{
  "day": "2026-08-16",
  "boundary": "UTC calendar day",
  "published_count": 109,
  "by_severity": {
    "CRITICAL": 14,
    "HIGH": 33,
    "MEDIUM": 43,
    "LOW": 19
  },
  "kev_count": 0,
  "exploit_reference_count": 5,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-19960",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01158,
      "epss_percentile": 0.64554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7478APC",
      "cwe": "CWE-77",
      "title": "Edimax EW-7478APC formWlbasic command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19960"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-19962",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01158,
      "epss_percentile": 0.64555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7478APC",
      "cwe": "CWE-74",
      "title": "Edimax EW-7478APC setWAN command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19962"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-19963",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01158,
      "epss_percentile": 0.64552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7478APC",
      "cwe": "CWE-77",
      "title": "Edimax EW-7478APC stainfo command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19963"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-19924",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00901,
      "epss_percentile": 0.5691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "AC10",
      "cwe": "CWE-287",
      "title": "Tenda AC10 httpd R7WebsSecurityHandler improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19924"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-19349",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00818,
      "epss_percentile": 0.54345,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Lemonldap-NG-Portal",
      "cwe": "CWE-305",
      "title": "Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19349"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-15056",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00813,
      "epss_percentile": 0.54165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kodezen",
      "product": "StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More",
      "cwe": "CWE-22",
      "title": "StoreEngine <= 2.1.1 - Authenticated (Vendor+) Arbitrary File Read via Path Traversal in Downloadable File URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15056"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-17604",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00805,
      "epss_percentile": 0.53914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Kirki – Freeform Page Builder, Website Builder & Customizer",
      "cwe": "CWE-22",
      "title": "Kirki <= 6.1.1 - Authenticated (Editor+) Path Traversal to Arbitrary File Read via 'data' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17604"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-17581",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00734,
      "epss_percentile": 0.51583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kilbot",
      "product": "WCPOS – Point of Sale (POS) plugin for WooCommerce",
      "cwe": "CWE-94",
      "title": "WCPOS <= 1.9.14 - Authenticated (Shop Manager+) Code Injection via 'thermal' Template Engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17581"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-14524",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00702,
      "epss_percentile": 0.50432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "prosolution",
      "product": "ProSolution WP Client",
      "cwe": "CWE-22",
      "title": "ProSolution WP Client <= 2.0.8 - Unauthenticated Arbitrary File Deletion via 'newfilename' and 'filename' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14524"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-16098",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00641,
      "epss_percentile": 0.47958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "prosolution",
      "product": "ProSolution WP Client",
      "cwe": "CWE-434",
      "title": "ProSolution WP Client <= 2.0.10 - Unauthenticated Arbitrary File Upload via Content-Disposition Header Filename Override",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16098"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-16099",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00588,
      "epss_percentile": 0.45521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eteubert",
      "product": "Podlove Podcast Publisher",
      "cwe": "CWE-502",
      "title": "Podlove Podcast Publisher <= 4.5.3 - Authenticated (Contributor+) PHP Object Injection to Arbitrary File Deletion via 'unfurl_data' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16099"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-72887",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0055,
      "epss_percentile": 0.43653,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Net-OAuth",
      "cwe": "CWE-757",
      "title": "Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72887"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-14498",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00549,
      "epss_percentile": 0.4361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "daggerhart",
      "product": "Query Wrangler",
      "cwe": "CWE-434",
      "title": "Query Wrangler <= 1.5.57 - Authenticated (Subscriber+) Remote Code Execution via 'options' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14498"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2024-13784",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00519,
      "epss_percentile": 0.41946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "reputeinfosystems",
      "product": "Contact Form, Survey, Quiz & Popup Form Builder – ARForms",
      "cwe": "CWE-502",
      "title": "Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.8.5 - Unauthenticated PHP Object Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-13784"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-13358",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00486,
      "epss_percentile": 0.39934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "croixhaug",
      "product": "Simply Schedule Appointments",
      "cwe": "CWE-639",
      "title": "Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.10 - Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13358"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-19959",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00471,
      "epss_percentile": 0.38896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7478APC",
      "cwe": "CWE-119",
      "title": "Edimax EW-7478APC formWanTcpipSetup stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19959"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-19961",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00471,
      "epss_percentile": 0.38896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7478APC",
      "cwe": "CWE-119",
