boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Saturday, September 19, 2026 · all times UTC← 2026-09-18 · archive

Security Box Score — September 19, 2026

103 CVEs published, led by Exim (4).

103 CVEs published September 19, 2026: 7 critical, 23 high, 62 medium, 10 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 78 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1043845380——
KEV catalog size1716

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2836 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux15075597526251371211560.17.8.0017+245 ▲
microsoft10002899204198469516289301.07.8.0044+554 ▲
google5162682331104811821218090.37.5.0025+452 ▲
red hat1567824432437440200.06.6.0028-16 ▼
apple24656367165317148881.46.5.0020+212 ▲
freebsd04823673000.07.8.0016-23 ▼
canonical0421311135000.07.8.0021-11 ▼
suse1341721121000.07.5.0036+8 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco97181537255159168.87.7.0039+51 ▲
ubiquiti059362210335.19.1.00490
palo alto networks9461426151324.34.7.0022-3 ▼
fortinet1040101017329717.57.0.0038+3 ▲
netgear23400277000.04.3.0025-7 ▼
f582561441414.08.7.0045+8 ▲
ivanti10246162025520.88.8.0147+7 ▲
sonicwall519784019421.18.3.0050-5 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache93605140253195153320.37.5.0049-8 ▼
mozilla11330081118670900.08.8.0026+54 ▲
drupal2694119668411.15.7.0024+26 ▲
gitlab17935235510533.25.3.0032+2 ▲
github32011090000.07.3.0044-2 ▼
docker3121830000.08.4.0016+1 ▲
wordpress0513102240.08.8.3120-2 ▼
go440211000.05.9.0029+4 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle634290558116605631012840.17.8.0034-255 ▼
ibm29791618341530513610.17.5.0030-2 ▼
adobe17177757344366102040.57.5.0023+111 ▲
progress3641539100611.68.1.0035-16 ▼
solarwinds1241743010416.79.1.0058+1 ▲
veeam01961030100.08.6.0032-10 ▼
zohocorp7173860000.07.7.0106+3 ▲
atlassian3918001300.07.6.00320
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link216619241112300.08.5.0154+5 ▲
siemens1552633103000.07.3.0018-4 ▼
synology1946510256000.05.6.0027+18 ▲
rockwell automation184353260000.08.6.0029+17 ▲
advantech172021710000.08.6.0068+17 ▲
schneider electric91821150000.08.5.0040+9 ▲
hikvision390540000.07.1.0036+3 ▲
abb181430000.07.2.0018+1 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1773482616613323210.37.2.0021+121 ▲
sourcecodester482170012889000.05.5.0028+18 ▲
spring017013608215000.06.5.00240
nvidia3216620117290000.07.8.0029+8 ▲
mongodb64162694584100.07.1.0026+32 ▲
itsourcecode341500037113000.02.1.0026+17 ▲
wwbn1061462349740000.06.9.0024+104 ▲
hewlett packard enterprise (hpe)1291381571466110.77.2.0029+126 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-60004.867899.79.8
CVE-2026-85706.145696.510.0
CVE-2026-83549.085194.87.8
CVE-2026-82329.076794.39.8
CVE-2026-86218.074994.210.0
CVE-2026-79756.051592.08.7
CVE-2026-83548.046791.310.0
CVE-2026-77806.042090.59.8
CVE-2026-76698.041190.36.5
CVE-2026-47864.040890.29.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.1456KEV
CVE-2026-8621810.0.0749KEV
CVE-2026-8354810.0.0467KEV
CVE-2026-7565010.0.0215KEV
CVE-2026-8615210.0.0186
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-8222210.0.0155
CVE-2026-8200410.0.0144
CVE-2026-8245610.0.0139
Most disclosures (vendor)
VendorCVEs
linux1889
microsoft1010
google847
oracle635
ibm313
apple252
adobe212
red hat197
dell193
apache151
Most KEV additions (YTD)
VendorKEV
microsoft30
cisco16
google9
apple8
fortinet7
linux6
ivanti5
adobe4
berriai4
jfrog4
Most-affected ecosystems
EcosystemAdvisories
Maven93
Packagist41
npm19
PyPI15
crates.io3
Go2
RubyGems2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2026-58704Google0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-87491Google0
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
CVE-2026-81578PaperCut3
CVE-2026-82078PaperCut3
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171767
CVE-2021-27102n/a2021-11-171767
CVE-2021-27101n/a2021-11-171767
CVE-2021-27103n/a2021-11-171767
CVE-2021-21017Adobe2021-11-171767
CVE-2021-28550Adobe2021-11-171767
CVE-2021-42013Apache Software Foundation2021-11-171767
CVE-2021-41773Apache Software Foundation2021-11-171767
CVE-2021-30858Apple2021-11-171767
CVE-2021-30860Apple2021-11-171767

