boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Saturday, September 5, 2026 · all times UTC← 2026-09-04 · archive

Security Box Score — September 5, 2026

131 CVEs published, led by xmlsoft (8).

131 CVEs published September 5, 2026: 17 critical, 32 high, 45 medium, 3 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 34 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 106 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published183936582——
KEV catalog size1695

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2369 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux1884149420201569411230.17.8.0016+166 ▲
google382202280856978887870.37.5.0026+36 ▲
microsoft91908148129045515287281.57.8.0044-7 ▼
red hat336594027331135200.06.6.0028-1 ▼
apple0316598516578882.56.5.00290
freebsd04823673000.07.8.00160
canonical0421311135000.07.8.00200
suse937521101000.07.5.0036+4 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco11952445260561313.77.5.0042-12 ▼
ubiquiti059362210335.19.1.00490
palo alto networks0371321121325.44.7.00200
netgear03200275000.04.3.00250
fortinet0307814128620.07.0.00500
f572461431414.28.7.0047+7 ▲
sonicwall519784019421.18.3.0050+4 ▲
vmware019410327210.58.3.00400
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache8514103217176133320.47.5.0049-31 ▼
mozilla342218079620900.08.1.0029+33 ▲
drupal2694119668411.15.7.0024+26 ▲
gitlab076317479422.65.3.00290
github32011090000.07.3.0044+1 ▲
docker090630000.07.2.00160
wordpress0513102240.08.8.31200
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle022694841170519962840.27.8.00340
ibm706891503012289610.17.5.0029+38 ▲
adobe26085030224791930.57.8.0021-5 ▼
progress2631439100611.68.1.0036-8 ▼
solarwinds0231733010417.49.1.00580
veeam01961030100.08.6.0032-10 ▼
zohocorp1113620000.08.8.0144+1 ▲
atlassian0615001300.08.1.00320
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link348151698300.08.5.0160+3 ▲
rockwell automation184353260000.08.6.0029+18 ▲
siemens13822583000.07.3.0016+1 ▲
synology02736153000.05.6.0025-1 ▼
schneider electric4131840000.08.2.0032+4 ▲
hitachi energy470340000.06.9.0017+4 ▲
abb070430000.07.2.00180
hikvision060420000.07.2.00400
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1919013103695210.57.3.0021+16 ▲
sourcecodester1170009377000.05.5.0029+1 ▲
spring017012598415000.06.5.00240
nvidia3016420115290000.07.8.0028+14 ▲
elastic42129127983100.06.5.0028+42 ▲
splunk0128647705110.86.5.00250
itsourcecode6122003587000.02.1.0026+6 ▲
siyuan-note131164434371000.08.6.0028+5 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.995799.99.8
CVE-2026-60004.867899.79.8
CVE-2026-72898.823299.610.0
CVE-2026-73570.323898.38.9
CVE-2026-64638.312098.28.9
CVE-2026-71362.251497.89.1
CVE-2026-64849.164196.89.3
CVE-2026-48376.154896.65.4
CVE-2026-19681.078094.49.4
CVE-2026-82329.076794.39.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.8232KEV
CVE-2026-4836210.0.0431
CVE-2026-1918810.0.0193
CVE-2026-5823110.0.0171
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-6983610.0.0155
CVE-2026-7329910.0.0121
CVE-2026-7367810.0.0114
CVE-2026-7755410.0.0099
Most disclosures (vendor)
VendorCVEs
linux1789
oracle890
microsoft453
ibm428
google397
red hat224
apache119
splunk110
adobe96
mozilla93
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco13
apple8
google7
fortinet6
ivanti5
berriai4
oracle4
solarwinds4
sonicwall4
Most-affected ecosystems
EcosystemAdvisories
Maven33
Packagist32
npm13
PyPI11
Go1
RubyGems1
Fastest to KEV
CVEVendorDays
CVE-2026-20349Cisco0
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-72898Metabase0
CVE-2026-8037Progress Software0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-64849mlflow1
CVE-2026-81578PaperCut3
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171753
CVE-2021-27102n/a2021-11-171753
CVE-2021-27101n/a2021-11-171753
CVE-2021-27103n/a2021-11-171753
CVE-2021-21017Adobe2021-11-171753
CVE-2021-28550Adobe2021-11-171753
CVE-2021-42013Apache Software Foundation2021-11-171753
CVE-2021-41773Apache Software Foundation2021-11-171753
CVE-2021-30858Apple2021-11-171753
CVE-2021-30860Apple2021-11-171753

Transactions

EXPLOIT PUBLISHED — CVE-2026-4740 (Red Hat multicluster engine for Kubernetes 2.1). Public exploit reference added.