      "title": "Edimax EW-7478APC formWlSiteSurvey buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19961"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-73056",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0045,
      "epss_percentile": 0.37553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-307",
      "title": "SiYuan kernel before 3.7.4 Unthrottled Brute-Force via API Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73056"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-18432",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00448,
      "epss_percentile": 0.37432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shabti",
      "product": "Frontend Admin by DynamiApps",
      "cwe": "CWE-269",
      "title": "Frontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18432"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-19728",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00444,
      "epss_percentile": 0.37082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Extra Product Options Builder for WooCommerce",
      "cwe": "CWE-862",
      "title": "Extra Product Options Builder for WooCommerce < 1.2.176 - Unauthenticated Customer File Disclosure via getpublicfileupload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19728"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-72888",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00436,
      "epss_percentile": 0.36479,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Net-OAuth",
      "cwe": "CWE-770",
      "title": "Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-72888"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-17087",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00415,
      "epss_percentile": 0.34747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wptravelengine",
      "product": "WP Travel Engine – Tour Booking Plugin – Tour Operator Software",
      "cwe": "CWE-862",
      "title": "WP Travel Engine <= 6.8.4 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'booking_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17087"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-10035",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.004,
      "epss_percentile": 0.33433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpweaver",
      "product": "Turnkey bbPress by WeaverTheme",
      "cwe": "CWE-502",
      "title": "Turnkey bbPress by WeaverTheme <= 1.7.1 - Authenticated (Administrator+) PHP Object Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10035"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-15441",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00386,
      "epss_percentile": 0.31959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wcproducttable",
      "product": "Product Table & List Builder For WooCommerce",
      "cwe": "CWE-74",
      "title": "Product Table & List Builder For WooCommerce <= 5.6.0 - Unauthenticated CSS Injection via 'laptop_scroll_offset' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15441"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-19725",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00373,
      "epss_percentile": 0.30569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPvivid — Backup, Migration & Staging",
      "cwe": "CWE-22",
      "title": "WPvivid Backup & Migration < 0.9.131 - Unauthenticated Path Traversal via send_to_site_connect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19725"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-73060",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.30557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scriban",
      "product": "scriban",
      "cwe": "CWE-770",
      "title": "Scriban 3.0.0 through 7.2.5 Denial of Service via ScriptRange.Multiply",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73060"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-74251",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.30473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phoca.cz",
      "product": "Phoca Cart extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74251"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-17123",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.28765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wproyal",
      "product": "Royal Addons for Elementor – Addons and Templates Kit for Elementor",
      "cwe": "CWE-918",
      "title": "Royal Addons for Elementor <= 1.7.1064 - Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget 'webhook_url' Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17123"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-19717",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "CatFolders Document Gallery & PDF Library",
      "cwe": "CWE-200",
      "title": "CatFolders Document Gallery < 2.0.7 - Unauthenticated Attachment Disclosure via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19717"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-13167",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00346,
      "epss_percentile": 0.27791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpeverest",
      "product": "Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI",
      "cwe": "CWE-862",
      "title": "Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI <= 3.5.2 - Missing Authorization to Authenticated (Delegated+) Arbitrary Plugin Activation via REST API and AJAX Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13167"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-74789",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scriban",
      "product": "scriban",
      "cwe": "CWE-400",
      "title": "Scriban before 7.0.0 LoopLimit Bypass via Built-in Operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74789"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-13424",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ladela",
      "product": "Online Scheduling and Appointment Booking System – Bookly",
      "cwe": "CWE-79",
      "title": "Online Scheduling and Appointment Booking System <= 27.7 - Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13424"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-15602",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00329,
      "epss_percentile": 0.2591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webaways",
      "product": "NEX-Forms – Ultimate Forms Plugin for WordPress",
      "cwe": "CWE-89",
      "title": "NEX-Forms <= 9.2.4 - Authenticated (Admin+) SQL Injection via 'additional_params' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15602"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-9767",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weblizar",
      "product": "The School Management – Education & Learning ERP",
      "cwe": "CWE-89",
      "title": "The School Management <= 5.4 - Authenticated (Custom+) SQL Injection via 'order[0][dir]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9767"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-18316",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00324,