Transactions

EXPLOIT PUBLISHED — GitLab: 3 CVEs (CVE-2026-12910, CVE-2026-13210, CVE-2026-82837). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-61516 (Netis Systems NX10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82536 (RooCodeInc Roo-Code). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86749 (grokability snipe-it). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90509 (dromara orion-visor). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90515 (SourceCodester School Registration and Fee System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90520 (jaychouchannel Tourism-Management-System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90525 (itsourcecode Sales and Inventory System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90940 (201206030 novel-plus). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-91836 (OpenClaw ClawScan). Public exploit reference added.

DUE DATE PASSED — CVE-2026-85046 (Google Chrome). CISA remediation deadline was September 18, 2026; still in catalog.

RESCORED — CVE-2025-39964 (Linux). CVSS 3.3 → 5.5 (NVD).

Yesterday's Results

How to read these box scores · glossary

103 CVEs published. 25 box scores, 78 table rows — nothing truncated.

Totolink A3002MU formWsc command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0188   78.5     —
AFFECTED
  Product  Versions             Fixed
  A3002MU  Hh-B20211125.1046 –  —
TIMELINE
  Sep 18  Reserved by CNA
  Sep 19  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload Field
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0070   51.6     —
AFFECTED
  Product        Versions     Fixed
  Gravity Forms  unspecified  —
TIMELINE
  Sep 1   Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Received
sebwordpress The Welcomizer — The Welcomizer <= 2.8.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'twiz_custom_logic' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0070   51.6     —
AFFECTED
  Product         Versions     Fixed
  The Welcomizer  unspecified  —
TIMELINE
  Mar 17  Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · CVSS v3.1 · 12 references · NVD status: Received
Totolink A3002MU formWlWds buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0064   49.4     —
AFFECTED
  Product  Versions             Fixed
  A3002MU  Hh-B20211125.1046 –  —
TIMELINE
  Sep 18  Reserved by CNA
  Sep 19  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
opajaap WP Photo Album Plus — WP Photo Album Plus <= 9.2.09.002 - Authenticated (Subscriber+) Remote Code Execution via Multipart Upload Filename via ImageMagick Argument Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0053   43.5     —
AFFECTED
  Product              Versions     Fixed
  WP Photo Album Plus  unspecified  —
TIMELINE
  Sep 9   Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-74 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Received
wpmudev Forminator Forms – Contact Form, Payment Form & Custom Form Builder — Forminator Forms <= 1.57.2 - Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0040   34.2     —
AFFECTED
  Product                                                              Versions     Fixed
  Forminator Forms – Contact Form, Payment Form & Custom Form Builder  unspecified  —
TIMELINE
  Sep 15  Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Received
wordplus Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots — Better Messages <= 2.15.33 - Missing Authorization to Authenticated (Custom+) Chat-Room Transcript Disclosure via '/thread/<id>' REST Endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0040   33.9     —
AFFECTED
  Product                                                                    Versions     Fixed
  Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots  unspecified  —
TIMELINE
  Sep 11  Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 9 references · NVD status: Received
mdmag Quill Forms | Conversational Multi Step Forms, Surveys & quizzes — Quill Forms | Conversational Multi Step Forms, Surveys & quizzes <= 5.7.1 - Unauthenticated Stored Cross-Site Scripting via Multiple Choice 'Other' Value
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0039   32.6     —
AFFECTED
  Product                                                           Versions     Fixed
  Quill Forms | Conversational Multi Step Forms, Surveys & quizzes  unspecified  —
TIMELINE
