AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0277 85.2 —
AFFECTED Product Versions Fixed W3 Total Cache unspecified —
TIMELINE May 22 Reserved by CNA Jul 11 Published (CNA: Wordfence)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
79 CVEs published, led by MervinPraison (9).
79 CVEs published July 11, 2026: 5 critical, 23 high, 48 medium, 3 low; 0 in the KEV catalog at press time; 1 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 54 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 2398 | 14781 | 1296 | 2564 |
| KEV catalog size | 1671 | |||
651 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 38 | 1520 | 121 | 866 | 528 | 1 | 27 | 3 | 0.2 | 7.5 | .0013 | -58 ▼ |
| 79 | 1343 | 149 | 604 | 549 | 38 | 74 | 6 | 0.4 | 7.8 | .0023 | -511 ▼ | |
| microsoft | 53 | 819 | 61 | 554 | 189 | 6 | 380 | 28 | 3.4 | 7.8 | .0045 | -154 ▼ |
| red hat | 36 | 228 | 14 | 92 | 110 | 12 | 4 | 0 | 0.0 | 6.5 | .0026 | -3 ▼ |
| apple | 0 | 99 | 1 | 23 | 66 | 2 | 94 | 7 | 7.1 | 6.5 | .0031 | -14 ▼ |
| canonical | 1 | 21 | 2 | 6 | 8 | 5 | 0 | 0 | 0.0 | 5.5 | .0011 | +1 ▲ |
| suse | 6 | 19 | 4 | 11 | 4 | 0 | 0 | 0 | 0.0 | 8.6 | .0036 | +6 ▲ |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0015 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 4 | 3 | 8.3 | 8.8 | .0036 | +25 ▲ |
| cisco | 8 | 31 | 4 | 12 | 8 | 0 | 96 | 11 | 35.5 | 7.5 | .0056 | +5 ▲ |
| palo alto networks | 14 | 25 | 0 | 2 | 14 | 7 | 14 | 2 | 8.0 | 4.7 | .0021 | +5 ▲ |
| netgear | 0 | 17 | 0 | 0 | 16 | 1 | 8 | 0 | 0.0 | 4.3 | .0024 | -17 ▼ |
| checkpoint | 0 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | -3 ▼ |
| f5 | 0 | 9 | 4 | 3 | 1 | 0 | 7 | 1 | 11.1 | 8.9 | .0221 | 0 |
| ivanti | 0 | 9 | 2 | 3 | 0 | 0 | 33 | 5 | 55.6 | 8.8 | .5187 | -4 ▼ |
| fortinet | 0 | 8 | 1 | 3 | 2 | 0 | 28 | 3 | 37.5 | 7.3 | .0066 | -2 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 61 | 214 | 41 | 84 | 77 | 11 | 40 | 1 | 0.5 | 7.3 | .0048 | +5 ▲ |
| mozilla | 3 | 59 | 12 | 18 | 29 | 0 | 13 | 0 | 0.0 | 7.3 | .0025 | -2 ▼ |
| drupal | 46 | 51 | 6 | 5 | 35 | 5 | 5 | 1 | 2.0 | 5.9 | .0018 | +46 ▲ |
| gitlab | 7 | 40 | 0 | 5 | 27 | 6 | 4 | 2 | 5.0 | 4.7 | .0024 | -4 ▼ |
| github | 1 | 7 | 1 | 1 | 5 | 0 | 0 | 0 | 0.0 | 6.0 | .0026 | +1 ▲ |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 1 | 0 | 0.0 | 8.2 | .0016 | -2 ▼ |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 270 | 131 | 116 | 18 | 4 | 40 | 2 | 0.7 | 8.8 | .0040 | -2 ▼ |
| adobe | 3 | 149 | 13 | 52 | 79 | 2 | 75 | 4 | 2.7 | 5.8 | .0021 | -120 ▼ |
| ibm | 2 | 126 | 38 | 42 | 46 | 0 | 7 | 0 | 0.0 | 7.5 | .0025 | -8 ▼ |
| progress | 10 | 19 | 3 | 14 | 2 | 0 | 9 | 0 | 0.0 | 7.5 | .0034 | +5 ▲ |
| solarwinds | 0 | 7 | 1 | 2 | 2 | 0 | 11 | 4 | 57.1 | 7.5 | .0835 | -3 ▼ |
| veeam | 0 | 4 | 2 | 2 | 0 | 0 | 4 | 0 | 0.0 | 9.0 | .0046 | -1 ▼ |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -5 ▼ |
| d-link | 1 | 14 | 0 | 5 | 3 | 5 | 26 | 1 | 7.1 | 6.0 | .0058 | -7 ▼ |
| siemens | 4 | 13 | 0 | 7 | 6 | 0 | 1 | 0 | 0.0 | 7.1 | .0019 | -3 ▼ |
| rockwell automation | 0 | 7 | 1 | 5 | 1 | 0 | 0 | 0 | 0.0 | 8.7 | .0030 | 0 |
| abb | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -5 ▼ |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 1 | 0 | 0.0 | 7.8 | .0024 | -1 ▼ |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | 0 |