      "epss_percentile": 0.25329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "solacewp",
      "product": "Solace Extra",
      "cwe": "CWE-862",
      "title": "Solace Extra <= 1.6.0 - Missing Authorization to Unauthenticated Site Content Deletion and Unauthorized Demo Import via action-import-zip AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18316"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-19714",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00324,
      "epss_percentile": 0.25284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Simple JWT Login",
      "cwe": "CWE-287",
      "title": "Simple JWT Login < 3.6.8 - Unauthenticated Account Takeover via Missing Google id_token Audience Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19714"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-74795",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scriban",
      "product": "scriban",
      "cwe": "CWE-674",
      "title": "Scriban before 6.6.0 Denial of Service via Uncontrolled Recursion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74795"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-18385",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.24649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "properfraction",
      "product": "Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress",
      "cwe": "CWE-94",
      "title": "Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.19 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via First Name / Last Name Profile Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18385"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-17533",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "All-in-One WP Migration and Backup",
      "cwe": "CWE-269",
      "title": "All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Code Execution via REST Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17533"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-2497",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.24347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bestwebsoft",
      "product": "Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress",
      "cwe": "CWE-89",
      "title": "Gallery by BestWebSoft <= 4.7.9 - Authenticated (Editor+) SQL Injection via Gallery Image Order Array Keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2497"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-74792",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scriban",
      "product": "scriban",
      "cwe": "CWE-674",
      "title": "Scriban before 7.0.0 Stack Overflow via nested array initializers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74792"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-15002",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bluemediapl",
      "product": "Autopay",
      "cwe": "CWE-79",
      "title": "Autopay <= 5.0.0 - Unauthenticated Stored Cross-Site Scripting via 'bm_woocommerce_css_editor_content' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15002"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-18653",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Directory Kit",
      "cwe": "CWE-89",
      "title": "WP Directory Kit < 1.5.7 - Admin+ SQL Injection via section Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18653"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-11780",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.23375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "expresstech",
      "product": "Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker",
      "cwe": "CWE-79",
      "title": "Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'question_title' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11780"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-15345",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00306,
      "epss_percentile": 0.23259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shortpixel",
      "product": "ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization",
      "cwe": "CWE-862",
      "title": "ShortPixel Adaptive Images <= 3.11.5 - Missing Authorization to Authenticated (Subscriber+) Third-Party Plugin Option Modification via 'causer' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15345"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-18347",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.23218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Kirki – Freeform Page Builder, Website Builder & Customizer",
      "cwe": "CWE-862",
      "title": "Kirki <= 6.1.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'context' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18347"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-73061",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00302,
      "epss_percentile": 0.22848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scriban",
      "product": "scriban",
      "cwe": "CWE-284",
      "title": "Scriban before 7.2.2 Arbitrary Property Write via TypedObjectAccessor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73061"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-12998",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00301,
      "epss_percentile": 0.22799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmudev",
      "product": "Forminator Forms – Contact Form, Payment Form & Custom Form Builder",
      "cwe": "CWE-639",
      "title": "Forminator Forms <= 1.55.0.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'draft' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12998"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-19955",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00294,
      "epss_percentile": 0.21972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "TrailDB",
      "cwe": "CWE-125",
      "title": "TrailDB TOC Validation tdb.c tdb_open out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19955"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-12905",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ladela",
      "product": "Online Scheduling and Appointment Booking System – Bookly",
      "cwe": "CWE-639",
      "title": "Online Scheduling and Appointment Booking System – Bookly <= 27.7 - Authenticated (Staff+) Insecure Direct Object Reference to Sensitive Information Exposure via 'params[id]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12905"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-2283",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "faiyazalam",
      "product": "User Login History",
      "cwe": "CWE-89",
      "title": "User Login History <= 2.1.7 - Authenticated (Administrator+) SQL Injection via 'blog_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2283"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-15351",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wcvendors",
      "product": "WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors",