  Jul 13  Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 14 references · NVD status: Received
brechtvds WP Recipe Maker — WP Recipe Maker <= 10.8.1 - Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0038   31.8     —
AFFECTED
  Product          Versions     Fixed
  WP Recipe Maker  unspecified  —
TIMELINE
  Sep 11  Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Received
properfraction Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'eup_bio' Biography Field (Entity-Encoded Shortcode Bracket)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  N    8.1   .0036   29.9     —
AFFECTED
  Product                                                                                                                Versions     Fixed
  Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress  unspecified  —
TIMELINE
  Sep 4   Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Received
WordLift <= 3.54.10 - Unauthenticated Sensitive Information Exposure in JSON-LD REST API Endpoints
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0036   29.4     —
AFFECTED
  Product                             Versions     Fixed
  WordLift – AI powered SEO – Schema  unspecified  —
TIMELINE
  May 22  Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-200 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Received
hiroaki-miyashita Custom Field Template — Custom Field Template <= 2.7.8 - Authenticated (Contributor+) SQL Injection via 'post_ID' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0034   28.1     —
AFFECTED
  Product                Versions     Fixed
  Custom Field Template  unspecified  —
TIMELINE
  May 28  Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Received
Datalogics Ecommerce Delivery <= 2.6.65 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions (datalogics_create_shipping / datalogics_cancel_shipping)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0034   28.0     —
AFFECTED
  Product                                     Versions     Fixed
  Datalogics Ecommerce Delivery – Datalogics  unspecified  —
TIMELINE
  May 26  Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 18 references · NVD status: Received
bompus WP Customer Reviews — WP Customer Reviews <= 3.7.8 - Reflected Cross-Site Scripting via 'wpcr3_fname' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  L  N    6.1   .0033   26.6     —
AFFECTED
  Product              Versions     Fixed
  WP Customer Reviews  unspecified  —
TIMELINE
  Jun 8   Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Received
radius314 Bread — Bread <= 2.9.12 - Missing Authorization to Unauthenticated Information Exposure
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0033   26.5     —
AFFECTED
  Product  Versions     Fixed
  Bread    unspecified  —
TIMELINE
  Mar 24  Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Received
wordplus Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots — Better Messages <= 2.15.33 - Unauthenticated Information Exposure Spoofing via 'X-Real-IP' Header via /guests/register
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0032   25.8     —
AFFECTED
  Product                                                                    Versions     Fixed
  Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots  unspecified  —
TIMELINE
  Sep 10  Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-287 · CNA: Wordfence · CVSS v3.1 · 9 references · NVD status: Received
sh1zen WP Optimizer – PageSpeed, Cache, Minify & Core Web Vitals — WP Optimizer <= 2.5.0 - Authenticated (Administrator+) SQL Injection via 's' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0030   23.1     —
AFFECTED
  Product                                                    Versions     Fixed
  WP Optimizer – PageSpeed, Cache, Minify & Core Web Vitals  unspecified  —
TIMELINE
  Apr 14  Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Received
ysinnovations YS LeadGen – Popup Builder, Popup Maker & Form Builder for WordPress | Lead Generation, Email Marketing, Sales, Conversions, Opt-Ins & Subscribers — YS LeadGen – Popups, Opt-ins & Lead Capture <= 2.1.4 - Unauthenticated Information Disclosure in 'ysleadgen_get_captured_data' AJAX Action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0029   22.4     —
AFFECTED
  Product                                                                                                                                             Versions     Fixed