| dahua | 0 | 3 | 0 | 1 | 1 | 1 | 2 | 0 | 0.0 | 6.9 | .0036 | -3 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 28 | 99 | 0 | 0 | 53 | 46 | 0 | 0 | 0.0 | 5.5 | .0026 | -7 ▼ |
| dell | 33 | 89 | 4 | 41 | 40 | 3 | 2 | 1 | 1.1 | 7.0 | .0020 | +26 ▲ |
| capgo | 15 | 76 | 2 | 38 | 35 | 1 | 0 | 0 | 0.0 | 7.0 | .0029 | +15 ▲ |
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -68 ▼ |
| openclaw | 1 | 68 | 0 | 36 | 22 | 10 | 0 | 0 | 0.0 | 7.0 | .0021 | -13 ▼ |
| edimax | 0 | 65 | 0 | 39 | 0 | 26 | 1 | 0 | 0.0 | 7.4 | .0059 | 0 |
| itsourcecode | 10 | 63 | 0 | 0 | 19 | 44 | 0 | 0 | 0.0 | 2.1 | .0020 | -12 ▼ |
| themerex | 2 | 60 | 5 | 54 | 1 | 0 | 0 | 0 | 0.0 | 8.1 | .0043 | +2 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-48282 | .9924 | 99.9 | 10.0 |
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-48908 | .8813 | 99.8 | 10.0 |
| CVE-2026-34910 | .8696 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-56290 | .8325 | 99.7 | 10.0 |
| CVE-2026-20230 | .8321 | 99.7 | 8.6 |
| CVE-2026-48939 | .8250 | 99.6 | 10.0 |
| CVE-2026-56291 | .7607 | 99.5 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-48282 | 10.0 | .9924 | KEV |
| CVE-2026-48908 | 10.0 | .8813 | KEV |
| CVE-2026-34910 | 10.0 | .8696 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-56290 | 10.0 | .8325 | KEV |
| CVE-2026-48939 | 10.0 | .8250 | KEV |
| CVE-2026-56291 | 10.0 | .7607 | KEV |
| CVE-2026-48907 | 10.0 | .6883 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-50160 | 10.0 | .1775 |
| Vendor | CVEs |
|---|---|
| 579 | |
| linux | 456 |
| oracle | 241 |
| apache | 126 |
| red hat | 125 |
| capgo | 76 |
| ibm | 67 |
| microsoft | 67 |
| dell | 64 |
| themerex | 60 |
| Vendor | KEV |
|---|---|
| microsoft | 28 |
| cisco | 11 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| adobe | 4 |
| solarwinds | 4 |
| synacor | 4 |
| fortinet | 3 |
| linux | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 71 |
| npm | 6 |
| PyPI | 5 |
| NuGet | 3 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2025-67038 | Lantronix | 0 |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE-2026-20262 | Cisco | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE-2026-34909 | Ubiquiti Inc | 0 |
| CVE-2026-34910 | Ubiquiti Inc | 0 |
| CVE-2026-35273 | Oracle Corporation | 0 |
| CVE-2026-45659 | Microsoft | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1697 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1697 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1697 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1697 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1697 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1697 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1697 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1697 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1697 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1697 |
EXPLOIT PUBLISHED — CVE-2026-57827 (rsjoomla.com RSFiles extension for Joomla). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-57828 (phoca.cz Phoca Download extension for Joomla). Public exploit reference added.