Yesterday's Results

How to read these box scores · glossary

131 CVEs published. 25 box scores, 106 table rows — nothing truncated.

wpmudev Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN — Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0082   54.6     —
AFFECTED
  Product                                                                                                                                 Versions     Fixed
  Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN  unspecified  —
TIMELINE
  Aug 31  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Received
JoomUnited WP File Download — WP File Download <= 6.3.8 - Authenticated (Subscriber+) Arbitrary File Read via Path Traversal in 'remoteurl' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0068   49.7     —
AFFECTED
  Product           Versions     Fixed
  WP File Download  unspecified  —
TIMELINE
  Jul 7   Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 3 references · NVD status: Received
uscnanbu Welcart e-Commerce — Welcart e-Commerce <= 2.12.1 - Unauthenticated Arbitrary File Deletion via PHP Object Injection via 'reserve' Checkout Parameter and 'option' EDY Callback
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0057   45.0     —
AFFECTED
  Product             Versions     Fixed
  Welcart e-Commerce  unspecified  —
TIMELINE
  Aug 14  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-502 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Received
pickplugins Post Grid — Post Grid and Gutenberg Blocks – ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0044   36.8     —
AFFECTED
  Product    Versions  Fixed
  Post Grid  2.2.85 –  —
TIMELINE
  Nov 11  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · CVSS v3.1 · 4 references · NVD status: Received
inspireui MStore API – Create Native Android & iOS Apps On The Cloud — MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0038   31.0     —
AFFECTED
  Product                                                     Versions     Fixed
  MStore API – Create Native Android & iOS Apps On The Cloud  unspecified  —
TIMELINE
  Jun 26  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-287 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Received
supsysticcom Contact Form by Supsystic — Contact Form by Supsystic <= 1.10.2 - Unauthenticated Stored Cross-Site Scripting via IP Address Header
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0033   25.6     —
AFFECTED
  Product                    Versions     Fixed
  Contact Form by Supsystic  unspecified  —
TIMELINE
  Aug 31  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 12 references · NVD status: Received
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  L    8.2   .0032   24.0     —
AFFECTED
  Product  Versions  Fixed
  PCRE2    10.32 –   —
TIMELINE
  Sep 5   Reserved by CNA
  Sep 5   Published (CNA: mitre)
CWE-424 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Received
outlawgt Custom Contact Forms — Custom Contact Forms <= 7.16 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Deletion and Post Meta Modification via Nested 'fields[].ID' / 'choices[].ID' Parameters
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0030   22.1     —
AFFECTED
  Product               Versions     Fixed
  Custom Contact Forms  unspecified  —
TIMELINE
  Aug 17  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 14 references · NVD status: Received
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more <= 3.13.4 - Unauthenticated Stored Cross-Site Scripting via Comment Content via AdSense Regex Rewrite
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0029   21.4     —
AFFECTED
  Product                                                                Versions     Fixed
  iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Received
boldgrid W3 Total Cache — W3 Total Cache <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutator
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0029   20.9     —
AFFECTED
  Product         Versions     Fixed
  W3 Total Cache  unspecified  —
TIMELINE
  Aug 24  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Received
brainstormforce SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz — SureForms <= 2.12.2 - Unauthenticated Stored Cross-Site Scripting via Text Field Entity-Encoded Payload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0029   20.7     —
AFFECTED
  Product                                                                  Versions     Fixed
  SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz  unspecified  —
TIMELINE
  Jul 30  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 9 references · NVD status: Received
Elegant Themes Divi — Divi <= 4.27.6 - Authenticated (Contributor+) Server-Side Request Forgery via 'image_src' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  N  N    5.0   .0027   19.6     —
AFFECTED
  Product  Versions     Fixed
  Divi     unspecified  —
TIMELINE
  Mar 17  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-918 · CNA: Wordfence · CVSS v3.1 · 3 references · NVD status: Received
cleantalk Spam protection, Honeypot, Anti-Spam by CleanTalk — Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.86 - Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label Placeholder
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0027   19.3     —
AFFECTED
  Product                                            Versions     Fixed
  Spam protection, Honeypot, Anti-Spam by CleanTalk  unspecified  —
TIMELINE
  Aug 21  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 12 references · NVD status: Received
kstover Ninja Forms – The Contact Form Builder That Grows With You — Ninja Forms <= 3.15.1 - Unauthenticated Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0025   15.9     —
AFFECTED
  Product                                                     Versions     Fixed
  Ninja Forms – The Contact Form Builder That Grows With You  unspecified  —
TIMELINE
  Aug 13  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Received
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more <= 3.13.4 - Unauthenticated Stored Cross-Site Scripting via Comment Content
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0025   15.9     —
AFFECTED
  Product                                                                Versions     Fixed
  iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Received
Tyche Softwares Abandoned Cart Pro for WooCommerce — Abandoned Cart Pro for WooCommerce <= 10.7.1 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0025   15.7     —
AFFECTED
  Product                             Versions     Fixed
  Abandoned Cart Pro for WooCommerce  unspecified  —
TIMELINE
  Aug 27  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Received
fooplugins Gallery : FooGallery — Gallery : FooGallery <= 3.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0024   15.2     —
AFFECTED
  Product               Versions     Fixed
  Gallery : FooGallery  unspecified  —
TIMELINE
  Sep 3   Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 12 references · NVD status: Received
jfarthing84 Theme My Login — Theme My Login <= 7.1.15 - Authenticated (Subscriber+) Missing Authorization to Unauthorized Multisite Subsite Creation via 'gimmeanotherblog' Signup Stage
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0024   15.0     —
AFFECTED
  Product         Versions     Fixed
  Theme My Login  unspecified  —
TIMELINE
  Aug 31  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Received