  YS LeadGen – Popup Builder, Popup Maker & Form Builder for WordPress | Lead Generation, Email Marketing, Sales, Conversions, Opt-Ins & Subscribers  unspecified  —
TIMELINE
  Jan 20  Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-200 · CNA: Wordfence · CVSS v3.1 · 3 references · NVD status: Received
mischiefmarmot Create — Create <= 2.5.3 - Authenticated (Author+) SQL Injection via 'order_by' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0028   20.9     —
AFFECTED
  Product  Versions     Fixed
  Create   unspecified  —
TIMELINE
  Jun 24  Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Received
themeum Tutor LMS – eLearning and online course solution — Tutor LMS <= 4.0.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'lesson_id' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0028   20.8     —
AFFECTED
  Product                                           Versions     Fixed
  Tutor LMS – eLearning and online course solution  unspecified  —
TIMELINE
  Sep 10  Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 9 references · NVD status: Received
wowelements Wow Elements Addons for Elementor — Wow Elements Addons for Elementor <= 1.11.2 - Authenticated (Contributor+) Server-Side Request Forgery via Changelog File Setting
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  L    6.5   .0028   20.3     —
AFFECTED
  Product                            Versions     Fixed
  Wow Elements Addons for Elementor  unspecified  —
TIMELINE
  Jan 29  Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-918 · CNA: Wordfence · CVSS v3.1 · 4 references · NVD status: Received
easyappointments Easy Appointments — Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Contributor+) Sensitive Customer Information Exposure via ea_get_customers_ajax AJAX Action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0027   19.4     —
AFFECTED
  Product            Versions     Fixed
  Easy Appointments  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Received
themeum Tutor LMS – eLearning and online course solution — Tutor LMS <= 4.0.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'student_id' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0027   19.3     —
AFFECTED
  Product                                           Versions     Fixed
  Tutor LMS – eLearning and online course solution  unspecified  —
TIMELINE
  Sep 11  Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-639 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Received
gopayplugins GoPay for WooCommerce — GoPay for WooCommerce <= 1.0.36 - Authenticated (Shop Manager+) SQL Injection via 'log_table_filter' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0027   19.1     —
AFFECTED
  Product                Versions     Fixed
  GoPay for WooCommerce  unspecified  —
TIMELINE
  Aug 18  Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Received
tiktokbusinessplugin TikTok — TikTok <= 1.4.1 - Missing Authorization to Unauthenticated TikTok Integration Takeover via 'auth_code' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0026   18.1     —
AFFECTED
  Product  Versions     Fixed
  TikTok   unspecified  —
TIMELINE
  Jul 29  Reserved by CNA
  Sep 19  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-928078.817.2pdfcrowdSave as PDF Plugin by PDFCrowdCWE-94Save as PDF Plugin by PDFCrowd <= 4.6.1 - Authenticated (Contributor+) Arbitr…
CVE-2026-96154.316.7flexthemeFlex ImportCWE-862Flex Import <= 3.0 - Missing Authorization to Authenticated (Subscriber+) Arb…
CVE-2026-132006.516.5mischiefmarmotCreateCWE-89Create <= 2.5.3 - Authenticated (Author+) SQL Injection via 'order' Parameter
CVE-2026-778206.415.7stellarwpWPCompleteCWE-79WPComplete <= 2.9.9.0 - Authenticated (Contributor+) Stored Cross-Site Script…
CVE-2026-133547.215.6gabelivanAsset CleanUp: Page Speed BoosterCWE-79Asset CleanUp: Page Speed Booster <= 1.4.0.5 - Unauthenticated Stored Cross-S…
CVE-2026-54006.415.6davidandersonRedux FrameworkCWE-79Redux Framework <= 4.5.13 - Authenticated (Subscriber+) Cross-Site Scripting …
CVE-2026-97664.314.4empikEmpik for WoocommerceCWE-862Empik for Woocommerce <= 1.5.1 - Missing Authorization to Authenticated (Subs…
CVE-2026-159464.314.4shahrukhlinkgraphSearch Atlas SEO – OTTO AI SEO Automation for WordPressCWE-862Search Atlas SEO <= 2.6.23 - Missing Authorization to Authenticated (Subscrib…