DUE DATE PASSED — CVE-2026-48282 (Adobe ColdFusion). CISA remediation deadline was July 10, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-48908 (joomshaper.net SP Page Builder extension for Joomla). CISA remediation deadline was July 10, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-55255 (langflow-ai langflow). CISA remediation deadline was July 10, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-56290 (JoomlaCK.fr Page Builder CK extension for Joomla). CISA remediation deadline was July 10, 2026; still in catalog.
How to read these box scores · glossary
79 CVEs published. 25 box scores, 54 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0277 85.2 —
AFFECTED Product Versions Fixed W3 Total Cache unspecified —
TIMELINE May 22 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0223 81.3 —
AFFECTED Product Versions Fixed PraisonAI unspecified 1.6.78
TIMELINE Jul 9 Reserved by CNA Jul 11 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0160 73.9 —
AFFECTED Product Versions Fixed rsjoomla.com RSFiles extension for Joomla 1.0-1.17.11 – —
TIMELINE Jun 25 Reserved by CNA Jul 11 Public exploit reference published Jul 11 Published (CNA: Joomla)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0113 63.9 —
AFFECTED Product Versions Fixed Planyo online reservation system unspecified —
TIMELINE Mar 4 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N R C H H H 8.3 .0070 50.5 —
AFFECTED Product Versions Fixed Microsoft Edge (Chromium-based) 1.0.0.0 – —
TIMELINE Jun 29 Reserved by CNA Jul 11 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0062 47.2 —
AFFECTED Product Versions Fixed WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel unspecified —
TIMELINE Jun 25 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H H H 7.5 .0055 43.6 —
AFFECTED Product Versions Fixed LA-Studio Element Kit for Elementor unspecified —
TIMELINE Jul 9 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 9.4 .0054 43.0 —
AFFECTED Product Versions Fixed PraisonAI unspecified 4.6.78
TIMELINE Jul 9 Reserved by CNA Jul 11 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0054 43.0 —
AFFECTED Product Versions Fixed Swiss Toolkit For WP unspecified —
TIMELINE Feb 11 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0048 39.6 —
AFFECTED Product Versions Fixed Booking Package unspecified —
TIMELINE Jul 9 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0047 38.8 —
AFFECTED Product Versions Fixed Code Engine – PHP Snippets, AI Functions & Automation for WordPress unspecified —
TIMELINE Jun 27 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0041 34.4 —
AFFECTED Product Versions Fixed PraisonAI unspecified 4.6.78
TIMELINE Jul 8 Reserved by CNA Jul 11 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0038 31.5 —
AFFECTED Product Versions Fixed Simple JWT Login – Allows you to use JWT on REST endpoints. unspecified —
TIMELINE Jun 30 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P L N H H H 9.0 .0037 30.5 —
AFFECTED Product Versions Fixed phoca.cz Phoca Download extension for Joomla 1.0-6.1.2 – —
TIMELINE Jun 25 Reserved by CNA Jul 11 Public exploit reference published Jul 11 Published (CNA: Joomla)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L N N 5.3 .0037 30.3 —
AFFECTED Product Versions Fixed Cost Calculator Builder unspecified —
TIMELINE Jun 4 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N L N 5.3 .0036 29.4 —
AFFECTED Product Versions Fixed WCFM – Frontend Manager for WooCommerce unspecified —
