{
  "day": "2026-07-13",
  "boundary": "UTC calendar day",
  "published_count": 337,
  "by_severity": {
    "CRITICAL": 49,
    "HIGH": 147,
    "MEDIUM": 108,
    "LOW": 32
  },
  "kev_count": 1,
  "exploit_reference_count": 8,
  "awaiting_enrichment_count": 1,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2008-4128",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.32953,
      "epss_percentile": 0.98222,
      "kev": true,
      "kev_due_at": "2026-07-16",
      "vendor": "Cisco",
      "product": "IOS",
      "cwe": null,
      "title": "Cisco IOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2008-4128"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-6875",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.26734,
      "epss_percentile": 0.97864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ServiceNow",
      "product": "ServiceNow AI Platform",
      "cwe": "CWE-94",
      "title": "Sandbox Escape in ServiceNow AI Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6875"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-61498",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.04089,
      "epss_percentile": 0.89902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VITEC",
      "product": "Flamingo",
      "cwe": "CWE-78",
      "title": "Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61498"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-60121",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02336,
      "epss_percentile": 0.82232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VITEC",
      "product": "Flamingo",
      "cwe": "CWE-78",
      "title": "Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60121"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-59801",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02244,
      "epss_percentile": 0.81464,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9Router",
      "cwe": "CWE-306",
      "title": "9Router 0.4.41 - Unauthenticated API Exposure via /api/providers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59801"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-15546",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0105,
      "epss_percentile": 0.61585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shibby",
      "product": "Tomato",
      "cwe": "CWE-77",
      "title": "Shibby Tomato start_jffs2 sub_2D568 os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15546"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-15547",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0105,
      "epss_percentile": 0.61587,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shibby",
      "product": "Tomato",
      "cwe": "CWE-77",
      "title": "Shibby Tomato CIFS Mount sub_2D048 os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15547"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-22095",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00909,
      "epss_percentile": 0.57183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EVbee",
      "product": "DC-80",
      "cwe": "CWE-77",
      "title": "Command injection in diagnosis web endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22095"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-22103",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00909,
      "epss_percentile": 0.57183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EVbee",
      "product": "DC-80",
      "cwe": "CWE-77",
      "title": "Command injection in NPC start web endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22103"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-22100",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00809,
      "epss_percentile": 0.54066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EVbee",
      "product": "DC-80",
      "cwe": "CWE-78",
      "title": "Comnand injection in OCPP ReserveLogin message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22100"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-49972",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00777,
      "epss_percentile": 0.53003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "plank",
      "product": "laravel-mediable",
      "cwe": "CWE-434",
      "title": "Laravel-Mediable < 7.0.0 File Upload RCE via Extension Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49972"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-49970",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00771,
      "epss_percentile": 0.52816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "plank",
      "product": "laravel-mediable",
      "cwe": "CWE-22",
      "title": "Laravel-Mediable < 7.0.0 Path Traversal via File::sanitizePath()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49970"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-61500",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00747,
      "epss_percentile": 0.52043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rejetto",
      "product": "hfs",
      "cwe": "CWE-338",
      "title": "Rejetto HFS < 3.2.1 Session Forgery via Predictable Signing Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61500"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-26396",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00746,
      "epss_percentile": 0.51982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "OpenBMB XAgent v1.0.0 and before is vulnerable to path traversal in the file() function in XAgent/XAgentServer/application/routers/workspace.py. The input parameter “filename” is user-controllable and is concatenated into the file path to be read without proper validation, leading to a directory traversal vulnerability that may result in sensitive information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26396"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-6847",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00584,
      "epss_percentile": 0.45349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "4real",
      "product": "ThemisNETPanel",
      "cwe": "CWE-306",
      "title": "Unauthenticated Remote Code Execution in ThemisNETPanel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6847"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-15548",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00558,
      "epss_percentile": 0.44038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shibby",
      "product": "Tomato",
      "cwe": "CWE-119",
      "title": "Shibby Tomato DNS List Rendering httpd sub_407220 stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15548"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-51821",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00527,
      "epss_percentile": 0.42396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute arbitrary code via the /user/getUserLogin endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51821"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-14453",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00505,
      "epss_percentile": 0.4109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Centreon",
      "product": "Infra Monitoring",
      "cwe": "CWE-94",
      "title": "A user with low privileges can inject SSTI templates that can lead to RCE in open-tickets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14453"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-51536",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00492,
      "epss_percentile": 0.40281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-190",
      "title": "In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed across the call stack. Specifically, an upstream length calculated as an int is passed to a downstream function that expects an EipInt16 (a 16-bit signed integer). If a maliciously crafted packet with specific length fields is processed, the length parameter can overflow or be truncated into a negative value. This negative length bypasses subsequent bounds checking (due to signed/unsigned comparison issues) and is ultimately used in memory operations, leading to a Stack Buffer Overflow when reading data in DecodePaddedEPath.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51536"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-51537",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0048,
      "epss_percentile": 0.39547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-125",
      "title": "EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing short malformed packets. An attacker can send a valid ENIP outer frame carrying a malformed CIP ForwardOpen/LargeForwardOpen request, causing the parser to continue reading fields even when request data is insufficient. This issue is remotely triggerable via network traffic and does not require authentication.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51537"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-58065",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00477,
      "epss_percentile": 0.39353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow Git provider",
      "cwe": "CWE-322",
      "title": "Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58065"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-15543",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00476,
      "epss_percentile": 0.39303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "CH22",
      "cwe": "CWE-119",
      "title": "Tenda CH22 CertListInfo formCertListInfo buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15543"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-41041",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00475,
      "epss_percentile": 0.39229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Gravitino",
      "cwe": "CWE-177",
      "title": "Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended API endpoints.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41041"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-13014",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0047,
      "epss_percentile": 0.38881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thales CERT",
      "product": "Suspicious",
      "cwe": "CWE-22",
      "title": "Remote Code Execution vulnerability in \"Suspicious\" application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13014"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-58409",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00456,
      "epss_percentile": 0.38016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ChurchCRM",
      "product": "CRM",
      "cwe": "CWE-434",
      "title": "ChurchCRM: Authenticated Remote Code Execution (RCE) via Malicious Plugin Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58409"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-61505",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00452,
      "epss_percentile": 0.37704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rejetto",
      "product": "hfs",
      "cwe": "CWE-22",
      "title": "Rejetto HFS < 3.2.1 Limited File Disclosure via Path Traversal in lang Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61505"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-4769",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00447,
      "epss_percentile": 0.37369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WAGO",
      "product": "0765-110x/0100-0000",
      "cwe": "CWE-912",
      "title": "Unauthenticated Access to Internal Diagnostic Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4769"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-62184",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00445,
      "epss_percentile": 0.37228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openwrt",
      "product": "luci-app-banip",
      "cwe": "CWE-116",
      "title": "luci-app-banip Log Monitor IP Extraction Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62184"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-15544",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.36638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shibby",
      "product": "Tomato",
      "cwe": "CWE-119",
      "title": "Shibby Tomato apcupsd tomatodata.cgi getupsvar stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15544"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-13221",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00432,
      "epss_percentile": 0.36199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SHAY",
      "product": "perl",
      "cwe": "CWE-190",
      "title": "Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13221"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-51540",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00421,
      "epss_percentile": 0.35299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-191",
      "title": "OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing of connected explicit messages (SendUnitData).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51540"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-51541",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00421,
      "epss_percentile": 0.35299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-125",
      "title": "OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath size. An attacker can send a valid ENIP SendRRData frame carrying a very short CIP payload whose path_size field claims that many more path words are present than are actually available. Because the parser trusts the attacker-controlled path_size and continues decoding path segments without a remaining-length boundary, it reads beyond the end of the stack receive buffer.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51541"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-52533",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00414,
      "epss_percentile": 0.34723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-269",
      "title": "An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52533"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-12257",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mura Software",
      "product": "CMS",
      "cwe": "CWE-94",
      "title": "Remote code execution in Mura Software’s CMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12257"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-39042",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00409,
      "epss_percentile": 0.34288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-190",
