{
  "day": "2026-07-11",
  "boundary": "UTC calendar day",
  "published_count": 79,
  "by_severity": {
    "CRITICAL": 5,
    "HIGH": 23,
    "MEDIUM": 48,
    "LOW": 3
  },
  "kev_count": 0,
  "exploit_reference_count": 1,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-9282",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.02773,
      "epss_percentile": 0.85188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boldgrid",
      "product": "W3 Total Cache",
      "cwe": "CWE-22",
      "title": "W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9282"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-61447",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02226,
      "epss_percentile": 0.81314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-94",
      "title": "PraisonAI before 1.6.78 Remote Code Execution via CodeAgent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61447"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-57827",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01602,
      "epss_percentile": 0.73859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rsjoomla.com",
      "product": "rsjoomla.com RSFiles extension for Joomla",
      "cwe": "CWE-434",
      "title": "Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57827"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-3576",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.01131,
      "epss_percentile": 0.63861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xtreeme",
      "product": "Planyo online reservation system",
      "cwe": "CWE-20",
      "title": "Planyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3576"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-58281",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00704,
      "epss_percentile": 0.50492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-502",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58281"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-13353",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00623,
      "epss_percentile": 0.47197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smackcoders",
      "product": "WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel",
      "cwe": "CWE-94",
      "title": "WP Ultimate CSV Importer <= 8.0.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'MappedFields' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13353"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-15338",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00549,
      "epss_percentile": 0.43585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "choijun",
      "product": "LA-Studio Element Kit for Elementor",
      "cwe": "CWE-98",
      "title": "LA-Studio Element Kit for Elementor <= 1.6.1 - Authenticated (Contributor+) Local File Inclusion via 'progress_type' Widget Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15338"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-61445",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00538,
      "epss_percentile": 0.43018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-22",
      "title": "PraisonAI before 4.6.78 Arbitrary File Write and Command Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61445"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-2354",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00537,
      "epss_percentile": 0.42976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmessiah",
      "product": "Swiss Toolkit For WP",
      "cwe": "CWE-434",
      "title": "Swiss Toolkit For WP <= 1.4.6 - Authenticated (Author+) Arbitrary File Upload via upload_extension_files()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2354"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-15335",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00482,
      "epss_percentile": 0.39643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "masaakitanaka",
      "product": "Booking Package",
      "cwe": "CWE-89",
      "title": "Booking Package <= 1.7.20 - Unauthenticated SQL Injection via 'email' Form Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15335"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2025-6784",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00469,
      "epss_percentile": 0.388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tigroumeow",
      "product": "Code Engine – PHP Snippets, AI Functions & Automation for WordPress",
      "cwe": "CWE-77",
      "title": "Code Engine <= 0.3.5 - Authenticated (Contributor+) Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-6784"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-60090",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0041,
      "epss_percentile": 0.34366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-89",
      "title": "PraisonAI before 4.6.78 SQL/CQL Injection via vector dimension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60090"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-14262",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00382,
      "epss_percentile": 0.31514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nicu_m",
      "product": "Simple JWT Login – Allows you to use JWT on REST endpoints.",
      "cwe": "CWE-269",
      "title": "Simple JWT Login <= 3.6.6 - Authenticated (Subscriber+) Authentication Bypass to Privilege Escalation via 'payload' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14262"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-57828",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.30457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phoca.cz",
      "product": "phoca.cz Phoca Download extension for Joomla",
      "cwe": "CWE-434",
      "title": "Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57828"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-10865",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0037,
      "epss_percentile": 0.30302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stylemix",
      "product": "Cost Calculator Builder",
      "cwe": "CWE-200",
      "title": "Cost Calculator Builder <= 4.0.11 - Unauthenticated Sensitive Information Exposure of Payment Gateway Secret Keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10865"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-12994",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00361,
      "epss_percentile": 0.29358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wclovers",
      "product": "WCFM – Frontend Manager for WooCommerce",
      "cwe": "CWE-862",
      "title": "WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Missing Authorization to Unauthenticated Arbitrary Inquiry Reply Injection via wcfm-my-account-enquiry-manage Controller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12994"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-15155",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00356,
      "epss_percentile": 0.28879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevteam",
      "product": "Essential Addons for Elementor – Popular Elementor Templates & Widgets",
      "cwe": "CWE-640",
      "title": "Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeover via Email Header Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15155"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-6804",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00354,
      "epss_percentile": 0.28616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wupsales",
      "product": "AI Copilot – Content Generator",
      "cwe": "CWE-862",
      "title": "AI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Modification via 'publishTasks' and 'unpublishTasks' AJAX Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6804"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-13262",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00352,