TIMELINE Jun 23 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0036 28.9 —
AFFECTED Product Versions Fixed Essential Addons for Elementor – Popular Elementor Templates & Widgets unspecified —
TIMELINE Jul 8 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N L N 5.3 .0035 28.6 —
AFFECTED Product Versions Fixed AI Copilot – Content Generator unspecified —
TIMELINE Apr 21 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0035 28.4 —
AFFECTED Product Versions Fixed Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin unspecified —
TIMELINE Jun 24 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N L N 4.3 .0035 28.2 —
AFFECTED Product Versions Fixed Points and Rewards for WooCommerce unspecified —
TIMELINE Jun 2 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0033 25.6 —
AFFECTED Product Versions Fixed WP CTA – Call Now Button, Sticky Button & Call to Action Builder unspecified —
TIMELINE Mar 23 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N L N 5.3 .0032 25.5 —
AFFECTED Product Versions Fixed AI Copilot – Content Generator unspecified —
TIMELINE Apr 21 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0032 25.3 —
AFFECTED Product Versions Fixed CorvusPay WooCommerce Payment Gateway unspecified —
TIMELINE Apr 23 Reserved by CNA Jul 11 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P N N N N L 6.3 .0032 25.3 —
AFFECTED Product Versions Fixed ImageMagick unspecified 7.1.2-26 ImageMagick unspecified 6.9.13-51
TIMELINE Jul 10 Reserved by CNA Jul 11 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H L L 8.8 .0032 25.1 —
AFFECTED Product Versions Fixed PraisonAI unspecified 1.7.3
TIMELINE Jul 9 Reserved by CNA Jul 11 Published (CNA: VulnCheck)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-7655 | 8.1 | 24.9 | surecart | SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments | CWE-640 | SureCart <= 4.2.3 - Unauthenticated Linked WordPress Account Takeover via For… |
| CVE-2026-1359 | 8.8 | 23.2 | genolve | Genolve – Genolve AI Business Graphics, AI Images | CWE-863 | Genolve – AI image AI video generation <= 5.0.5 - Authenticated (Contributor+… |
| CVE-2026-7559 | 4.3 | 23.1 | redefiningtheweb | Affiliate Program & Referral Tracking for WooCommerce & WordPress – Affilia | CWE-862 | Affilia <= 3.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbit… |
| CVE-2026-56303 | 8.7 | 22.9 | Capgo | Capgo | CWE-200 | Capgo - Unauthenticated API Key Metadata Disclosure via SECURITY DEFINER RPC … |
| CVE-2026-13756 | 8.8 | 22.7 | WP Grid Builder | WP Grid Builder | CWE-269 | WP Grid Builder <= 2.3.3 - Authenticated (Subscriber+) Privilege Escalation v… |
| CVE-2026-11426 | 6.5 | 22.5 | WebFactory | Under Construction Page (Pro) | CWE-22 | UnderConstructionPage PRO <= 5.76 - Authenticated (Subscriber+) Arbitrary Fil… |
| CVE-2026-13250 | 5.3 | 22.5 | solacewp | Solace Extra | CWE-862 | Solace Extra <= 1.5.3 - Missing Authorization to Unauthenticated Arbitrary Co… |
| CVE-2026-12103 | 4.3 | 21.3 | subratamal | Wallet for WooCommerce | CWE-862 | Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Sub… |
| CVE-2026-12426 | 5.3 | 19.8 | supercleanse | Members – Membership & User Role Editor Plugin | CWE-200 | Members <= 3.2.22 - Unauthenticated Sensitive Information Disclosure via REST… |
| CVE-2026-15072 | 6.5 | 19.8 | iqonicdesign | KiviCare – Clinic & Patient Management System (EHR) | CWE-89 | KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Param… |