      "cwe": "CWE-89",
      "title": "WC Vendors <= 2.7.0 - Authenticated (Shop Manager+) SQL Injection via 'status' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15351"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-17582",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quantumcloud",
      "product": "Slider Hero with Video Background, Animation",
      "cwe": "CWE-89",
      "title": "Slider Hero with Video Background, Animation <= 9.1.7 - Authenticated (Administrator+) SQL Injection via 'description' Slide Field (Second-Order via Duplicate)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17582"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-74790",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00286,
      "epss_percentile": 0.21133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scriban",
      "product": "scriban",
      "cwe": "CWE-693",
      "title": "Scriban before 7.0.0 MemberFilter Bypass via TemplateContext Cache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74790"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-19929",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00284,
      "epss_percentile": 0.20981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "OpenBoxes",
      "cwe": "CWE-1336",
      "title": "OpenBoxes Template Processing DocumentController.groovy buildZebraTemplate special elements in template engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19929"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-16079",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pdamsten",
      "product": "Fullscreen Galleria",
      "cwe": "CWE-89",
      "title": "Fullscreen Galleria <= 1.6.12 - Authenticated (Contributor+) SQL Injection via 'href' Attribute in Post Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16079"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-15009",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "saadiqbal",
      "product": "Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution",
      "cwe": "CWE-79",
      "title": "Advanced File Manager <= 5.4.12 - Reflected Cross-Site Scripting via postMessage 'soundFile' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15009"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-73057",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stoatchat",
      "product": "stoatchat",
      "cwe": "CWE-400",
      "title": "stoatchat before 0.15.0 Uncapped SVG Rendering Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73057"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-73062",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scriban",
      "product": "scriban",
      "cwe": "CWE-770",
      "title": "Scriban 3.0.0 through 7.2.0 Denial of Service via Array Multiplication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73062"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-74783",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scriban",
      "product": "scriban",
      "cwe": "CWE-674",
      "title": "Scriban 6.6.0 through 7.2.0 Parser Recursion Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74783"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-74787",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scriban",
      "product": "scriban",
      "cwe": "CWE-674",
      "title": "Scriban before 7.0.0 Uncontrolled Recursion via object.to_json",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74787"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-74788",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scriban",
      "product": "scriban",
      "cwe": "CWE-770",
      "title": "Scriban before 7.0.0 Denial of Service via string.pad_left/pad_right",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74788"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-74794",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20389,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scriban",
      "product": "scriban",
      "cwe": "CWE-674",
      "title": "Scriban before 6.6.0 Denial of Service via Infinite Recursion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74794"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-74785",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scriban",
      "product": "scriban",
      "cwe": "CWE-400",
      "title": "Scriban before 7.0.0 Denial of Service via Unbounded Resource Consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74785"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-74786",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scriban",
      "product": "scriban",
      "cwe": "CWE-770",
      "title": "Scriban before 7.0.0 Denial of Service via Unbounded Template Output",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74786"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-19613",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ECS",
      "cwe": "CWE-200",
      "title": "ECS < 4.3.10 - Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeater ACF Source",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19613"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-19957",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0027,
      "epss_percentile": 0.19279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "graphlit",
      "product": "graphlit-mcp-server",
      "cwe": "CWE-918",
      "title": "graphlit graphlit-mcp-server ssrf-test Endpoint tools.ts fetch server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19957"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-74791",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00269,
      "epss_percentile": 0.19177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scriban",
      "product": "scriban",
      "cwe": "CWE-226",
      "title": "Scriban before 7.0.0 Authorization Bypass via Stale Include Cache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74791"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-15963",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "expresstech",
      "product": "Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker",
      "cwe": "CWE-89",
      "title": "Quiz and Survey Master (QSM) <= 11.2.1 - Authenticated (Contributor+) SQL Injection via 'randon_category' Quiz Option",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15963"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-19926",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Evergreen",
      "cwe": "CWE-74",
      "title": "Evergreen open-ils.fielder OpenSRF Service osrf-gateway-v1 sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19926"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-74784",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "scriban",
      "product": "scriban",
      "cwe": "CWE-770",
      "title": "Scriban before 7.2.0 Denial of Service via array.insert_at",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74784"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-15066",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.18126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "timwhitlock",