      "title": "An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial of service via the unflatten() function in libumsg.so.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39042"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-57743",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stmcan",
      "product": "RT-Theme 18 | Extensions",
      "cwe": "CWE-98",
      "title": "WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57743"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-15542",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00403,
      "epss_percentile": 0.33702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "will-moss",
      "product": "Isaiah",
      "cwe": "CWE-287",
      "title": "will-moss Isaiah Websocket Connection Authentication main.go improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15542"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-49876",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00402,
      "epss_percentile": 0.33593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Gravitino",
      "cwe": "CWE-918",
      "title": "Apache Gravitino: Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49876"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-15557",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00397,
      "epss_percentile": 0.33066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "waooAI",
      "product": "waoowaoo",
      "cwe": "CWE-287",
      "title": "waooAI waoowaoo Internal Task Header api-auth.ts requireProjectAuthLight improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15557"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-15545",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.33001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shibby",
      "product": "Tomato",
      "cwe": "CWE-119",
      "title": "Shibby Tomato apcupsd tomatodata.cgi main out-of-bounds write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15545"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-15685",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00391,
      "epss_percentile": 0.32402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ollama",
      "product": "Ollama",
      "cwe": "CWE-129",
      "title": "Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15685"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-56877",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00391,
      "epss_percentile": 0.32434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Skillable",
      "product": "SCORM Lab Launch Integration",
      "cwe": "CWE-472",
      "title": "The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026-07-13 does not validate the client-supplied userId parameter against the authenticated SCORM session token. An authenticated user can substitute arbitrary userId values to bypass per-user lab launch rate limits and consume other users' lab allocations, resulting in denial of service against targeted users' lab and exam access. Skillable was formerly named Learn on Demand Systems.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56877"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-57856",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00389,
      "epss_percentile": 0.32248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cockpit HQ",
      "product": "Cockpit CMS",
      "cwe": "CWE-22",
      "title": "Cockpit CMS Path Traversal via Bucket Name in Bucket File Storage API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57856"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-51538",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00388,
      "epss_percentile": 0.32185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When the server processes critical encapsulation commands, it verifies whether the provided session_handle exists in the global session list, but it fails to verify whether that handle belongs to the specific TCP connection issuing the request. Because there is no strong binding between a session handle and its originating socket, any attacker on the network can use a valid session handle created by another legitimate client to bypass access controls.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51538"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-58228",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00382,
      "epss_percentile": 0.31475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phoenixframework",
      "product": "phoenix_live_view",
      "cwe": "CWE-79",
      "title": "Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link>",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58228"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-61462",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0038,
      "epss_percentile": 0.31333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zereight",
      "product": "mcp-gitlab",
      "cwe": "CWE-73",
      "title": "mcp-gitlab Path Traversal via job_id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61462"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-57724",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00375,
      "epss_percentile": 0.30797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeum",
      "product": "Kirki",
      "cwe": "CWE-502",
      "title": "WordPress Kirki plugin <= 6.0.12 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57724"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-57738",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00375,
      "epss_percentile": 0.30799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axiomthemes",
      "product": "777",
      "cwe": "CWE-502",
      "title": "WordPress 777 theme <= 1.13.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57738"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-57401",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00371,
      "epss_percentile": 0.30396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brainstorm Force",
      "product": "SureDash",
      "cwe": "CWE-22",
      "title": "WordPress SureDash plugin <= 1.8.0 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57401"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-62327",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00371,
      "epss_percentile": 0.30326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9Router",
      "cwe": "CWE-306",
      "title": "9Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/stats",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62327"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-62328",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9Router",
      "cwe": "CWE-359",
      "title": "9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62328"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-57389",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adrian Tobey",
      "product": "Groundhogg",
      "cwe": "CWE-22",
      "title": "WordPress Groundhogg plugin <= 4.4.1 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57389"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-57709",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Swings",
      "product": "Membership For WooCommerce",
      "cwe": "CWE-22",
      "title": "WordPress Membership For WooCommerce plugin <= 3.1.0 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57709"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-57788",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edge-Themes",
      "product": "Aalto",
      "cwe": "CWE-98",
      "title": "WordPress Aalto theme <= 1.8 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57788"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-57789",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jwsthemes",
      "product": "Aqua",
      "cwe": "CWE-98",
      "title": "WordPress Aqua theme <= 5.1.2 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57789"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-57790",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeMove",
      "product": "Billey",
      "cwe": "CWE-98",
      "title": "WordPress Billey theme <= 2.1.8 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57790"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-57791",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeMove",
      "product": "Brook",
      "cwe": "CWE-98",
      "title": "WordPress Brook theme <= 2.9.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57791"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-57792",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mikado-Themes",
      "product": "Dør",
      "cwe": "CWE-98",
      "title": "WordPress Dør theme <= 2.4.1 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57792"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-57793",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elated-Themes",
      "product": "Flow",
      "cwe": "CWE-98",
      "title": "WordPress Flow theme <= 1.8 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57793"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-57794",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uxper",
      "product": "Golo Framework",
      "cwe": "CWE-98",
      "title": "WordPress Golo Framework plugin <= 1.7.3 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57794"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-57795",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themelexus",
      "product": "Kitchor",
      "cwe": "CWE-98",
      "title": "WordPress Kitchor theme <= 1.4.3 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57795"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-57796",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VLThemes",
      "product": "Leedo",
      "cwe": "CWE-98",
      "title": "WordPress Leedo theme <= 3.0.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57796"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-57798",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SaurabhSharma",
      "product": "NewsPlus Shortcodes",
      "cwe": "CWE-98",
      "title": "WordPress NewsPlus Shortcodes plugin <= 4.2.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57798"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-57799",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.3027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uxper",
      "product": "Nuss",
      "cwe": "CWE-98",
      "title": "WordPress Nuss theme <= 1.3.6 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57799"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-57800",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.3027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edge-Themes",
      "product": "Overworld",
      "cwe": "CWE-98",
      "title": "WordPress Overworld theme <= 1.5 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57800"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-57801",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.3027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Select-Themes",
      "product": "SetSail",
      "cwe": "CWE-98",
      "title": "WordPress SetSail theme <= 2.1 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57801"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-57802",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Select-Themes",
      "product": "Struktur",
      "cwe": "CWE-98",
      "title": "WordPress Struktur theme < 2.7 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57802"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-57803",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Select-Themes",
      "product": "Struktur Core",
      "cwe": "CWE-98",
      "title": "WordPress Struktur Core plugin < 2.7 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57803"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-57804",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodexThemes",
      "product": "TheGem Theme Elements (for Elementor)",
      "cwe": "CWE-98",
      "title": "WordPress TheGem Theme Elements (for Elementor) plugin < 5.12.1.1 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57804"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-61463",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00368,
      "epss_percentile": 0.30055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-shiori",
      "product": "shiori",
      "cwe": "CWE-269",
      "title": "Shiori Authenticated Privilege Escalation via PATCH /api/v1/auth/account",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61463"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-59245",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.29211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow FAB provider",
      "cwe": "CWE-269",
      "title": "Apache Airflow FAB provider: FAB auth manager: a DAG named \"DAGs\" hijacks the global all-DAGs permission (access_control privilege escalation via resource_name() collision)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59245"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-58487",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00358,
      "epss_percentile": 0.29063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hedgedoc",
      "product": "hedgedoc",
      "cwe": "CWE-79",
      "title": "HedgeDoc: Stored HTML injection via email local-part",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58487"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-57433",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00357,
      "epss_percentile": 0.2895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HAARG",
      "product": "Storable",
      "cwe": "CWE-190",
      "title": "Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57433"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-57719",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00347,
      "epss_percentile": 0.27912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeRevolution",
      "product": "Aimogen Pro",
      "cwe": "CWE-434",
      "title": "WordPress Aimogen Pro plugin <= 2.8.3 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57719"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-58411",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ChurchCRM",
      "product": "CRM",
      "cwe": "CWE-79",
      "title": "ChurchCRM has Reflected Cross-Site Scripting (XSS) via unsanitized request parameter names and values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58411"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-15596",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00347,
      "epss_percentile": 0.27888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-79",
      "title": "SourceCodester Class and Exam Timetabling System subject.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15596"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-55771",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cedar-policy",
      "product": "cedar-java",
      "cwe": "CWE-94",
      "title": "CedarJava has policy injection, type confusion, and incorrect equality comparison vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55771"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-57371",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "denishua",
      "product": "WPJAM Basic",
      "cwe": "CWE-502",
      "title": "WordPress WPJAM Basic plugin <= 7.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57371"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-51539",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.2747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "A Denial of Service (DoS) vulnerability exists in the receive loop of libmodbus 3.1.12 when running on Windows. The issue stems from improper timeout management during network read operations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51539"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-61503",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rejetto",
      "product": "hfs",
      "cwe": "CWE-204",
      "title": "Rejetto HFS < 3.2.1 Username Enumeration via Login Response Differences",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61503"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-15597",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System edit_exam2.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15597"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-57815",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.25533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPMU DEV - Your All-in-One WordPress Platform",
      "product": "Forminator",
      "cwe": "CWE-22",
      "title": "WordPress Forminator plugin <= 1.55.0.2 - Arbitrary File Download vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57815"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-57710",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00319,
      "epss_percentile": 0.24759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quantumcloud",
      "product": "WoowBot Pro Max",
      "cwe": "CWE-434",
      "title": "WordPress WoowBot Pro Max plugin <= 14.1.7 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57710"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-57697",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Metagauss",
      "product": "ProfileGrid",
      "cwe": "CWE-288",
      "title": "WordPress ProfileGrid plugin <= 5.9.9.6 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57697"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-15541",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "will-moss",
      "product": "Isaiah",
      "cwe": "CWE-862",
      "title": "will-moss Isaiah Master Websocket server.go Server.Handle authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15541"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-22102",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00314,
      "epss_percentile": 0.24194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EVbee",
      "product": "DC-80",
      "cwe": "CWE-20",
      "title": "Arbitrary file overwrite through certificate update functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22102"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-62240",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.24258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "crewAIInc",
      "product": "crewAI",
      "cwe": "CWE-918",
      "title": "CrewAI < 1.15.1 SSRF Filter Bypass via HTTP Redirect in Scrape Tools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62240"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-15598",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.2413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "antv",
      "product": "layout",
      "cwe": "CWE-94",
      "title": "antv layout object.js setNestedValue prototype pollution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15598"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-22096",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00312,
      "epss_percentile": 0.24027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EVbee",
      "product": "DC-80",
      "cwe": "CWE-306",
      "title": "Missing authentication for webserver endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22096"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-57811",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00311,
      "epss_percentile": 0.23865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Realtyna",
      "product": "Realtyna Organic IDX plugin",
      "cwe": "CWE-94",
      "title": "WordPress Realtyna Organic IDX plugin plugin <= 5.2.0 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57811"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-15530",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00311,
      "epss_percentile": 0.23923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "WuzhiCMS",
      "cwe": "CWE-200",
      "title": "WuzhiCMS Attachment API index.php listimage information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15530"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-57713",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Marcus (aka @msykes)",
      "product": "Events Manager",
      "cwe": "CWE-502",
      "title": "WordPress Events Manager plugin <= 7.3.6 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57713"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-61501",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rejetto",
      "product": "hfs",
      "cwe": "CWE-79",
      "title": "Rejetto HFS < 3.2.1 Stored XSS in Admin Log Viewer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61501"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-57744",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00304,
      "epss_percentile": 0.23127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stmcan",
      "product": "RT-Theme 18 | Extensions",
      "cwe": "CWE-502",
      "title": "WordPress RT-Theme 18 | Extensions plugin <= 2.5 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57744"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-57770",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00304,
      "epss_percentile": 0.23126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeGoods",
      "product": "Grand Photography",
      "cwe": "CWE-502",
      "title": "WordPress Grand Photography theme <= 5.7.8 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57770"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-59518",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00304,
      "epss_percentile": 0.23127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpWax",
      "product": "Directorist",
      "cwe": "CWE-502",
      "title": "WordPress Directorist plugin <= 8.8.2 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59518"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-61458",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pglombardo",
      "product": "PasswordPusher",
      "cwe": "CWE-307",
      "title": "PasswordPusher < 2.9.2 Passphrase Brute-Force via Unthrottled Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61458"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-57830",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "Helix Ultimate extension for Joomla",
      "cwe": "CWE-862",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57830"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-57805",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Select-Themes",
      "product": "Tonda",
      "cwe": "CWE-98",
      "title": "WordPress Tonda theme <= 2.5 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57805"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-15594",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00298,
      "epss_percentile": 0.22445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "waooAI",
      "product": "waoowaoo",
      "cwe": "CWE-266",
      "title": "waooAI waoowaoo Media hash.ts stablePublicIdFromStorageKey improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15594"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-62199",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-184",
      "title": "OpenClaw < 2026.6.6 Authentication Bypass via Environment Filtering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62199"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-62200",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-184",
      "title": "OpenClaw < 2026.6.6 Authentication Bypass via Git ext transport",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62200"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-58488",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hedgedoc",
      "product": "hedgedoc",
      "cwe": "CWE-290",
      "title": "HedgeDoc: Rate-limit bypass via CF-Connecting-IP header spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58488"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-55773",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.22042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cedar-policy",
      "product": "cedar-java",
      "cwe": "CWE-94",
      "title": "CedarJava has a policy injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55773"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-57774",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vowelweb",
      "product": "VW Food Corner",
      "cwe": "CWE-862",
      "title": "WordPress VW Food Corner theme <= 1.1.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57774"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-57776",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vowelweb",
      "product": "VW Wedding",
      "cwe": "CWE-862",
      "title": "WordPress VW Wedding theme <= 1.3.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57776"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-59521",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ShapedPlugin LLC",
      "product": "Real Testimonials",
      "cwe": "CWE-502",
      "title": "WordPress Real Testimonials plugin <= 3.1.15 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59521"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-40553",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "gawk",
      "cwe": "CWE-121",
      "title": "Stack-based buffer overflow in gawk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40553"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-57727",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeum",
      "product": "Kirki",
      "cwe": "CWE-862",
      "title": "WordPress Kirki plugin <= 6.0.13 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57727"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-62190",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.21095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-706",
      "title": "OpenClaw < 2026.6.9 Authorization Bypass via flock wrapper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62190"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-62185",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.20954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "argoproj",
      "product": "argo-helm",
      "cwe": "CWE-1188",
      "title": "Argo CD Helm Chart < 10.0.0 Missing Network Policy RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62185"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-57702",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Melograno Venture Studio",
      "product": "Amelia",
      "cwe": "CWE-89",
      "title": "WordPress Amelia plugin <= 2.4.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57702"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-57707",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20874,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quantumcloud",
      "product": "Simple Business Directory Pro",
      "cwe": "CWE-89",
      "title": "WordPress Simple Business Directory Pro plugin <= 15.9.4 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57707"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-57714",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LatePoint",
      "product": "LatePoint",
      "cwe": "CWE-89",
      "title": "WordPress LatePoint plugin <= 5.6.3 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57714"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-57726",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20869,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeum",
      "product": "Kirki",
      "cwe": "CWE-89",
      "title": "WordPress Kirki plugin <= 6.0.12 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57726"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-57739",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcyMailing Newsletter Team",
      "product": "AcyMailing SMTP Newsletter",
      "cwe": "CWE-89",
      "title": "WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57739"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-57855",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cockpit HQ",
      "product": "Cockpit CMS",
      "cwe": "CWE-284",
      "title": "Cockpit CMS Missing Authorization in Bucket File Storage API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57855"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-62242",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codecentric",
      "product": "spring-boot-admin",
      "cwe": "CWE-918",
      "title": "Spring Boot Admin Server < 4.1.2 SSRF via Unauthenticated Instance Registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62242"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-57386",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.2029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kodezen LLC",
      "product": "aBlocks",
      "cwe": "CWE-266",
      "title": "WordPress aBlocks plugin < 2.9.1 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57386"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-57410",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MailerPress Team",
      "product": "MailerPress",
      "cwe": "CWE-266",
      "title": "WordPress MailerPress plugin <= 2.0.2 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57410"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-57729",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UX-themes",
      "product": "Flatsome",
      "cwe": "CWE-862",
      "title": "WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57729"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-15595",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00278,
      "epss_percentile": 0.20382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-79",
      "title": "SourceCodester Class and Exam Timetabling System forsubject.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15595"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-58500",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "appium",
      "product": "appium-mcp",
      "cwe": "CWE-79",
      "title": "MCP Appium: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58500"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-11964",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00275,
      "epss_percentile": 0.20019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Registration & Membership",
      "cwe": null,
      "title": "User Registration & Membership < 5.2.2 - Unauthenticated PayPal Webhook Signature Verification Bypass Leading to Membership Activation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11964"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-15516",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00274,
      "epss_percentile": 0.19892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "MacCMS Pro",
      "cwe": "CWE-285",
      "title": "MacCMS Pro Installation Index.php step5 authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15516"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-55772",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cedar-policy",
      "product": "cedar-java",
      "cwe": "CWE-843",
      "title": "CedarJava has a type confusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55772"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-4765",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.1969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RD Station Conversas",
      "product": "Tallos Chat",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) in Tallos Chat by RD Station Conversas",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4765"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-57773",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.19377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zorem",
      "product": "Advanced Shipment Tracking for WooCommerce",
      "cwe": "CWE-89",
      "title": "WordPress Advanced Shipment Tracking for WooCommerce plugin <= 4.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57773"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-57393",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EDGARROJAS",
      "product": "WooCommerce PDF Invoice Builder",
      "cwe": "CWE-497",
      "title": "WordPress WooCommerce PDF Invoice Builder plugin <= 2.0.8 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57393"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-15537",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Book Store System",
      "cwe": "CWE-74",
      "title": "SourceCodester Online Book Store System login.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15537"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-12582",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Library Management System",
      "cwe": null,
      "title": "Library Management System < 3.5.8 - Unauthenticated SQL Injection via book_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12582"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-57813",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00261,
      "epss_percentile": 0.1798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "properfraction",
      "product": "MailOptin",
      "cwe": "CWE-266",
      "title": "WordPress MailOptin plugin <= 1.2.77.3 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57813"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-15680",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lorex",
      "product": "2K Indoor Wi-Fi Security Camera",
      "cwe": "CWE-134",
      "title": "Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15680"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-15574",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI (RHOAI)",
      "cwe": "CWE-538",
      "title": "Vllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header and full chat payloads logged at hard-coded debug default",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15574"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-15529",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.1764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yzhao062",
      "product": "pyod",
      "cwe": "CWE-20",
      "title": "yzhao062 pyod persistence.py pyod.utils.persistence.load deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15529"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-15538",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "primefaces",
      "product": "primereact",
      "cwe": "CWE-94",
      "title": "primefaces primereact API ObjectUtils.mutateFieldData prototype pollution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15538"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-15517",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jinher",
      "product": "OA",
      "cwe": "CWE-74",
      "title": "Jinher OA PlanGiveOut.aspx sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15517"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-15607",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00254,
      "epss_percentile": 0.17116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tanstack",
      "product": "db",
      "cwe": "CWE-94",
      "title": "tanstack db Alias Path select.ts select prototype pollution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15607"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-22098",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00253,
      "epss_percentile": 0.16989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EVbee",
      "product": "DC-80",
      "cwe": "CWE-532",
      "title": "Sensitive information is written to logs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22098"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-57385",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.16984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "appsbd",
      "product": "Vitepos",
      "cwe": "CWE-89",
      "title": "WordPress Vitepos plugin <= 3.4.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57385"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-57771",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.16982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Milan Petrovic",
      "product": "GD Rating System",
      "cwe": "CWE-89",
      "title": "WordPress GD Rating System plugin <= 3.7 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57771"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-57772",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.16984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Inventory",
      "product": "WP Inventory Manager",
      "cwe": "CWE-89",
      "title": "WordPress WP Inventory Manager plugin <= 2.4.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57772"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-57787",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.16982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CreativeWS",
      "product": "CWS SVGicons",
      "cwe": "CWE-89",
      "title": "WordPress CWS SVGicons plugin <= 1.5.5 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57787"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-62194",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.16796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-732",
      "title": "OpenClaw 2026.5.20 < 2026.6.9 Privilege Escalation via Plugin Install",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62194"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-15553",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ragic",
      "product": "Enterprise Cloud Database",
      "cwe": "CWE-434",
      "title": "Ragic｜Enterprise Cloud Database - Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15553"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-14846",
      "cvss_base": 4.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PrestaShop",
      "product": "The firmware",
      "cwe": "CWE-1236",
      "title": "Incorrect neutralisation in the PrestaShop firmware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14846"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-57364",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.16399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPDeveloper",
      "product": "Better Payment – Instant Payments, Donations, Fundraising with Subscriptions &amp; More",
      "cwe": "CWE-1284",
      "title": "WordPress Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More plugin <= 2.2.0 - Other Vulnerability Type vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57364"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-57395",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.1638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themefic",
      "product": "Tourfic",
      "cwe": "CWE-862",
      "title": "WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57395"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-57418",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.1638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BoldGrid",
      "product": "Client Invoicing by Sprout Invoices",
      "cwe": "CWE-862",
      "title": "WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.13 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57418"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-15518",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00248,
      "epss_percentile": 0.16434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AREA 17",
      "product": "Twill CMS",
      "cwe": "CWE-284",
      "title": "AREA 17 Twill CMS Media Library Insert FileLibraryController.php storeFile unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15518"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-15533",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00248,
      "epss_percentile": 0.16444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "DedeCMS",
      "cwe": "CWE-74",
      "title": "DedeCMS Column Management search.php code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15533"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-15535",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00247,
      "epss_percentile": 0.16252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AkariAsai",
      "product": "self-rag",
      "cwe": "CWE-20",
      "title": "AkariAsai self-rag retrieval_lm index.py Indexer.deserialize_from deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15535"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-62189",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-59",
      "title": "OpenClaw < 2026.6.9 Symlink Following via Mirror Sync",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62189"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-14165",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dassault Systèmes",
      "product": "Tuleap Enterprise Edition",
      "cwe": "CWE-639",
      "title": "Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14165"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-15584",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Pen Drive Powered by Red Hat Lightspeed",
      "cwe": "CWE-250",
      "title": "Redhatinsights/incluster-checks: incluster-checks: privileged host-chroot debug pods created in shared default namespace enable privilege escalation to node root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15584"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-57698",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.15966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VillaTheme",
      "product": "Abandoned Cart Recovery for WooCommerce",
      "cwe": "CWE-288",
      "title": "WordPress Abandoned Cart Recovery for WooCommerce plugin <= 1.1.12 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57698"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-59515",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00243,
      "epss_percentile": 0.15715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sergey",
      "product": "AIWU",
      "cwe": "CWE-89",
      "title": "WordPress AIWU plugin <= 1.5.4 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59515"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-57377",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPXPO",
      "product": "WowAddons",
      "cwe": "CWE-862",
      "title": "WordPress WowAddons plugin <= 1.6.8 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57377"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-57390",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EDGARROJAS",
      "product": "Extra Product Options Builder for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Extra Product Options Builder for WooCommerce plugin <= 1.2.167 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57390"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-57392",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themefic",
      "product": "Tourfic",
      "cwe": "CWE-862",
      "title": "WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57392"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-57404",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "magepeopleteam",
      "product": "Booking and Rental Manager",
      "cwe": "CWE-862",