| CVE-2026-9017 | 5.3 | 19.8 | webaways | NEX-Forms – Ultimate Forms Plugin for WordPress | CWE-862 | NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Arbitrary Form … |
| CVE-2026-7620 | 4.3 | 19.7 | rainafarai | Notification for Telegram | CWE-862 | Notification for Telegram <= 3.5.1 - Missing Authorization to Authenticated (… |
| CVE-2026-61857 | 6.3 | 18.6 | ImageMagick | ImageMagick | CWE-252 | ImageMagick before 7.1.2-26 Heap Use-After-Free via XMP |
| CVE-2026-61439 | 8.7 | 17.9 | MervinPraison | PraisonAI | CWE-1188 | PraisonAI before 4.6.78 Prompt Injection Defense Bypass |
| CVE-2026-13378 | 7.2 | 17.8 | wpvibes | Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database | CWE-79 | Form Vibes <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting via Contact… |
| CVE-2025-5017 | 4.9 | 17.7 | catalyst2020 | Catalyst Connect Zoho CRM Client Portal | CWE-89 | Catalyst Connect Zoho CRM Client Portal <= 2.2.0 - Authenticated (Administrat… |
| CVE-2026-61442 | 7.1 | 17.4 | MervinPraison | PraisonAI | CWE-862 | PraisonAI Platform before 0.1.9 Authorization Bypass via PATCH |
| CVE-2026-3367 | 4.4 | 17.4 | lustmored | Lockme calendars integration | CWE-79 | Lockme OAuth2 calendars integration <= 2.11.0 - Authenticated (Administrator+… |
| CVE-2026-5743 | 6.4 | 16.9 | gallerycreator | SimpLy Gallery | CWE-79 | Mixed Media Gallery Blocks <= 3.3.3.1 - Authenticated (Author+) Stored Cross-… |
| CVE-2026-11591 | 4.4 | 16.9 | trustindex | Widgets for Google Reviews | CWE-79 | Widgets for Google Reviews <= 13.3 - Authenticated (Editor+) Stored Cross-Sit… |
| CVE-2026-10041 | 4.3 | 16.7 | wclovers | WCFM – Frontend Manager for WooCommerce | CWE-639 | WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Authenticated (Subscriber… |
| CVE-2026-13114 | 7.2 | 16.3 | stylemix | Motors – Car Dealership & Classified Listings Plugin | CWE-79 | Motors <= 1.4.112 - Unauthenticated Stored Cross-Site Scripting via Comment C… |
| CVE-2026-61428 | 6.9 | 16.1 | MervinPraison | PraisonAI | CWE-290 | PraisonAI AgentMail before 4.6.78 Message Injection via Webhook |
| CVE-2026-61858 | 4.8 | 16.2 | ImageMagick | ImageMagick | CWE-59 | ImageMagick before 7.1.2-26 Policy Bypass via APNG encoder |
| CVE-2026-11898 | 4.4 | 16.2 | videousermanuals | White Label CMS | CWE-79 | White Label CMS <= 2.7.12 - Authenticated (Administrator+) Stored Cross-Site … |
| CVE-2026-61448 | 2.1 | 16.0 | parse-community | parse-server | CWE-434 | Parse Server 9.0.0 Stored XSS via malformed Content-Type |
| CVE-2026-15073 | 6.5 | 15.6 | iqonicdesign | KiviCare – Clinic & Patient Management System (EHR) | CWE-89 | KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Param… |
| CVE-2026-61454 | 8.7 | 15.3 | getgrav | grav | CWE-200 | Grav before 2.0.4 Information Disclosure via __GRAV_CONFIG__ |
| CVE-2026-56296 | 6.9 | 15.3 | Cap-go | capgo | CWE-203 | Cap-go - App Existence Oracle via Unauthenticated transfer_app RPC |
| CVE-2026-6801 | 5.3 | 15.3 | postmagthemes | Context Blog | CWE-200 | Context Blog <= 1.3.5 - Unauthenticated Sensitive Information Exposure via 'p… |
| CVE-2026-7544 | 4.3 | 15.1 | 2coders | Mux Video Uploader | CWE-200 | Mux Video Uploader <= 1.1.4 - Authenticated (Subscriber+) Information Exposure |
| CVE-2026-13116 | 4.3 | 14.9 | wpovernight | PDF Invoices & Packing Slips for WooCommerce | CWE-639 | PDF Invoices & Packing Slips for WooCommerce <= 5.14.0 - Insecure Direct Obje… |