netweblogic Events Manager – Calendar, Bookings, Tickets, and more! — Events Manager - Calendar, Bookings, Tickets, and more! <= 7.3.3 - Unauthenticated Stored Cross-Site Scripting via Event Attributes
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  C  L  L  N    5.4   .0022   12.0     —
AFFECTED
  Product                                                  Versions     Fixed
  Events Manager – Calendar, Bookings, Tickets, and more!  unspecified  —
TIMELINE
  Dec 19  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 4 references · NVD status: Received
unitecms Unlimited Elements For Elementor — Unlimited Elements For Elementor <= 2.0.17 - Reflected Cross-Site Scripting via 'formData[id]' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  L  N    6.1   .0022   11.8     —
AFFECTED
  Product                           Versions     Fixed
  Unlimited Elements For Elementor  unspecified  —
TIMELINE
  Aug 17  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Received
dearhive DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer — Dear Flipbook <= 2.4.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via '.dvcss' Element Class Attribute
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0021   11.5     —
AFFECTED
  Product                                                      Versions     Fixed
  DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer  unspecified  —
TIMELINE
  May 14  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Received
dearhive DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer — Dear Flipbook <= 2.4.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via '.df-element' Element Inner HTML
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0021   10.6     —
AFFECTED
  Product                                                      Versions     Fixed
  DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer  unspecified  —
TIMELINE
  May 14  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Received
quadlayers Social Chat – Click To Chat App Button — Social Chat <= 8.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0020   10.0     —
AFFECTED
  Product                                 Versions     Fixed
  Social Chat – Click To Chat App Button  unspecified  —
TIMELINE
  Jul 30  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Received
sc0ttkclark Pods – Custom Content Types and Fields — Pods <= 3.3.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'not_found' Shortcode Attribute
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0020   10.0     —
AFFECTED
  Product                                 Versions     Fixed
  Pods – Custom Content Types and Fields  unspecified  —
TIMELINE
  Aug 19  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Received
Themovation QuickCal — QuickCal <= 1.0.20 - Unauthenticated Stored Cross-Site Scripting via Custom Field Parameters
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0019    8.7     —
AFFECTED
  Product   Versions     Fixed
  QuickCal  unspecified  —
TIMELINE
  Jul 16  Reserved by CNA
  Sep 5   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-166497.28.7Gravity FormsGravity FormsCWE-79Gravity Forms <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via Pos…
CVE-2026-82304await8.7UnknownMusic Store—Music Store – WordPress eCommerce < 1.4.5 - Unauthenticated SQLi via paypal-d…
CVE-2026-19861await8.1UnknownJetFormBuilder — Dynamic Blocks Form Builder—JetFormBuilder < 3.6.5.2 - Unauthenticated Stored XSS via WYSIWYG Field in No…
CVE-2026-81404await8.1UnknownIPGP Visitors Origin—IPGP Visitors Origin < 1.6 - Reflected XSS
CVE-2025-15694await7.4UnknownJoli Table Of Contents—Joli Table Of Contents 2.0.0 - 2.8.0 - Admin+ Stored XSS
CVE-2026-188436.16.4The Beaver Builder TeamBeaver Builder Plugin (Starter Version)CWE-79Beaver Builder Plugin (Pro Version) <= 2.11.0.1 - Reflected Cross-Site Script…