      "title": "WordPress Booking and Rental Manager plugin <= 2.6.9 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57404"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-57408",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "peachpayments",
      "product": "Peach Payments Gateway",
      "cwe": "CWE-862",
      "title": "WordPress Peach Payments Gateway plugin <= 4.0.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57408"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-57412",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Codemenschen",
      "product": "Gift Vouchers",
      "cwe": "CWE-862",
      "title": "WordPress Gift Vouchers plugin <= 4.6.9 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57412"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-57424",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "knitpay",
      "product": "Razorpay Payment Links for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Razorpay Payment Links for WooCommerce plugin <= 2.1.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57424"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-12385",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextendweb",
      "product": "Smart Slider 3",
      "cwe": "CWE-200",
      "title": "Smart Slider 3 <= 3.5.1.37 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via WP_Query Parameter Injection via 'keyword' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12385"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-15540",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00242,
      "epss_percentile": 0.15631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Book Store System",
      "cwe": "CWE-73",
      "title": "SourceCodester Online Book Store System Administrative index.php php file inclusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15540"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-49969",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "plank",
      "product": "laravel-mediable",
      "cwe": "CWE-918",
      "title": "Laravel-Mediable < 7.0.0 SSRF via RemoteUrlAdapter URL Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49969"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-6850",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-1333",
      "title": "Crafted message attachment causes client-side denial of service via markdown parser regex backtracking in Mattermost",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6850"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-57797",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeMove",
      "product": "EduMall",
      "cwe": "CWE-862",
      "title": "WordPress EduMall theme <= 4.5.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57797"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-15618",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0024,
      "epss_percentile": 0.15314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mosaxiv",
      "product": "clawlet",
      "cwe": "CWE-693",
      "title": "mosaxiv clawlet exec Safety Guard tool_exec.go guardExecCommand protection mechanism",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15618"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-62143",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp-modules",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery protection bypass in misp-modules html_to_markdown via IPv4-mapped IPv6 addresses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62143"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-57378",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phil Kurth",
      "product": "Advanced Forms",
      "cwe": "CWE-862",
      "title": "WordPress Advanced Forms plugin <= 1.9.3.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57378"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-57705",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "Event Tickets",
      "cwe": "CWE-862",
      "title": "WordPress Event Tickets plugin <= 5.28.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57705"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-15519",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00238,
      "epss_percentile": 0.15143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "usestrix",
      "product": "strix",
      "cwe": "CWE-829",
      "title": "usestrix PyPI system_prompt.jinja inclusion of functionality from untrusted control sphere",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15519"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-57694",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.1502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeum",
      "product": "Tutor LMS",
      "cwe": "CWE-639",
      "title": "WordPress Tutor LMS plugin <= 3.9.13 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57694"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-58486",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hedgedoc",
      "product": "hedgedoc",
      "cwe": "CWE-400",
      "title": "HedgeDoc: Denial-of-service via YAML alias expansion in note frontmatter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58486"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-57400",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Swings",
      "product": "Event Tickets Manager for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Event Tickets Manager for WooCommerce plugin <= 1.5.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57400"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-57406",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roxnor",
      "product": "FundEngine",
      "cwe": "CWE-862",
      "title": "WordPress FundEngine plugin <= 1.7.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57406"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-62192",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00233,
      "epss_percentile": 0.14441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62192"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-62195",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-732",
      "title": "OpenClaw 2026.5.20 < 2026.6.6 Authorization Bypass via MCP loopback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62195"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-62196",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw 2026.3.22 < 2026.6.6 Authorization Bypass via WhatsApp Group IDs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62196"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-15539",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00227,
      "epss_percentile": 0.13672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Book Store System",
      "cwe": "CWE-284",
      "title": "SourceCodester Online Book Store System Book Image Upload Feature index.php books unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15539"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-14934",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00226,
      "epss_percentile": 0.13591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google Cloud",
      "product": "BigQuery",
      "cwe": "CWE-862",
      "title": "Cross-Tenant Repository Takeover via Improper Access Control in BigQuery, Dataform and Colab Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14934"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-61955",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13587,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hannan",
      "product": "گرویتی فرم فارسی",
      "cwe": "CWE-89",
      "title": "WordPress گرویتی فرم فارسی plugin <= 3.0.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61955"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-57405",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13544,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themehunk",
      "product": "Open Shop",
      "cwe": "CWE-862",
      "title": "WordPress Open Shop theme <= 1.7.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57405"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-57740",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13544,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcyMailing Newsletter Team",
      "product": "AcyMailing SMTP Newsletter",
      "cwe": "CWE-862",
      "title": "WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57740"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-57768",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "favethemes",
      "product": "Houzez Login Register",
      "cwe": "CWE-266",
      "title": "WordPress Houzez Login Register plugin <= 3.3.3 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57768"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-58408",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ChurchCRM",
      "product": "CRM",
      "cwe": "CWE-862",
      "title": "ChurchCRM : Broken Access Control in `CSVCreateFile.php` Allows Low-Privileged Users to Export All Members' PII",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58408"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-58102",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00214,
      "epss_percentile": 0.12025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JONASBN",
      "product": "Crypt::OpenSSL::X509",
      "cwe": "CWE-125",
      "title": "Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58102"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-15525",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00214,
      "epss_percentile": 0.12114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kLOsk",
      "product": "adloop",
      "cwe": "CWE-918",
      "title": "kLOsk adloop write.py _validate_urls server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15525"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-62187",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.11894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openclaw",
      "product": "feishu",
      "cwe": "CWE-863",
      "title": "OpenClaw < 2026.6.9 Feishu tools Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62187"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-62188",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.11894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openclaw",
      "product": "feishu",
      "cwe": "CWE-863",
      "title": "OpenClaw < 2026.6.9 Feishu Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62188"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-40467",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "gawk",
      "cwe": "CWE-416",
      "title": "Use after free in gawk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40467"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-40469",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "gawk",
      "cwe": "CWE-190",
      "title": "Heap buffer overflow in gawk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40469"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-57419",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.1183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fahad Mahmood",
      "product": "Stock Locations for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Stock Locations for WooCommerce plugin <= 3.1.8 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57419"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-57432",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SHAY",
      "product": "perl",
      "cwe": "CWE-125",
      "title": "Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57432"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-9708",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-639",
      "title": "Incoming webhook user attribution via unvalidated webhook owner",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9708"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-15532",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0021,
      "epss_percentile": 0.1152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Online Book Store System",
      "cwe": "CWE-79",
      "title": "SourceCodester Online Book Store System User Management cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15532"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-62147",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift distributed tracing 3",
      "cwe": "CWE-863",
      "title": "Tempo-operator: tempo operator: query rbac bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62147"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-22097",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00208,
      "epss_percentile": 0.11252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EVbee",
      "product": "DC-80",
      "cwe": "CWE-347",
      "title": "Missing firmware validation allows remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22097"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-57778",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevart",
      "product": "Booking calendar, Appointment Booking System",
      "cwe": "CWE-862",
      "title": "WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57778"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-57779",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themebeez",
      "product": "Fascinate",
      "cwe": "CWE-862",
      "title": "WordPress Fascinate theme <= 1.1.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57779"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-57781",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.1123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sovlix",
      "product": "MeetingHub",
      "cwe": "CWE-862",
      "title": "WordPress MeetingHub plugin <= 1.25.10 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57781"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-57782",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PressTigers",
      "product": "Universal Clocks",
      "cwe": "CWE-862",
      "title": "WordPress Universal Clocks plugin <= 1.2.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57782"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-62191",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.1114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-862",
      "title": "OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass via Message Mutations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62191"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-57810",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saad Iqbal",