| CVE-2026-8678 | 4.3 | 14.4 | richardperdaan | MyParcel | CWE-862 | MyParcel <= 4.25.1 - Missing Authorization to Authenticated (Subscriber+) Arb… |
| CVE-2026-61429 | 8.4 | 13.0 | MervinPraison | PraisonAI | CWE-918 | PraisonAI before 1.6.78 SSRF via Crawl4AI Chromium backend |
| CVE-2026-3552 | 4.3 | 12.0 | surflabtech | SurfLink – Link Manager & Backup Restore | CWE-862 | SurfLink < 2.6.0 - Missing Authorization to Authenticated (Subscriber+) 410 G… |
| CVE-2026-12738 | 4.3 | 12.0 | saadiqbal | WP Easy Pay – Payment and Donation form Builder for Square | CWE-862 | WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) A… |
| CVE-2026-9738 | 4.4 | 11.2 | printfriendly | Print, PDF & Email by PrintFriendly | CWE-79 | Print, PDF, Email by PrintFriendly <= 5.5.10 - Authenticated (Administrator+)… |
| CVE-2026-15470 | 2.1 | 11.2 | Eleveo | Call Recording Software | CWE-266 | Eleveo Call Recording Software group.jsp improper authorization |
| CVE-2026-12126 | 6.4 | 10.7 | wclovers | WCFM Marketplace – Multivendor Marketplace for WooCommerce | CWE-79 | WCFM Marketplace <= 3.7.3 - Authenticated (Vendor+) Stored Cross-Site Scripti… |
| CVE-2026-1832 | 4.3 | 10.7 | thrivedesk | Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk | CWE-862 | ThriveDesk <= 2.1.7 - Missing Authorization to Authenticated (Subscriber+) Ca… |
| CVE-2026-15010 | 6.4 | 10.6 | robin-w | bbp style pack | CWE-79 | bbp style pack <= 6.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scrip… |
| CVE-2026-56372 | 4.8 | 10.0 | ImageMagick | ImageMagick | CWE-122 | ImageMagick - Heap Buffer Overflow Read via Unrecognized Magnify Method |
| CVE-2025-13968 | 6.4 | 9.6 | starboardsuite | Starboard Suite Reservation Calendars | CWE-79 | Starboard Suite Reservation Calendars <= 3.1.4 - Authenticated (Contributor+)… |
| CVE-2026-15097 | 6.4 | 9.6 | themifyme | Themify Builder | CWE-79 | Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scr… |
| CVE-2026-12141 | 4.9 | 9.3 | leap13 | Premium Addons for Elementor – Powerful Elementor Templates & Widgets | CWE-79 | Premium Addons for Elementor <= 4.11.84 - Authenticated (Contributor+) Stored… |
| CVE-2026-61870 | 2.1 | 9.2 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-26 Memory Leak via VIFF Encoder |
| CVE-2026-1382 | 6.4 | 8.7 | freshlabs | fresh Podcaster | CWE-79 | fresh Podcaster <= 1.0.7 - Authenticated (Contributor+) Stored Cross-Site Scr… |
| CVE-2026-15096 | 6.4 | 8.8 | themifyme | Themify Builder | CWE-79 | Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scr… |
| CVE-2026-56240 | 5.3 | 8.1 | Capgo | Capgo | CWE-285 | Capgo - Billing Authorization Bypass via Exhausted Usage Credits |
| CVE-2026-11901 | 5.3 | 7.6 | thimpress | WP Hotel Booking | CWE-345 | WP Hotel Booking <= 2.3.1 - Unauthenticated Insufficient Verification of Data… |
| CVE-2026-56763 | 6.3 | 7.5 | Hono | Hono | CWE-1321 | Hono - Prototype Pollution via __proto__ Key in parseBody with dot Option |
| CVE-2026-61465 | 4.8 | 7.0 | ImageMagick | ImageMagick | CWE-770 | ImageMagick before 7.1.2-26 Memory Allocation Policy Bypass |
| CVE-2026-10660 | 6.4 | 5.6 | zephyrproject | zephyr | CWE-787 | Shared reassembly buffer in Bluetooth BAP Broadcast Assistant enables cross-c… |
| CVE-2026-60088 | 6.8 | 4.4 | MervinPraison | PraisonAI | CWE-22 | PraisonAI before 4.6.78 Path Traversal via Custom Commands |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-11 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion.