{
  "day": "2026-08-02",
  "boundary": "UTC calendar day",
  "published_count": 49,
  "by_severity": {
    "CRITICAL": 4,
    "HIGH": 21,
    "MEDIUM": 23,
    "LOW": 1
  },
  "kev_count": 0,
  "exploit_reference_count": 2,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-9335",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00646,
      "epss_percentile": 0.48191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "keras-team",
      "product": "keras-team/keras",
      "cwe": "CWE-22",
      "title": "Improper Handling of HDF5 ExternalLinks in keras-team/keras",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9335"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-65321",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00455,
      "epss_percentile": 0.37941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laughingman7743",
      "product": "PyAthena",
      "cwe": "CWE-89",
      "title": "PyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65321"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-16540",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00358,
      "epss_percentile": 0.29073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Simply Schedule Appointments",
      "cwe": "CWE-863",
      "title": "Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16540"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-16062",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00351,
      "epss_percentile": 0.28256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Event Booking Manager for WooCommerce",
      "cwe": "CWE-502",
      "title": "Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ PHP Object Injection via Event Timeline and FAQ Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16062"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-16261",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00333,
      "epss_percentile": 0.26331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "login-social",
      "cwe": "CWE-287",
      "title": "Huge IT Login <= 1.0.4 - Unauthenticated Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16261"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-68581",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.25009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-vikunja",
      "product": "vikunja",
      "cwe": "CWE-863",
      "title": "Vikunja 0.22.0 through 2.3.0 Authentication Bypass via Principal ID Collision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68581"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2025-71399",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00306,
      "epss_percentile": 0.23263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "better-auth",
      "product": "better-auth",
      "cwe": "CWE-20",
      "title": "Better Auth before 1.4.5 Path Normalization Bypass via rou3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71399"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-16256",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.22972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "POUCO Import Users",
      "cwe": "CWE-269",
      "title": "Pouco Import Users <= 1.0.0 - Unauthenticated Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16256"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-9856",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "huggingface",
      "product": "huggingface/transformers",
      "cwe": "CWE-22",
      "title": "Path Traversal in huggingface/transformers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9856"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-13389",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "webtoffee-cookie-consent",
      "cwe": "CWE-862",
      "title": "WebToffee Cookie Consent < 3.5.3 - Consent Log Disclosure/Deletion, Page Creation & License Deactivation via Unprotected REST Routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13389"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-14817",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Element Pack Addons for Elementor",
      "cwe": "CWE-79",
      "title": "Element Pack Elementor Addons < 8.7.13 - Contributor+ DOM-Based Stored XSS via uikit Data Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14817"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-15236",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Gallery for Google Photos",
      "cwe": "CWE-200",
      "title": "Gallery for Google Photos < 1.2.1 - Unauthenticated Google OAuth Token Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15236"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-15248",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Meta Box",
      "cwe": "CWE-862",
      "title": "Meta Box < 5.13.1 - Contributor+ Arbitrary Attachment Deletion via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15248"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-14920",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "AcyMailing",
      "cwe": "CWE-89",
      "title": "AcyMailing < 10.11.1 - Unauthenticated SQL Injection via subscription[] Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14920"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-68579",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-787",
      "title": "FreeRDP before 3.30.0 Heap Overflow via CliprdrStream_Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68579"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-15206",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "SMS Alert",
      "cwe": "CWE-287",
      "title": "SMS Alert Order Notifications – WooCommerce < 3.9.8 - Unauthenticated Account Takeover via Unbound OTP Verification in Signup-with-Mobile",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15206"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-15241",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "AI ChatBot for WooCommerce",
      "cwe": "CWE-284",
      "title": "ChatBot for eCommerce – WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_gemini_response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15241"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-16285",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.1815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Product Attachment for WooCommerce",
      "cwe": "CWE-862",
      "title": "WooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media Download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16285"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2025-71401",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "better-auth",
      "product": "better-auth",
      "cwe": "CWE-770",
      "title": "better-auth before 1.4.2 basePath Modification DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71401"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-12231",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "timstrifler",
      "product": "Exclusive Addons for Elementor",
      "cwe": "CWE-79",
      "title": "Exclusive Addons for Elementor <= 2.7.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'exad_infobox_image'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12231"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-67357",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-200",
      "title": "ArcadeDB before 26.7.3 Information Disclosure via get_server_settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67357"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-67356",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-269",
      "title": "ArcadeDB before 26.7.3 Privilege Escalation via JavaScript Trigger",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67356"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-18571",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.15967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18571"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-3245",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canon Production Printing",
      "product": "PRISMAproduction",
      "cwe": "CWE-502",
      "title": "A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3245"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-68580",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-122",
      "title": "FreeRDP before 3.29.0 Integer Overflow via Audio Input Channel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68580"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-15151",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Five Star Restaurant Reservations",
      "cwe": "CWE-284",
      "title": "Five Star Restaurant Reservations < 2.7.23 - Booking Manager+ Missing Authorization via rtb_reset_notifications",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15151"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-18573",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.1291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: client access-type policy condition bypass during client update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18573"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-10848",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10848"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-68578",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArcadeData",