      "product": "APIExperts Square for WooCommerce",
      "cwe": "CWE-89",
      "title": "WordPress APIExperts Square for WooCommerce plugin <= 4.7.4 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57810"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-15552",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ragic",
      "product": "Enterprise Cloud Database",
      "cwe": "CWE-79",
      "title": "Ragic｜Enterprise Cloud Database - Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15552"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-58101",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.1075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JONASBN",
      "product": "Crypt::OpenSSL::X509",
      "cwe": "CWE-476",
      "title": "Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58101"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-49971",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "plank",
      "product": "laravel-mediable",
      "cwe": "CWE-79",
      "title": "Laravel-Mediable < 7.0.0 Stored XSS via SVG File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49971"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-11963",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00201,
      "epss_percentile": 0.10305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Registration & Membership",
      "cwe": null,
      "title": "User Registration & Membership < 5.2.2 - Subscriber+ Cross-User Role and Membership Tier Modification via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11963"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-40468",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00201,
      "epss_percentile": 0.10321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "gawk",
      "cwe": "CWE-190",
      "title": "Heap buffer overflow in gawk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40468"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2025-45869",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.002,
      "epss_percentile": 0.1018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-918",
      "title": "LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can exploit the ShareFileCallback servlet by manipulating input parameters to trigger a server-side request to an attacker-controlled host.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-45869"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-15523",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Simple Online Leave Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Simple Online Leave Management System dashboard.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15523"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-15536",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System patviewprescription.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15536"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-15558",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Simple Online Leave Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Simple Online Leave Management System deletemp.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15558"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-15559",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Simple Online Leave Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Simple Online Leave Management System POST accept.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15559"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-62197",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-918",
      "title": "OpenClaw < 2026.6.6 Policy Bypass via CDP Discovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62197"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-61975",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock",
      "product": "JetReviews",
      "cwe": "CWE-497",
      "title": "WordPress JetReviews plugin <= 3.0.1 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61975"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-61976",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock",
      "product": "JetBlocks For Elementor",
      "cwe": "CWE-497",
      "title": "WordPress JetBlocks For Elementor plugin <= 1.5.0 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61976"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-61977",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock",
      "product": "JetSearch",
      "cwe": "CWE-497",
      "title": "WordPress JetSearch plugin <= 3.6.1.2 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61977"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-57375",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FluxBuilder",
      "product": "MStore API",
      "cwe": "CWE-862",
      "title": "WordPress MStore API plugin <= 4.18.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57375"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-61952",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jose Vega",
      "product": "WooCommerce Bulk Edit Products – WP Sheet Editor",
      "cwe": "CWE-862",
      "title": "WordPress WooCommerce Bulk Edit Products – WP Sheet Editor plugin <= 1.8.21 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61952"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-62186",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00192,
      "epss_percentile": 0.09204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-862",
      "title": "OpenClaw < 2026.6.8 Authorization Bypass via HTTP Model Override",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62186"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-61971",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00192,
      "epss_percentile": 0.09238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cozmoslabs",
      "product": "User Profile Picture",
      "cwe": "CWE-639",
      "title": "WordPress User Profile Picture plugin <= 2.6.3 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61971"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-57812",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.0908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NSquared",
      "product": "Simply Schedule Appointments",
      "cwe": "CWE-862",
      "title": "WordPress Simply Schedule Appointments plugin <= 1.6.12.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57812"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-22099",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00188,
      "epss_percentile": 0.08759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EVbee",
      "product": "DC-80",
      "cwe": "CWE-287",
      "title": "Missing authentication for Bluetooth communication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22099"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-57372",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00188,
      "epss_percentile": 0.08797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "denishua",
      "product": "WPJAM Basic",
      "cwe": "CWE-918",
      "title": "WordPress WPJAM Basic plugin <= 7.0 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57372"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-57407",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00188,
      "epss_percentile": 0.08798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Swings",
      "product": "PDF Generator for WordPress",
      "cwe": "CWE-918",
      "title": "WordPress PDF Generator for WordPress plugin <= 1.6.2 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57407"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-62193",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw 2026.6.5 < 2026.6.9 Authentication Bypass via Plugin Install",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62193"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-12274",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Tutor LMS",
      "cwe": null,
      "title": "Tutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12274"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-57829",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.08161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "Helix Ultimate extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57829"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-61502",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rejetto",
      "product": "hfs",
      "cwe": "CWE-352",
      "title": "Rejetto HFS < 3.2.1 Cross-Site Request Forgery via GET Requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61502"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-57368",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NooTheme",
      "product": "Jobmonster",
      "cwe": "CWE-79",
      "title": "WordPress Jobmonster theme <= 4.8.5 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57368"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-57421",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CRM Perks",
      "product": "CRM Perks Forms",
      "cwe": "CWE-79",
      "title": "WordPress CRM Perks Forms plugin <= 1.1.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57421"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-57733",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tagDiv",
      "product": "tagDiv Cloud Library",
      "cwe": "CWE-79",
      "title": "WordPress tagDiv Cloud Library plugin <= 3.9.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57733"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-57695",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00178,
      "epss_percentile": 0.0769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dan Rossiter",
      "product": "Document Gallery",
      "cwe": "CWE-79",
      "title": "WordPress Document Gallery plugin <= 5.1.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57695"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-14906",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox for iOS",
      "cwe": "CWE-434",
      "title": "Malicious webpage titles could allow overwriting of bundled PDF resources when saving webpages as PDFs in Firefox for iOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14906"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-61983",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.0743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "andy_moyle",
      "product": "Church Admin",
      "cwe": "CWE-862",
      "title": "WordPress Church Admin plugin <= 5.0.30 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61983"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-61985",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.0743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "magepeopleteam",
      "product": "Car Rental Manager",
      "cwe": "CWE-862",
      "title": "WordPress Car Rental Manager plugin <= 1.3.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61985"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-57363",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuantumCloud",
      "product": "ChatBot",
      "cwe": "CWE-79",
      "title": "WordPress ChatBot plugin <= 8.3.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57363"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-57369",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themifyme",
      "product": "Themify Builder",
      "cwe": "CWE-79",
      "title": "WordPress Themify Builder plugin <= 7.7.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57369"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-57376",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Element Invader",
      "product": "ElementInvader Addons for Elementor",
      "cwe": "CWE-79",
      "title": "WordPress ElementInvader Addons for Elementor plugin <= 1.4.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57376"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-57379",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPPOOL",
      "product": "FormyChat",
      "cwe": "CWE-79",
      "title": "WordPress FormyChat plugin <= 2.15.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57379"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-57380",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hupe13",
      "product": "Extensions for Leaflet Map",
      "cwe": "CWE-79",
      "title": "WordPress Extensions for Leaflet Map plugin <= 5.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57380"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-57381",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Property Hive",
      "product": "PropertyHive",
      "cwe": "CWE-79",
      "title": "WordPress PropertyHive plugin <= 2.2.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57381"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-57382",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mitchell Bennis",
      "product": "Simple File List",
      "cwe": "CWE-79",
      "title": "WordPress Simple File List plugin <= 6.3.8 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57382"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-57383",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eyecix",
      "product": "JobSearch",
      "cwe": "CWE-79",
      "title": "WordPress JobSearch plugin <= 3.2.9 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57383"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-57387",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picu",
      "product": "picu",
      "cwe": "CWE-79",
      "title": "WordPress picu plugin <= 3.5.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57387"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-57388",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themefic",
      "product": "Hydra Booking",
      "cwe": "CWE-79",
      "title": "WordPress Hydra Booking plugin <= 1.1.44 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57388"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-57394",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tribulant Software",
      "product": "Newsletters",
      "cwe": "CWE-79",
      "title": "WordPress Newsletters plugin <= 4.14 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57394"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-57396",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flintop",
      "product": "Free Gifts for WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Free Gifts for WooCommerce plugin <= 13.1.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57396"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-57398",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebCodingPlace",