      "epss_percentile": 0.28409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ahmadmj",
      "product": "Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin",
      "cwe": "CWE-89",
      "title": "Majestic Support <= 1.1.9 - Authenticated (Subscriber+) SQL Injection via 'val' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13262"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-10628",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0035,
      "epss_percentile": 0.28172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpswings",
      "product": "Points and Rewards for WooCommerce",
      "cwe": "CWE-862",
      "title": "Points and Rewards for WooCommerce <= 2.10.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10628"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-4661",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "blendmedia",
      "product": "WP CTA – Call Now Button, Sticky Button & Call to Action Builder",
      "cwe": "CWE-89",
      "title": "WP CTA <= 2.2.2 - Unauthenticated Time-Based Blind SQL Injection via 'fildname' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4661"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-6803",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.25464,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wupsales",
      "product": "AI Copilot – Content Generator",
      "cwe": "CWE-862",
      "title": "AI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via AJAX Actions 'removeGroup' and 'clear'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6803"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-6939",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "corvusinfo",
      "product": "CorvusPay WooCommerce Payment Gateway",
      "cwe": "CWE-79",
      "title": "CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Stored Cross-Site Scripting via 'approval_code' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6939"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-61861",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.25259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-416",
      "title": "ImageMagick before 7.1.2-26 Use-After-Free in FormatMagickCaption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61861"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-61426",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-200",
      "title": "PraisonAI before 1.7.3 Unauthenticated Agent Access via Insecure Defaults",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61426"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-7655",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surecart",
      "product": "SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments",
      "cwe": "CWE-640",
      "title": "SureCart <= 4.2.3 - Unauthenticated Linked WordPress Account Takeover via Forged customer.updated Webhook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7655"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-1359",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "genolve",
      "product": "Genolve – Genolve AI Business Graphics, AI Images",
      "cwe": "CWE-863",
      "title": "Genolve – AI image AI video generation <= 5.0.5 - Authenticated (Contributor+) Incorrect Authorization to Privilege Escalation via theopt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1359"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-7559",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00304,
      "epss_percentile": 0.23117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "redefiningtheweb",
      "product": "Affiliate Program & Referral Tracking for WooCommerce & WordPress – Affilia",
      "cwe": "CWE-862",
      "title": "Affilia <= 3.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Status Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7559"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-56303",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-200",
      "title": "Capgo - Unauthenticated API Key Metadata Disclosure via SECURITY DEFINER RPC Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56303"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-13756",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Grid Builder",
      "product": "WP Grid Builder",
      "cwe": "CWE-269",
      "title": "WP Grid Builder <= 2.3.3 - Authenticated (Subscriber+) Privilege Escalation via 'key' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13756"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-11426",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.22547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebFactory",
      "product": "Under Construction Page (Pro)",
      "cwe": "CWE-22",
      "title": "UnderConstructionPage PRO <= 5.76 - Authenticated (Subscriber+) Arbitrary File Read via template_thumbnail Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11426"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-13250",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.22509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "solacewp",
      "product": "Solace Extra",
      "cwe": "CWE-862",
      "title": "Solace Extra <= 1.5.3 - Missing Authorization to Unauthenticated Arbitrary Content Deletion via delete_previously_imported AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13250"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-12103",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.21258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "subratamal",
      "product": "Wallet for WooCommerce",
      "cwe": "CWE-862",
      "title": "Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12103"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-12426",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.19826,
      "kev": false,
      "kev_due_at": null,
      "vendor": "supercleanse",
      "product": "Members – Membership & User Role Editor Plugin",
      "cwe": "CWE-200",
      "title": "Members <= 3.2.22 - Unauthenticated Sensitive Information Disclosure via REST API Pagination Side Channel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12426"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-15072",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00273,
      "epss_percentile": 0.19802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iqonicdesign",
      "product": "KiviCare – Clinic & Patient Management System (EHR)",
      "cwe": "CWE-89",
      "title": "KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in KCQueryBuilder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15072"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-9017",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00273,
      "epss_percentile": 0.1977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webaways",
      "product": "NEX-Forms – Ultimate Forms Plugin for WordPress",
      "cwe": "CWE-862",
      "title": "NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_send_nf_email AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9017"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-7620",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rainafarai",
      "product": "Notification for Telegram",
      "cwe": "CWE-862",
      "title": "Notification for Telegram <= 3.5.1 - Missing Authorization to Authenticated (Subscriber+) Cron Modification via nftb_cron_action_set AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7620"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-61857",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-252",
      "title": "ImageMagick before 7.1.2-26 Heap Use-After-Free via XMP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61857"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-61439",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-1188",