      "product": "Loco Translate",
      "cwe": "CWE-79",
      "title": "Loco Translate <= 2.8.7 - Authenticated (Translator+) Stored Cross-Site Scripting via PO File Extracted Comments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15066"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-12477",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmonks",
      "product": "Gravity Booster – Styles & Layouts for Gravity Forms",
      "cwe": "CWE-79",
      "title": "Gravity Booster <= 5.26 - Authenticated (Editor+) Stored Cross-Site Scripting via 'stylerSettings' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12477"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2024-58375",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.1723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opentofu",
      "product": "opentofu",
      "cwe": "CWE-497",
      "title": "OpenTofu before 1.8.3 Secret Variable Leaking via Static Evaluation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-58375"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-10734",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.17097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "infility",
      "product": "Infility Global",
      "cwe": "CWE-79",
      "title": "Infility Global <= 2.15.21 - Unauthenticated Stored Cross-Site Scripting via /cf7_record Log Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10734"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-19933",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00252,
      "epss_percentile": 0.1692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DefaultFuction",
      "product": "Customer-Relationship-Management-In-C-Project",
      "cwe": "CWE-119",
      "title": "DefaultFuction Customer-Relationship-Management-In-C-Project Customer Search gets stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19933"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-19927",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00251,
      "epss_percentile": 0.16831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "OpenBoxes",
      "cwe": "CWE-918",
      "title": "OpenBoxes Product Upload Endpoint ProductController.groovy upload server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19927"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-19928",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00251,
      "epss_percentile": 0.16831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "OpenBoxes",
      "cwe": "CWE-266",
      "title": "OpenBoxes Role Interceptor RoleInterceptor.groovy needManager privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19928"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-19726",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.16383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Visualizer",
      "cwe": "CWE-863",
      "title": "Visualizer < 4.0.7 - Contributor+ Cross-User Chart Configuration Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19726"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2025-10005",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "buildwps",
      "product": "PPWP – Password Protect Pages",
      "cwe": "CWE-639",
      "title": "Password Protect WordPress Lite <= 1.9.20 - Insecure Direct Object Reference to Authenticated (Contributor+) Password Protected Post Password Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-10005"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-19930",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00242,
      "epss_percentile": 0.15679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Dolibarr",
      "cwe": "CWE-74",
      "title": "Dolibarr User Cloning card.php ldap injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19930"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-73058",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stoatchat",
      "product": "stoatchat",
      "cwe": "CWE-918",
      "title": "stoatchat before 0.15.0 SSRF via IPv6 unspecified address bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73058"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-19932",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00237,
      "epss_percentile": 0.14954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DefaultFuction",
      "product": "Notice-System-Managent",
      "cwe": "CWE-74",
      "title": "DefaultFuction Notice-System-Managent NoticeController execute GroovyShell.evaluate code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19932"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-74796",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.13943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opentofu",
      "product": "opentofu",
      "cwe": "CWE-59",
      "title": "OpenTofu before 1.11.7 Symlink Following Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74796"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-19958",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00228,
      "epss_percentile": 0.13773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iatsiuk",
      "product": "pptr-mcp",
      "cwe": "CWE-74",
      "title": "iatsiuk pptr-mcp execute Tool vm-executor.ts executeCode code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19958"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-16779",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "extendthemes",
      "product": "Kubio AI Page Builder",
      "cwe": "CWE-862",
      "title": "Kubio AI Page Builder <= 2.8.5 - Missing Authorization to Authenticated (Contributor+) Front-Page/Menu/Template Configuration Reversion via kubio_restore_front_page AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16779"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-73059",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stoatchat",
      "product": "stoatchat",
      "cwe": "CWE-863",
      "title": "stoatchat before 0.15.0 Permission Bypass via message_fetch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73059"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-19964",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00218,
      "epss_percentile": 0.12502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jij-Inc",
      "product": "Jij-MCP-Server",
      "cwe": "CWE-74",
      "title": "Jij-Inc Jij-MCP-Server jm_check python_repr.py PythonREPL.run code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19964"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-19956",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gomarble-ai",
      "product": "facebook-ads-mcp-server",
      "cwe": "CWE-918",
      "title": "gomarble-ai facebook-ads-mcp-server server.py fetch_pagination_url server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19956"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-19711",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Premium Packages",
      "cwe": "CWE-284",