CVE-2026-38536.46.0Elegant ThemesDiviCWE-79Divi <= 4.27.6 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scr…
CVE-2026-861445.65.6xmlsoftlibxml2CWE-669In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProce…
CVE-2025-15693await5.5UnknownJCH Optimize—JCH Optimize 4.2.1 - 5.0.0 - Admin+ Path Traversal
CVE-2026-81423await5.4UnknownAccept Stripe Payments—Accept Stripe Payments < 2.1.4 - Open Redirect via IPN Handler
CVE-2026-84934await5.3UnknownJCH Optimize—JCH Optimize < 6.0.1 - Subscriber+ Stored XSS via getcacheinfo Task Override
CVE-2026-84898await5.2UnknownEventin—Eventin < 4.1.21 - Contributor+ LFI via Event Layout Meta
CVE-2026-19858await5.1UnknownJetFormBuilder — Dynamic Blocks Form Builder—JetFormBuilder < 3.6.5.2 - Unauthenticated Password Hash and Arbitrary Metada…
CVE-2026-78149await5.1UnknownSmart Post—Post Carousel 4.0.0 - 4.0.7 - Unauthenticated Password-Protected Post Content…
CVE-2026-81348await5.1UnknownMy Private Site—My Private Site < 4.2.3 - Unauthenticated Sensitive Information Exposure via …
CVE-2026-84937await5.1UnknownVideo Player for YouTube—YT Player < 2.1.0 - Contributor+ SQLi via ytp_ajax
CVE-2026-82846await4.7UnknownMasteriyo LMS—Masteriyo LMS 1.18.0 - 2.3.3 - Instructor+ Stored XSS via Course Custom Fields
CVE-2026-83544await4.7UnknownGreenshift—Greenshift < 13.2.0 - Contributor+ Stored XSS via Block Animation customProps…
CVE-2026-84021await4.7UnknownBold Page Builder—Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via bt_bb_button/bt_bb_he…
CVE-2026-84022await4.7UnknownBold Page Builder—Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via Multiple Shortcode El…
CVE-2026-84221await4.7UnknownKirki—Kirki 6.0.0 - 6.2.5 - Editor+ SQLi via Content Manager Field ID
CVE-2026-84896await4.7UnknownKing Addons for Elementor—King Addons for Elementor < 51.1.77 - Contributor+ Stored XSS via Magazine Gr…
CVE-2026-84899await4.7UnknownVikWidgetsLoader—VikWidgetsLoader < 1.12.0 - Contributor+ Stored XSS via Gutenberg Block class…
CVE-2026-84930await4.7UnknownCatFolders Document Gallery & PDF Library—CatFolders Document Gallery < 2.0.7 - Author+ Stored XSS via titleTag Block A…
CVE-2026-84931await4.7UnknownJoli Table Of Contents—Joli Table Of Contents < 3.0.3 - Author+ Stored XSS via joli-toc Shortcode Th…
CVE-2026-84935await4.7UnknownHT Menu—HT Menu < 1.2.7 - Subscriber+ Stored XSS via Menu Settings
CVE-2026-77826await4.2UnknownRegistrationMagic—RegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentication Bypass v…
CVE-2026-78362await4.2UnknownSEO Flow by LupsOnline—SEO Flow by LupsOnline 3.0.0 - 3.0.2 - Unauthenticated Privilege Escalation v…
CVE-2026-81424await4.2UnknownAccept Stripe Payments—Accept Stripe Payments < 2.1.4 - Unauthenticated Product Substitution via IDOR
CVE-2026-15247await3.8UnknownSearch Atlas SEO—Search Atlas SEO < 2.6.24 - Subscriber+ Google Service Account Credential Ove…
CVE-2026-78150await3.8UnknownSmart Post—Post Carousel 4.0.0 - 4.0.7 - Contributor+ Private and Protected Post Content…
CVE-2026-84745await3.6UnknownThe Events Calendar—The Events Calendar &lt; 6.17.3.1 - Contributor+ Non-Public Event, Venue and …
CVE-2026-84926await3.6UnknownEmbedPress—EmbedPress 4.6.0 - 4.6.3 - Contributor+ Administrator Email Disclosure via Go…
CVE-2026-861408.03.3xmlsoftlibxml2CWE-121In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-b…
CVE-2026-84936await3.4UnknownEmbedPress—EmbedPress 4.6.0 - 4.6.3 - Unauthenticated Google Reviews API Quota Consumpti…
CVE-2026-861426.93.0xmlsoftlibxml2CWE-122In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEva…
CVE-2026-83543await3.1UnknownGreenshift—Greenshift < 13.2.0 - Contributor+ SSRF via get-csv-to-json REST Endpoint
CVE-2026-84225await3.1UnknownKirki—Kirki 6.0.0 - 6.2.5 - Authenticated Collaboration Comment Status Modification…
CVE-2026-84901await3.1UnknownEventin—Eventin < 4.1.22 - Contributor+ Site Homepage Hijack and Event Taxonomy Manip…
CVE-2026-84927await3.1UnknownEmbedPress—EmbedPress 4.6.0 - 4.6.3 - Contributor+ Google Reviews Modification
CVE-2026-861386.92.0xmlsoftlibxml2CWE-190In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow…
CVE-2026-861436.92.0xmlsoftlibxml2CWE-192In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback…
CVE-2026-861372.91.8xmlsoftlibxml2CWE-125In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, a…
CVE-2026-861412.91.8xmlsoftlibxml2CWE-252xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNe…
CVE-2026-861396.91.3xmlsoftlibxml2CWE-190In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
CVE-2026-101969.8—getwpfunnelsMail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce EmailsCWE-502Mail Mint <= 1.31.0 - Unauthenticated PHP Object Injection in Arbitrary Form …
CVE-2026-861239.4—sqlchatsqlchatCWE-918SQL Chat Unauthenticated Database-Connection Proxy in the /api/connection End…
CVE-2026-861489.4—TendaCP3CWE-77Tenda CP3 Kylin system.c SystemAsh os command injection
CVE-2026-861499.4—TendaCP3CWE-77Tenda CP3 NetCheckPing.cpp os command injection
CVE-2026-861519.4—TendaCP3CWE-78Tenda CP3 Network Configuration Management system.c sub_2F77E8 os command inj…
CVE-2026-861219.3—trycuacua-computer-serverCWE-306Cua computer-server before 0.3.42 Unauthenticated RCE via Desktop Control
CVE-2026-861249.3—HKUDSAutoAgentCWE-306AutoAgent Unauthenticated Remote Code Execution via the Sandbox TCP Command S…
CVE-2026-861849.3—laradashboardlaradashboardCWE-306Lara Dashboard before 1.3.0 Missing Authentication in screenshot-login Route
CVE-2026-861899.3—WWBNAVideoCWE-73WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php
CVE-2026-861909.3—WWBNAVideoCWE-200WWBN AVideo Broken Access Control via videoViewsInfo hash Parameter
CVE-2026-672769.2—MikrotikRouterOSCWE-347SSH user impersonation possible in Mikrotik RouterOS
CVE-2026-860609.2—MikrotikRouterOSCWE-88SSH session privilege manipulation via a crafted username in Mikrotik RouterOS
CVE-2026-861179.2—coollabsiocoolifyCWE-287Coolify through 4.3.17 OAuth Account Takeover via Unverified Email Matching
CVE-2026-861199.2—webstudio-iswebstudioCWE-918Webstudio through 0.296.0 SSRF via /cgi proxy routes
CVE-2025-90498.8—scriptsbundleNokri – Job Board WordPress ThemeCWE-862Nokri – Job Board WordPress Theme <= 1.6.4 - Missing Authorization to Authent…
CVE-2026-672778.8—MikrotikRouterOSCWE-306Kernel memory disclosure and denial of service in MikroTik RouterOS btest ser…
CVE-2026-07998.7—The Tcpdump GrouplibpcapCWE-125OOBR and OOBW in libpcap before 1.10.7
CVE-2026-672818.7—MikrotikRouterOSCWE-22Unauthenticated file read in Mikrotik RouterOS
CVE-2026-861698.7—axolotl-ai-cloudaxolotlCWE-829Axolotl through 0.18.0 Remote Code Execution via Multipack Patching
CVE-2026-861738.7—mindsdbmindsdbCWE-918MindsDB through 26.1.0 Unauthenticated SSRF via Web Crawler
CVE-2026-861778.7—pterodactylpanelCWE-862Pterodactyl Panel before 1.14.1 Privilege Escalation via Schedule Tasks
CVE-2026-861938.7—getgravgrav-plugin-apiCWE-863Grav API Plugin Authentication Bypass via Group-Inherited Super
CVE-2026-861958.7—getgravgrav-plugin-apiCWE-269grav-plugin-api 1.0.0 through 1.0.19 Privilege Escalation via Dot-Keyed Super…
CVE-2026-861968.7—getgravgrav-plugin-apiCWE-290Grav API Plugin before 1.0.20 Authentication Bypass via Host Header
CVE-2026-861858.6—BilibiliBilibili DesktopCWE-295Bilibili Desktop through 1.18.0 Remote Code Execution via TLS Verification By…
CVE-2026-862077.7—N-ableN-centralCWE-305Authentication bypass leads to unauthorised access to N-central