      "title": "PraisonAI before 4.6.78 Prompt Injection Defense Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61439"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-13378",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpvibes",
      "product": "Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database",
      "cwe": "CWE-79",
      "title": "Form Vibes <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting via Contact Form 7 Form Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13378"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2025-5017",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "catalyst2020",
      "product": "Catalyst Connect Zoho CRM Client Portal",
      "cwe": "CWE-89",
      "title": "Catalyst Connect Zoho CRM Client Portal <= 2.2.0 - Authenticated (Administrator+) SQL Injection via uid Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-5017"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-61442",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-862",
      "title": "PraisonAI Platform before 0.1.9 Authorization Bypass via PATCH",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61442"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-3367",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.1743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lustmored",
      "product": "Lockme calendars integration",
      "cwe": "CWE-79",
      "title": "Lockme OAuth2 calendars integration <= 2.11.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'App ID' Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3367"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-5743",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.16864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gallerycreator",
      "product": "SimpLy Gallery",
      "cwe": "CWE-79",
      "title": "Mixed Media Gallery Blocks <= 3.3.3.1 - Authenticated (Author+) Stored Cross-Site Scripting via sliderMaxHeight Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5743"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-11591",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.16865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "trustindex",
      "product": "Widgets for Google Reviews",
      "cwe": "CWE-79",
      "title": "Widgets for Google Reviews <= 13.3 - Authenticated (Editor+) Stored Cross-Site Scripting via 'fomo-title' and 'fomo-text' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11591"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-10041",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wclovers",
      "product": "WCFM – Frontend Manager for WooCommerce",
      "cwe": "CWE-639",
      "title": "WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Vendor Data Manipulation via Multiple AJAX Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10041"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-13114",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.1629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stylemix",
      "product": "Motors – Car Dealership & Classified Listings Plugin",
      "cwe": "CWE-79",
      "title": "Motors <= 1.4.112 - Unauthenticated Stored Cross-Site Scripting via Comment Content and User Biographical Info",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13114"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-61428",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-290",
      "title": "PraisonAI AgentMail before 4.6.78 Message Injection via Webhook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61428"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-61858",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-59",
      "title": "ImageMagick before 7.1.2-26 Policy Bypass via APNG encoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61858"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-11898",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "videousermanuals",
      "product": "White Label CMS",
      "cwe": "CWE-79",
      "title": "White Label CMS <= 2.7.12 - Authenticated (Administrator+) Stored Cross-Site Scripting via Import Settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11898"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-61448",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00245,
      "epss_percentile": 0.15991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "parse-community",
      "product": "parse-server",
      "cwe": "CWE-434",
      "title": "Parse Server 9.0.0 Stored XSS via malformed Content-Type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61448"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-15073",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iqonicdesign",
      "product": "KiviCare – Clinic & Patient Management System (EHR)",
      "cwe": "CWE-89",
      "title": "KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in DoctorSessionController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15073"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-61454",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-200",
      "title": "Grav before 2.0.4 Information Disclosure via __GRAV_CONFIG__",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61454"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-56296",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "capgo",
      "cwe": "CWE-203",
      "title": "Cap-go - App Existence Oracle via Unauthenticated transfer_app RPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56296"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-6801",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "postmagthemes",
      "product": "Context Blog",
      "cwe": "CWE-200",
      "title": "Context Blog <= 1.3.5 - Unauthenticated Sensitive Information Exposure via 'postID' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6801"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-7544",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "2coders",
      "product": "Mux Video Uploader",
      "cwe": "CWE-200",
      "title": "Mux Video Uploader <= 1.1.4 - Authenticated (Subscriber+) Information Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7544"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-13116",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpovernight",
      "product": "PDF Invoices & Packing Slips for WooCommerce",
      "cwe": "CWE-639",
      "title": "PDF Invoices & Packing Slips for WooCommerce <= 5.14.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'order_id' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13116"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-8678",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.1438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "richardperdaan",
      "product": "MyParcel",
      "cwe": "CWE-862",
      "title": "MyParcel <= 4.25.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Shipment Data Disclosure and Modification via wcmp_get_shipment_options and wcmp_save_shipment_options AJAX Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8678"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-61429",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-918",
      "title": "PraisonAI before 1.6.78 SSRF via Crawl4AI Chromium backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61429"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-3552",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.11983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surflabtech",
      "product": "SurfLink – Link Manager & Backup Restore",
      "cwe": "CWE-862",