      "product": "Real Estate Manager Pro",
      "cwe": "CWE-79",
      "title": "WordPress Real Estate Manager Pro plugin <= 12.8.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57398"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-57399",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Proxy &amp; VPN Blocker",
      "product": "Proxy &amp; VPN Blocker",
      "cwe": "CWE-79",
      "title": "WordPress Proxy & VPN Blocker plugin <= 3.5.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57399"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-57403",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Milan Petrovic",
      "product": "GD Security Headers",
      "cwe": "CWE-79",
      "title": "WordPress GD Security Headers plugin <= 1.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57403"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-57409",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RealMag777",
      "product": "Active Products Tables for WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Active Products Tables for WooCommerce plugin <= 1.1.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57409"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-57411",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aman",
      "product": "CF7 Views &#8211; Complete Entry Management for Contact Form 7",
      "cwe": "CWE-79",
      "title": "WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin <= 3.2.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57411"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-57415",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Codemenschen",
      "product": "Gift Vouchers",
      "cwe": "CWE-79",
      "title": "WordPress Gift Vouchers plugin <= 4.7.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57415"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-57416",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SiteGround",
      "product": "SiteGround Email Marketing",
      "cwe": "CWE-79",
      "title": "WordPress SiteGround Email Marketing plugin <= 1.7.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57416"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-57417",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RexTheme",
      "product": "Cart Lift",
      "cwe": "CWE-79",
      "title": "WordPress Cart Lift plugin <= 3.1.57 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57417"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-57422",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VillaTheme",
      "product": "Bopo – WooCommerce Product Bundle Builder",
      "cwe": "CWE-79",
      "title": "WordPress Bopo – WooCommerce Product Bundle Builder plugin <= 1.2.0 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57422"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-57423",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kofi Mokome",
      "product": "Message Filter for Contact Form 7",
      "cwe": "CWE-79",
      "title": "WordPress Message Filter for Contact Form 7 plugin <= 1.6.3.8 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57423"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-57668",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Basix",
      "product": "NEX-Forms",
      "cwe": "CWE-79",
      "title": "WordPress NEX-Forms plugin <= 9.2.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57668"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-57706",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokan, Inc.",
      "product": "Dokan",
      "cwe": "CWE-79",
      "title": "WordPress Dokan plugin <= 5.0.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57706"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-57708",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CRM Perks",
      "product": "Contact Form Entries",
      "cwe": "CWE-79",
      "title": "WordPress Contact Form Entries plugin <= 1.5.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57708"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-57712",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPZOOM",
      "product": "WPZOOM Portfolio",
      "cwe": "CWE-79",
      "title": "WordPress WPZOOM Portfolio plugin <= 1.4.29 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57712"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-57715",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPManageNinja",
      "product": "Fluent CRM",
      "cwe": "CWE-79",
      "title": "WordPress Fluent CRM plugin <= 3.1.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57715"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-57718",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unlimited Elements",
      "product": "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)",
      "cwe": "CWE-79",
      "title": "WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.12 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57718"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-57725",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeum",
      "product": "Kirki",
      "cwe": "CWE-79",
      "title": "WordPress Kirki plugin <= 6.0.11 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57725"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-57728",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UX-themes",
      "product": "Flatsome",
      "cwe": "CWE-79",
      "title": "WordPress Flatsome theme <= 3.20.5 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57728"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-57732",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tagDiv",
      "product": "tagDiv Opt-In Builder",
      "cwe": "CWE-79",
      "title": "WordPress tagDiv Opt-In Builder plugin <= 1.7.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57732"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-57734",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tagDiv",
      "product": "tagDiv Composer",
      "cwe": "CWE-79",
      "title": "WordPress tagDiv Composer plugin <= 5.4.3 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57734"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-57741",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcyMailing Newsletter Team",
      "product": "AcyMailing SMTP Newsletter",
      "cwe": "CWE-79",
      "title": "WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57741"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-57745",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stmcan",
      "product": "RT-Theme 18 | Extensions",
      "cwe": "CWE-79",
      "title": "WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57745"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-10106",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-863",
      "title": "Unauthorized users can trigger interactive post actions in private channels via action cookie channel mismatch in Mattermost",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10106"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-58410",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.07235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ChurchCRM",
      "product": "CRM",
      "cwe": "CWE-639",
      "title": "ChurchCRM: Improper object-level authorization allows low-privileged users to read and modify other families’ records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58410"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-9571",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07195,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-305",
      "title": "Deactivated user accounts can continue to obtain valid OAuth access tokens via refresh token grant in Mattermost",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9571"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-61504",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.07049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rejetto",
      "product": "hfs",
      "cwe": "CWE-79",
      "title": "Rejetto HFS < 3.2.1 Stored XSS via File Names in Basic Web Listing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61504"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-12275",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.06864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Tutor LMS",
      "cwe": null,
      "title": "Tutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private Course Content Disclosure via Droip/Kirki Integration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12275"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-10085",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-862",
      "title": "Ordinary group/direct message member can enable group_constrained and remove all channel participants",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10085"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-12271",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Tutor LMS",
      "cwe": null,
      "title": "Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12271"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-12396",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Job Portal",
      "cwe": null,
      "title": "WP Job Portal < 2.5.5 - Subscriber+ Arbitrary Job Approval, Featuring and Rejection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12396"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-61958",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saad Iqbal",
      "product": "License Manager for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress License Manager for WooCommerce plugin <= 3.0.17 - Arbitrary Content Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61958"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-61968",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saad Iqbal",
      "product": "myCred",
      "cwe": "CWE-862",
      "title": "WordPress myCred plugin <= 3.1.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61968"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-12273",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Tutor LMS",
      "cwe": null,
      "title": "Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Auto-Approved Comment Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12273"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-12536",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themefusion",
      "product": "Avada (Fusion) Builder",
      "cwe": "CWE-79",
      "title": "Avada Builder <= 3.15.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Module Title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12536"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-57786",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "purethemes",
      "product": "WorkScout-Core",
      "cwe": "CWE-352",
      "title": "WordPress WorkScout-Core plugin <= 1.7.08 - Cross Site Request Forgery (CSRF) to Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57786"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-57391",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tangible",
      "product": "Loops & Logic",
      "cwe": "CWE-79",
      "title": "WordPress Loops & Logic plugin <= 4.2.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57391"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-57413",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bdthemes",
      "product": "Instant Image Generator",
      "cwe": "CWE-918",
      "title": "WordPress Instant Image Generator plugin <= 2.1.4 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57413"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-9824",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-862",
      "title": "Remote cluster metadata enumeration via /share-channel autocomplete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9824"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-12397",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Job Portal",
      "cwe": null,
      "title": "WP Job Portal < 2.5.5 - Subscriber+ Employer Email Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12397"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-22093",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0016,
      "epss_percentile": 0.05739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EVbee",
      "product": "EVbee Service",
      "cwe": "CWE-295",
      "title": "Adversary-in-the-Middle (AitM) attack vulnerability in EVbee Service app",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22093"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-62198",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw 2026.5.28 < 2026.6.6 Authorization Bypass via Web Search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62198"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-48363",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00158,
      "epss_percentile": 0.05524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion",
      "cwe": "CWE-427",
      "title": "ColdFusion | Uncontrolled Search Path Element (CWE-427)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48363"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-48364",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00158,
      "epss_percentile": 0.05525,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion",
      "cwe": "CWE-427",
      "title": "ColdFusion | Uncontrolled Search Path Element (CWE-427)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48364"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-57365",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitesh Chandwani",
      "product": "reCAPTCHA (v2 &amp; v3) for Asgaros Forum",
      "cwe": "CWE-79",
      "title": "WordPress reCAPTCHA (v2 & v3) for Asgaros Forum plugin <= 1.1.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57365"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-57402",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdesk",
      "product": "Flexible Refund and Return Order for WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Flexible Refund and Return Order for WooCommerce plugin <= 1.0.51 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57402"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-57414",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuantumCloud",