      "product": "arcadedb",
      "cwe": "CWE-306",
      "title": "ArcadeDB before 26.7.3 Authentication Bypass via MCP Transport",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68578"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-68582",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00211,
      "epss_percentile": 0.1161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "go-vikunja",
      "product": "vikunja",
      "cwe": "CWE-639",
      "title": "Vikunja 0.24.0 Broken Object Level Authorization via Link-Share Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68582"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2025-71400",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "better-auth",
      "product": "passkey",
      "cwe": "CWE-639",
      "title": "better-auth passkey before 1.4.0 IDOR via delete-passkey",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71400"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-16042",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "LWS Optimize",
      "cwe": "CWE-862",
      "title": "LWS Optimize < 3.4 - Subscriber+ Cache Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16042"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-11872",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Clever Mega Menu for Visual Composer",
      "cwe": "CWE-284",
      "title": "Clever Mega Menu for Visual Composer <= 1.0.1 - Subscriber+ Menu Item Meta Update via save_clever_menu_item",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11872"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-18572",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-863",
      "title": "Keycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18572"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-14841",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "King Addons for Elementor",
      "cwe": "CWE-79",
      "title": "King Addons for Elementor < 51.1.76 - Reflected XSS via Posts Grid Widget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14841"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-10774",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-401",
      "title": "PSA key-slot leak in Bluetooth Mesh subnet deletion leading to resource-exhaustion DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10774"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-15939",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00179,
      "epss_percentile": 0.07747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Simple Restrict",
      "cwe": "CWE-863",
      "title": "Simple Restrict < 1.2.9 - Contributor+ Restricted Content Disclosure via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15939"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2025-15675",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.07089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Charitable",
      "cwe": "CWE-79",
      "title": "Charitable < 1.8.5.3 - Admin+ Stored XSS via Photo Field ALT Text",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15675"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-12586",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Lenxel WP",
      "cwe": "CWE-287",
      "title": "Lenxel WP <= 1.0.31 - Unauthenticated Account Takeover via Arbitrary Password Reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12586"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-14938",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "FluentBoards",
      "cwe": "CWE-639",
      "title": "FluentBoards < 1.95.3 - Subscriber+ Cross-Board Task Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14938"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-16291",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.0491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ProfileGrid",
      "cwe": "CWE-639",
      "title": "ProfileGrid < 5.9.9.8 - Subscriber+ Arbitrary Notification Deletion via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16291"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-18570",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: full-scope-disabled client policy validation bypass via omitted fullscopeallowed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18570"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-16064",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Event Booking Manager for WooCommerce",
      "cwe": "CWE-863",
      "title": "Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ Arbitrary Post Modification via mpwem_quick_edit_event",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16064"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-68583",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openwrt",
      "product": "luci",
      "cwe": "CWE-79",
      "title": "luci-app-adblock-fast before 1.2.4-4 Stored XSS via file_url.name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68583"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-14864",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "JetEngine",
      "cwe": "CWE-79",
      "title": "JetEngine < 3.8.12 - Contributor+ Stored XSS via jet_engine Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14864"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-15385",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "RT Mega Menu",
      "cwe": "CWE-79",
      "title": "RT Mega Menu < 1.5.2 - Subscriber+ Stored XSS via Menu Item CSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15385"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-16063",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Event Booking Manager for WooCommerce",
      "cwe": "CWE-79",
      "title": "Event Booking Manager for WooCommerce < 5.3.7 - Author+ Stored XSS via Event Timeline Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16063"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-16273",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Narrative Publisher",
      "cwe": "CWE-79",
      "title": "Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post Meta",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16273"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-16292",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Frontend File Manager Plugin",
      "cwe": "CWE-352",
      "title": "Frontend File Manager Plugin <= 23.6 - File Metadata Update via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16292"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-15669",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-15669 (Unknown Bit Form). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10774",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10774 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10848",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10848 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-12696",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-12696 (Unknown wpForo Forum). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-12966",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-12966 (Unknown Direct Payments for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13329",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13329 (Unknown Buckaroo Woocommerce Payments Plugin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13596",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13596 (Unknown Participants Database). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14292",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14292 (Unknown Download Manager). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14315",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14315 (Unknown Pixel Tag Manager for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14561",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14561 (Unknown Authora : Easy login with mobile number). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14839",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14839 (Unknown Mapster WP Maps). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15234",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15234 (Unknown Codeless Page Builder). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15262",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15262 (Unknown Admin Columns for ACF Fields). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67206",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67206 (wolfcms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67207",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67207 (wolfcms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67288",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67288 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67298",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67298 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-20316",
      "detail": "DUE DATE PASSED — CVE-2026-20316 (Cisco Secure Firewall Management Center (FMC)). CISA remediation deadline was August 1, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-6492",
      "detail": "RESCORED — CVE-2026-6492 (arnobt78 Hotel Booking Management System). CVSS 6.9 → 5.5 (NVD)."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