      "title": "Premium Packages – Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbitrary Amount Withdrawal Request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19711"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-19925",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.0021,
      "epss_percentile": 0.11502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Stock Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Stock Management System Master.php delete_supplier sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19925"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-2487",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weblizar",
      "product": "Admin Custom Login",
      "cwe": "CWE-79",
      "title": "Admin Custom Login <= 3.6.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Message Above Login Form' Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2487"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-15726",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cryout-creations",
      "product": "Serious Slider",
      "cwe": "CWE-79",
      "title": "Serious Slider <= 1.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'theme' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15726"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-19921",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.1024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Online Shopping System",
      "cwe": "CWE-74",
      "title": "code-projects Online Shopping System homeaction.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19921"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-19923",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.1024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Online Shopping System",
      "cwe": "CWE-74",
      "title": "code-projects Online Shopping System checkout_process.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19923"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-19934",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System vieworder.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19934"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-19922",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.10032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Online Shopping System",
      "cwe": "CWE-79",
      "title": "code-projects Online Shopping System checkout.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19922"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-15790",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "emarket-design",
      "product": "Video Gallery – YouTube Gallery, Playlist & Video Grid",
      "cwe": "CWE-79",
      "title": "Video Gallery <= 4.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment 'post_title' via emd_mb_meta Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15790"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-15604",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "toocheke",
      "product": "Toocheke Companion",
      "cwe": "CWE-79",
      "title": "Toocheke Companion <= 2.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'series_bg_color' Post Meta",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15604"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-16758",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aliakro",
      "product": "Snippet Shortcodes",
      "cwe": "CWE-79",
      "title": "Snippet Shortcodes <= 5.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16758"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-16775",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "Smash Balloon Social Post Feed – Simple Social Feeds for WordPress",
      "cwe": "CWE-79",
      "title": "Smash Balloon Social Post Feed <= 4.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16775"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-18402",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "brainstormforce",
      "product": "SureDash – Community, Courses & Member Dashboard",
      "cwe": "CWE-79",
      "title": "SureDash <= 1.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'draweropenverposition' Block/Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18402"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-2357",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boldthemes",
      "product": "Bold Page Builder",
      "cwe": "CWE-79",
      "title": "Bold Page Builder <= 5.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2357"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-19712",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Masteriyo LMS",
      "cwe": "CWE-79",
      "title": "Masteriyo LMS < 2.3.3 - Instructor+ Stored XSS via Quiz Description",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19712"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-74797",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00174,
      "epss_percentile": 0.07222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opentofu",
      "product": "opentofu",
      "cwe": "CWE-400",
      "title": "OpenTofu before 1.11.4 Denial of Service via malicious zip",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74797"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-13712",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.0588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Divi",
      "cwe": "CWE-79",
      "title": "Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13712"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-17608",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aresit",
      "product": "WP Compress – Instant Performance & Speed Optimization",
      "cwe": "CWE-352",
      "title": "WP Compress <= 7.10.09 - Cross-Site Request Forgery to Arbitrary Options Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17608"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-74578",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: algif_skcipher - force synchronous processing on trees without ctx->state",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74578"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-15384",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Manual Image Crop",
      "cwe": "CWE-287",