      "product": "ChatBot for eCommerce &#8211; WoowBot",
      "cwe": "CWE-79",
      "title": "WordPress ChatBot for eCommerce – WoowBot plugin <= 4.6.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57414"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-57420",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netrr",
      "product": "Author Box WP Lens",
      "cwe": "CWE-79",
      "title": "WordPress Author Box WP Lens plugin <= 2.1.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57420"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-57693",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spacetime",
      "product": "Ad Inserter",
      "cwe": "CWE-79",
      "title": "WordPress Ad Inserter plugin <= 2.8.11 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57693"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-57711",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.0531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PSM Plugins",
      "product": "SupportCandy",
      "cwe": "CWE-79",
      "title": "WordPress SupportCandy plugin <= 3.4.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57711"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-57780",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05312,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Plugin Envision",
      "product": "Envision Page Builder",
      "cwe": "CWE-79",
      "title": "WordPress Envision Page Builder plugin <= 0.22 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57780"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-57783",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "merkulove",
      "product": "Speaker",
      "cwe": "CWE-79",
      "title": "WordPress Speaker plugin <= 4.1.13 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57783"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-59523",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NSquared",
      "product": "Simply Schedule Appointments",
      "cwe": "CWE-862",
      "title": "WordPress Simply Schedule Appointments plugin <= 1.6.11.11 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59523"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-6541",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-639",
      "title": "Unscoped updates to other playbooks' metric configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6541"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-9820",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00152,
      "epss_percentile": 0.0494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-862",
      "title": "Mattermost schemes teams endpoint exposes private team invite IDs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9820"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-15605",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00151,
      "epss_percentile": 0.04773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "wandb",
      "cwe": "CWE-327",
      "title": "wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.download weak hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15605"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-10551",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Breeze Cache",
      "cwe": null,
      "title": "Breeze Cache < 2.5.6 - Unauthenticated Stored XSS via Minify Library",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10551"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-57691",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eli",
      "product": "Anti-Malware Security and Brute-Force Firewall",
      "cwe": "CWE-79",
      "title": "WordPress Anti-Malware Security and Brute-Force Firewall plugin <= 4.23.89 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57691"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-10103",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.0423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-639",
      "title": "Authenticated remote cluster can modify or delete posts it does not own in Mattermost Connected Workspaces shared channels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10103"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-15684",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Glarysoft",
      "product": "Glary Utilities",
      "cwe": "CWE-59",
      "title": "Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15684"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-57814",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPMU DEV - Your All-in-One WordPress Platform",
      "product": "Forminator",
      "cwe": "CWE-79",
      "title": "WordPress Forminator plugin <= 1.55.0.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57814"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-57816",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FunnelKit",
      "product": "Funnel Builder by FunnelKit",
      "cwe": "CWE-79",
      "title": "WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57816"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-59516",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Room 34 Creative Services, LLC",
      "product": "ICS Calendar",
      "cwe": "CWE-79",
      "title": "WordPress ICS Calendar plugin <= 12.1.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59516"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-9597",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-305",
      "title": "Deactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9597"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-15527",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0014,
      "epss_percentile": 0.03837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "better-auth",
      "product": "better-icons",
      "cwe": "CWE-22",
      "title": "better-auth better-icons scan_project_icons/sync_icon path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15527"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-12081",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Database for Contact Form 7, WPforms, Elementor forms",
      "cwe": null,
      "title": "Database for Contact Form 7, WPforms, Elementor forms < 1.5.2 - Unauthenticated PHP Object Injection via Entry File Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12081"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-15521",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00137,
      "epss_percentile": 0.03582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makafeli",
      "product": "n8n-workflow-builder",
      "cwe": "CWE-22",
      "title": "makafeli n8n-workflow-builder update_node_from_file server.cjs path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15521"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-15522",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00137,
      "epss_percentile": 0.03583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tugcantopaloglu",
      "product": "godot-mcp",
      "cwe": "CWE-22",
      "title": "tugcantopaloglu godot-mcp run_project index.js validatePath path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15522"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-15524",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00137,
      "epss_percentile": 0.03584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alioshr",
      "product": "memory-bank-mcp",
      "cwe": "CWE-22",
      "title": "alioshr memory-bank-mcp list-project-files-validation-factory.ts path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15524"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-15526",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00137,
      "epss_percentile": 0.03585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "augmnt",
      "product": "augments-mcp-server",
      "cwe": "CWE-22",
      "title": "augmnt augments-mcp-server scan_project_deps scan-project-deps.ts scanProjectDeps path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15526"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-15520",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00136,
      "epss_percentile": 0.03534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "LibreDWG",
      "cwe": "CWE-119",
      "title": "GNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15520"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-15682",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.03166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AnyDesk",
      "product": "AnyDesk",
      "cwe": "CWE-59",
      "title": "AnyDesk Support Information Link Following Denial-of-Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15682"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-62239",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.02938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dao-AILab",
      "product": "flash-attention",
      "cwe": "CWE-59",
      "title": "FlashAttention Symlink Attack via tarfile.extractall in hopper/setup.py",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62239"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-53365",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "vsock/virtio: fix zerocopy completion for multi-skb sends",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53365"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-58489",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hedgedoc",
      "product": "hedgedoc",
      "cwe": "CWE-352",
      "title": "HedgeDoc: CSRF in GitHub Gist export callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58489"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-15531",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00121,
      "epss_percentile": 0.0227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yashbhalgat",
      "product": "HashNeRF-pytorch",
      "cwe": "CWE-20",
      "title": "yashbhalgat HashNeRF-pytorch Checkpoint File run_nerf.py torch.load deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15531"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-61970",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeisle",
      "product": "Auto Featured Image (Auto Post Thumbnail)",
      "cwe": "CWE-918",
      "title": "WordPress Auto Featured Image (Auto Post Thumbnail) plugin <= 5.0.4 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61970"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-7162",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WinFsp",
      "product": "WinFsp",
      "cwe": "CWE-190",
      "title": "Successful exploitation of the integer overflow vulnerability could allow an attacker to achieve system-level access to the affected software.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7162"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-60103",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "blender",
      "product": "blender",
      "cwe": "CWE-125",
      "title": "Blender 3.0.0 - 5.1.2 Out-of-Bounds Read via crafted .blend SDNA block",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60103"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-15515",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tencent",
      "product": "PC Manager",
      "cwe": "CWE-426",
      "title": "Tencent PC Manager QMUDisk Driver qmudisk64.sys uncontrolled search path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15515"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-53364",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53364"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-15528",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00113,
      "epss_percentile": 0.01645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lamaalrajih",
      "product": "kicad-mcp",
      "cwe": "CWE-693",
      "title": "lamaalrajih kicad-mcp path_validator.py protection mechanism",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15528"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-9492",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00109,
      "epss_percentile": 0.01408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GIGABYTE",
      "product": "MBStorage",
      "cwe": "CWE-782",
      "title": "GIGABYTE｜Gigabyte Control Center - Improper Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9492"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-61956",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.01327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hamsalam",
      "product": "ووسلام &#8211; همگام سازی ووکامرس و باسلام",
      "cwe": "CWE-352",
      "title": "WordPress ووسلام – همگام سازی ووکامرس و باسلام plugin <= 1.9.1 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61956"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-15681",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.0119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AnyDesk",
      "product": "AnyDesk",
      "cwe": "CWE-59",
      "title": "AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15681"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-15683",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00096,
      "epss_percentile": 0.00823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lorex",
      "product": "2K Indoor Wi-Fi Security Camera",
      "cwe": "CWE-295",
      "title": "Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15683"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-15551",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00081,
      "epss_percentile": 0.00243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "rlottie",
      "cwe": "CWE-190",
      "title": "Samsung rlottie: Numeric truncation in gray_hline() leads to heap-based buffer overflow when rendering a crafted Lottie animation at native canvas size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15551"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-51536",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-51536. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-51537",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-51537. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-51538",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-51538. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-51540",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-51540. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-51541",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-51541. Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