CVE-2026-861877.4—WWBNAVideoCWE-330WWBN AVideo Weak PRNG Password Generation via External Login
CVE-2026-861117.1—bookwyrm-socialbookwyrmCWE-639BookWyrm through 0.9.1 Insecure Direct Object Reference in EditStatus Exposes…
CVE-2026-861137.1—bookwyrm-socialbookwyrmCWE-639BookWyrm through 0.9.1 Insecure Direct Object Reference in edit-readthrough A…
CVE-2026-861147.1—getarcaneapparcaneCWE-862Arcane before 2.0.0 Missing Administrator Authorization on the Compose Templa…
CVE-2026-861167.1—metabasemetabaseCWE-862Metabase before 0.63.1 Missing Function-Level Authorization on the Glossary M…
CVE-2026-861757.1—netbox-communitynetboxCWE-522NetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIs
CVE-2026-861927.1—siyuan-notesiyuanCWE-639SiYuan before v3.8.2 Information Disclosure via Attribute-View
CVE-2026-672796.9—MikrotikRouterOSCWE-841SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS
CVE-2026-861886.9—WWBNAVideoCWE-79AVideo YPTSocket Plugin Unauthenticated Cross-Site Scripting
CVE-2026-861946.9—getgravgrav-plugin-formCWE-862Grav Form Plugin before 9.1.22 Cross-Page Form Execution
CVE-2026-862066.9—N-ableN-centralCWE-791Access control filter bypass allows unauthorised access to APIs
CVE-2025-156476.8—artem-ogreCDTCWE-125CDT before 1.4.5 Out-of-Bounds Read via opposedVertexInd
CVE-2026-672786.3—MikrotikRouterOSCWE-347TLS server impersonation possible in Mikrotik RouterOS
CVE-2026-861866.3—WWBNAVideoCWE-307AVideo API Rate Limit Bypass via Bot User-Agent Header
CVE-2026-827525.9—ash-projectashCWE-1284Ash string length constraints count graphemes, so a combining-mark string of …
CVE-2026-62445.5—The Tcpdump GrouplibpcapCWE-369division by zero in libpcap before 1.10.7
CVE-2026-65545.5—The Tcpdump GrouplibpcapCWE-835infinte loop in libpcap before 1.10.7
CVE-2026-319115.5—The Tcpdump GrouplibpcapCWE-617abort() in libpcap before 1.10.7 on an invalid BPF opcode
CVE-2026-319125.5—The Tcpdump GrouplibpcapCWE-125OOBR in libpcap before 1.10.7
CVE-2026-128435.4—StellarWPLearnDash LMSCWE-862LearnDash LMS 4.25.0 - 5.1.6 - Unauthenticated Arbitrary Course Enrollment vi…
CVE-2026-861125.3—bookwyrm-socialbookwyrmCWE-639BookWyrm through 0.9.1 Missing Authorization on the Favorite and Unfavorite E…
CVE-2026-861155.3—simstudioaisimCWE-441Sim before 0.8.14 Confused Deputy in Tool URL Routing Mints an Internal Token…
CVE-2026-861185.3—sentrizgonicCWE-862gonic before 0.22.0 Missing Administrator Check on the Subsonic startScan End…
CVE-2026-861205.3—apitableapitableCWE-636APITable through 1.13.0-beta.1 Fail-Open Authorization in the Fusion API Node…
CVE-2026-861225.3—rowboatlabsrowboatCWE-918Rowboat through 0.9.1 Server-Side Request Forgery via Custom MCP Server
CVE-2026-861745.3—makeplaneplaneCWE-639Plane through 1.4.2 Arbitrary Comment Write via Public Deploy Board
CVE-2026-861765.3—netbox-communitynetboxCWE-639NetBox through 4.7.0 Information Disclosure via REST and GraphQL APIs
CVE-2026-861785.3—pixelfedpixelfedCWE-862Pixelfed through 0.12.9 Unauthorized Story Access via API
CVE-2026-861915.3—siyuan-notesiyuanCWE-639SiYuan before v3.8.2 Private Attribute View Key Enumeration
CVE-2026-861975.1—getgravgravCWE-79Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox
CVE-2026-182385.0—The Tcpdump GrouplibpcapCWE-126OOBR in rpcap client in libpcap before 1.10.7
CVE-2025-156144.8—GeniviaugrepCWE-125ugrep before 7.6.0 Heap Buffer Over-read via .Z decompression
CVE-2026-155504.3—Saturday DriveNinja Forms - Save ProgressCWE-862Ninja Forms - Save Progress <= 3.0.30 - Missing Authorization to Authenticate…
CVE-2026-183134.3—The Tcpdump GrouplibpcapCWE-401rpcapd memory leak in libpcap before 1.10.7
CVE-2026-861502.0—TendaCP3CWE-259Tenda CP3 hostapd hard-coded credentials

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-05 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.