      "title": "Manual Image Crop < 1.15 - Subscriber+ Arbitrary Attachment Image Overwrite via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15384"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13700",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13700 (Unknown WooMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14229",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14229 (Unknown ECS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14230",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14230 (Unknown ECS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14832",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14832 (Unknown ShopSmart Loyalty for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16007",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16007 (AppFlowy-IO AppFlowy-Cloud). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16541",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16541 (Unknown Simply Schedule Appointments). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16611",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16611 (Unknown Product Feed PRO for WooCommerce by AdTribes). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18216",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18216 (Unknown Backup Migration). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-18807",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-18807 (Unknown ECS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19478",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19478 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19650",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19650 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19895",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19895 (opensourcepos Open Source Point of Sale). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19897",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19897 (mangroup dtale). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19900",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19900 (LB-LINK X-PRO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19903",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19903 (SourceCodester Online Clothing Store). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19917",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19917 (code-projects Online Food Order System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19965",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19965 (automad). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19966",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19966 (CodeCanyon TimeCamp Integration for CRM). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19967",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19967 (Open Asset Import Library Assimp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19968",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19968 (Open Asset Import Library Assimp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19969",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19969 (Open Asset Import Library Assimp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19970",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19970 (Open Asset Import Library Assimp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19972",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19972 (itsourcecode Hospital Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19973",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19973 (itsourcecode Hospital Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19974",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19974 (treefrogframework treefrog-framework). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19976",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19976 (COMFAST CF-N1-S). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19977",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19977 (EFM ipTIME A3004T). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19978",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19978 (jiantao88 android-mcp-server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19984",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19984 (jkawamoto mcp-florence2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19986",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19986 (Adblock for Youtube Extension). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19988",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19988 (Alaev SEO Tools Extension). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19992",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19992 (Orange View Limited DualSafe Password Manager & Digital Vault Extension). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19993",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19993 (Webkul Bagisto). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19994",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19994 (Webkul Bagisto). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19995",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19995 (Webkul Bagisto). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19996",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19996 (Webkul Bagisto). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19997",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19997 (Webkul Bagisto). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19998",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19998 (code-projects Online Shopping System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-19999",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-19999 (Open Asset Import Library Assimp Assimp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-20000",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-20000 (itsourcecode Hospital Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72743",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72743 (dataease SQLBot). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-73678",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-73678 (MindsDB Minds Platform). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-74842",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-74842 (Kira-Pgr PromptShopMCP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-74843",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-74843 (Wavlink WN531P3). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-74899",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-74899 (jahlives openssl_encrypt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75011",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75011 (kylecui NetForensicMCP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75012",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75012 (TOTOLINK EX1200L). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75013",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75013 (TOTOLINK EX1200L). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75014",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75014 (SourceCodester Pet Grooming Management Software). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75077",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75077 (SourceCodester Class and Exam Timetabling System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-75078",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-75078 (SourceCodester Class and Exam Timetabling System). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19918",
      "detail": "RESCORED — CVE-2026-19918 (SpaceX Starlink Router Gen 3). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-19919",
      "detail": "RESCORED — CVE-2026-19919 (code-projects Online Shopping System). CVSS 6.9 → 5.5 (NVD)."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