      "title": "SurfLink < 2.6.0 - Missing Authorization to Authenticated (Subscriber+) 410 Gone URL Import via 'surfl_import_410' AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3552"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-12738",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "saadiqbal",
      "product": "WP Easy Pay – Payment and Donation form Builder for Square",
      "cwe": "CWE-862",
      "title": "WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Status Modification via wpep_draft_confirm AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12738"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-9738",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "printfriendly",
      "product": "Print, PDF & Email by PrintFriendly",
      "cwe": "CWE-79",
      "title": "Print, PDF, Email by PrintFriendly <= 5.5.10 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'content_position_css' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9738"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-15470",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00207,
      "epss_percentile": 0.11163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eleveo",
      "product": "Call Recording Software",
      "cwe": "CWE-266",
      "title": "Eleveo Call Recording Software group.jsp improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15470"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-12126",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.1074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wclovers",
      "product": "WCFM Marketplace – Multivendor Marketplace for WooCommerce",
      "cwe": "CWE-79",
      "title": "WCFM Marketplace <= 3.7.3 - Authenticated (Vendor+) Stored Cross-Site Scripting via Attachment 'post_title'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12126"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-1832",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thrivedesk",
      "product": "Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk",
      "cwe": "CWE-862",
      "title": "ThriveDesk <= 2.1.7 - Missing Authorization to Authenticated (Subscriber+) Cache Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1832"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-15010",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "robin-w",
      "product": "bbp style pack",
      "cwe": "CWE-79",
      "title": "bbp style pack <= 6.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Topic Form Additional Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15010"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-56372",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-122",
      "title": "ImageMagick - Heap Buffer Overflow Read via Unrecognized Magnify Method",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56372"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2025-13968",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "starboardsuite",
      "product": "Starboard Suite Reservation Calendars",
      "cwe": "CWE-79",
      "title": "Starboard Suite Reservation Calendars <= 3.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13968"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-15097",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themifyme",
      "product": "Themify Builder",
      "cwe": "CWE-79",
      "title": "Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'height_slider' Slider Module Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15097"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-12141",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "leap13",
      "product": "Premium Addons for Elementor – Powerful Elementor Templates & Widgets",
      "cwe": "CWE-79",
      "title": "Premium Addons for Elementor <= 4.11.84 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'premium_tooltip_text' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12141"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-61870",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00191,
      "epss_percentile": 0.09166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-401",
      "title": "ImageMagick before 7.1.2-26 Memory Leak via VIFF Encoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61870"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-1382",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "freshlabs",
      "product": "fresh Podcaster",
      "cwe": "CWE-79",
      "title": "fresh Podcaster <= 1.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'freshpodcaster' Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1382"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-15096",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.0875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themifyme",
      "product": "Themify Builder",
      "cwe": "CWE-79",
      "title": "Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Module 'b_width_map' Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15096"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-56240",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-285",
      "title": "Capgo - Billing Authorization Bypass via Exhausted Usage Credits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56240"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-11901",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thimpress",
      "product": "WP Hotel Booking",
      "cwe": "CWE-345",
      "title": "WP Hotel Booking <= 2.3.1 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via PayPal IPN Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11901"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-56763",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hono",
      "product": "Hono",
      "cwe": "CWE-1321",
      "title": "Hono - Prototype Pollution via __proto__ Key in parseBody with dot Option",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56763"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-61465",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.07044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-770",
      "title": "ImageMagick before 7.1.2-26 Memory Allocation Policy Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61465"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-10660",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.0559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Shared reassembly buffer in Bluetooth BAP Broadcast Assistant enables cross-connection memory corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10660"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-60088",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-22",
      "title": "PraisonAI before 4.6.78 Path Traversal via Custom Commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60088"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57827",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57827 (rsjoomla.com RSFiles extension for Joomla). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57828",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57828 (phoca.cz Phoca Download extension for Joomla). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-48282",
      "detail": "DUE DATE PASSED — CVE-2026-48282 (Adobe ColdFusion). CISA remediation deadline was July 10, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-48908",
      "detail": "DUE DATE PASSED — CVE-2026-48908 (joomshaper.net SP Page Builder extension for Joomla). CISA remediation deadline was July 10, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-55255",
      "detail": "DUE DATE PASSED — CVE-2026-55255 (langflow-ai langflow). CISA remediation deadline was July 10, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-56290",
      "detail": "DUE DATE PASSED — CVE-2026-56290 (JoomlaCK.fr Page Builder CK extension for Joomla). CISA remediation deadline was July 10, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
