFIG__
CVE-2026-562966.928.5Cap-gocapgoCWE-203Cap-go - App Existence Oracle via Unauthenticated transfer_app RPC
CVE-2026-68015.328.5postmagthemesContext BlogCWE-200Context Blog <= 1.3.5 - Unauthenticated Sensitive Information Exposure via 'p…
CVE-2026-121266.428.4wcloversWCFM Marketplace – Multivendor Marketplace for WooCommerceCWE-79WCFM Marketplace <= 3.7.3 - Authenticated (Vendor+) Stored Cross-Site Scripti…
CVE-2026-18324.328.0thrivedeskAgentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDeskCWE-862ThriveDesk <= 2.1.7 - Missing Authorization to Authenticated (Subscriber+) Ca…
CVE-2025-139686.427.5starboardsuiteStarboard Suite Reservation CalendarsCWE-79Starboard Suite Reservation Calendars <= 3.1.4 - Authenticated (Contributor+)…
CVE-2026-150976.427.5themifymeThemify BuilderCWE-79Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scr…
CVE-2026-614298.427.4MervinPraisonPraisonAICWE-918PraisonAI before 1.6.78 SSRF via Crawl4AI Chromium backend
CVE-2026-154702.127.4EleveoCall Recording SoftwareCWE-266Eleveo Call Recording Software group.jsp improper authorization
CVE-2026-97384.425.9printfriendlyPrint, PDF & Email by PrintFriendlyCWE-79Print, PDF, Email by PrintFriendly <= 5.5.10 - Authenticated (Administrator+)…
CVE-2026-13826.425.5freshlabsfresh PodcasterCWE-79fresh Podcaster <= 1.0.7 - Authenticated (Contributor+) Stored Cross-Site Scr…
CVE-2026-150106.425.5robin-wbbp style packCWE-79bbp style pack <= 6.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scrip…
CVE-2026-150966.425.5themifymeThemify BuilderCWE-79Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scr…
CVE-2026-618616.324.6ImageMagickImageMagickCWE-416ImageMagick before 7.1.2-26 Use-After-Free in FormatMagickCaption
CVE-2026-562405.322.5CapgoCapgoCWE-285Capgo - Billing Authorization Bypass via Exhausted Usage Credits
CVE-2026-121414.920.9leap13Premium Addons for Elementor – Powerful Elementor Templates & WidgetsCWE-79Premium Addons for Elementor <= 4.11.84 - Authenticated (Contributor+) Stored…
CVE-2026-567636.319.1HonoHonoCWE-1321Hono - Prototype Pollution via __proto__ Key in parseBody with dot Option
CVE-2026-618576.318.0ImageMagickImageMagickCWE-252ImageMagick before 7.1.2-26 Heap Use-After-Free via XMP
CVE-2026-119015.317.2thimpressWP Hotel BookingCWE-345WP Hotel Booking <= 2.3.1 - Unauthenticated Insufficient Verification of Data…
CVE-2026-106606.415.6zephyrprojectzephyrCWE-787Shared reassembly buffer in Bluetooth BAP Broadcast Assistant enables cross-c…
CVE-2026-618584.815.7ImageMagickImageMagickCWE-59ImageMagick before 7.1.2-26 Policy Bypass via APNG encoder
CVE-2026-563724.89.6ImageMagickImageMagickCWE-122ImageMagick - Heap Buffer Overflow Read via Unrecognized Magnify Method
CVE-2026-618702.18.8ImageMagickImageMagickCWE-401ImageMagick before 7.1.2-26 Memory Leak via VIFF Encoder
CVE-2026-600886.87.8MervinPraisonPraisonAICWE-22PraisonAI before 4.6.78 Path Traversal via Custom Commands
CVE-2026-614654.86.7ImageMagickImageMagickCWE-770ImageMagick before 7.1.2-26 Memory Allocation Policy Bypass

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-11 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.