CVE-2026-765794.714.1litespeedtechLiteSpeed CacheCWE-79LiteSpeed Cache <= 7.9 - Reflected Cross-Site Scripting via ESI 'esi' Parameter
CVE-2026-19845.313.8vowelwebIbtana – Ecommerce Product AddonsCWE-862Ibtana – Ecommerce Product Addons <= 0.4.7.7 - Missing Authorization to Authe…
CVE-2026-98325.313.6themehighPayment Gateway of Stripe for WooCommerceCWE-347Payment Gateway of Stripe for WooCommerce <= 5.0.8 - Unauthenticated Improper…
CVE-2026-75274.713.3johndarrelHide My WP Ghost – Security & FirewallCWE-601WP Ghost (Hide My WP Ghost) <= 7.0.02 - Unauthenticated Open Redirect via 're…
CVE-2026-157606.513.0Divi EssentialDivi EssentialsCWE-862Divi Essentials <= 5.8.1 - Missing Authorization to Authenticated (Subscriber…
CVE-2026-54106.412.3davidandersonRedux FrameworkCWE-79Redux Framework <= 4.5.13 - Authenticated (Subscriber+) Stored Cross-Site Scr…
CVE-2026-879176.112.2dvankootenMC4WP: Mailchimp for WordPressCWE-79MC4WP: Mailchimp for WordPress <= 4.14.0 - Reflected Cross-Site Scripting via…
CVE-2026-890816.112.2themeumTutor LMS – eLearning and online course solutionCWE-79Tutor LMS <= 4.0.8 - Reflected Cross-Site Scripting via 'back_url' and 'searc…
CVE-2026-929676.112.2wppochippPochippCWE-79Pochipp <= 1.20.2 - Reflected Cross-Site Scripting via 'keyword' Parameter
CVE-2026-98584.312.2wpexpertshubPartial Shipment for WooCommerceCWE-862Partial Shipment for Woocommerce <= 3.4 - Missing Authorization to Authentica…
CVE-2026-118994.312.1edgarrojasPDF Builder for WooCommerce. Create invoices,packing slips and moreCWE-862PDF Builder for WooCommerce. Create invoices,packing slips and more <= 2.0.11…
CVE-2026-159474.312.0shahrukhlinkgraphSearch Atlas SEO – OTTO AI SEO Automation for WordPressCWE-862Search Atlas SEO <= 2.6.23 - Missing Authorization to Authenticated (Subscrib…
CVE-2026-120424.411.2f1logicWP2Social Auto PublishCWE-79WP2Social Auto Publish <= 2.4.12 - Authenticated (Administrator+) Stored Cros…
CVE-2026-24226.411.2ghozylabWP Composer – The Easiest Page BuilderCWE-79WP Composer <= 1.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripti…
CVE-2026-12566.410.7ysinnovationsYS LeadGen – Popup Builder, Popup Maker & Form Builder for WordPress | Lead Generation, Email Marketing, Sales, Conversions, Opt-Ins & SubscribersCWE-79YS LeadGen – Popups, Opt-ins & Lead Capture <= 2.1.4 - Missing Authorization …
CVE-2026-847506.510.6UnknownUltra Addons for Contact Form 7CWE-434Ultimate Addons for Contact Form 7 3.2.4 - 3.5.50 - Unauthenticated Arbitrary…
CVE-2026-83546.410.3celomitanGum Addon for ElementorCWE-79Gum Addon for Elementor <= 1.3.15 - Authenticated (Contributor+) Stored Cross…
CVE-2026-137706.410.3appmysiteAppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker)CWE-79AppMySite <= 3.15.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting…
CVE-2026-22784.39.6vowelwebVW Writer BlogCWE-862VW Writer Blog <= 1.3.8 - Missing Authorization to Authenticated (Subscriber+…
CVE-2026-156604.39.6cleverpluginsSEO BoosterCWE-862SEO Booster <= 7.4.7 - Authenticated (Subscriber+) Missing Authorization to A…
CVE-2026-124024.49.5xootixOTP Login & Register WoocommerceCWE-79OTP Login & Register Woocommerce <= 2.7.3 - Authenticated (Administrator+) St…
CVE-2026-150986.49.3creativeinteractivemediaReal3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF EmbedderCWE-79Real 3D Flipbook <= 5.1.1 - Authenticated (Contributor+) Stored Cross-Site Sc…
CVE-2026-865919.88.2UnknownBotiga ProCWE-862Botiga Pro < 1.6.5 - Unauthenticated Arbitrary Blog Options Update via Templa…
CVE-2026-924305.38.2UnknownRede Itaú for WooCommerce — Payment PIX, Credit Card and DebitCWE-862Rede Itaú for WooCommerce < 5.4.7 - Unauthenticated Order Status Manipulation…
CVE-2026-889268.67.5UnknownVikRentItems Flexible Rental Management SystemCWE-89VikRentItems Flexible Rental Management System < 1.2.4 - Unauthenticated SQLi
CVE-2026-12424.37.5blockspareBlockSpare – Gutenberg Blocks for News, Magazine, Blog & Business WebsitesCWE-863BlockSpare - Gutenberg Site Builder Blocks & Starter Sites <= 4.2.6 - Incorre…
CVE-2026-856808.87.0UnknownUltimate MemberCWE-79Ultimate Member < 2.13.1 - Unauthenticated Stored XSS via Profile Page Title
CVE-2026-888248.86.7UnknownMaster BlocksCWE-79Master Blocks 1.4.1 - 1.4.1.4 - Unauthenticated Stored XSS via White Label Se…
CVE-2026-198605.56.7UnknownJetFormBuilder — Dynamic Blocks Form BuilderCWE-73JetFormBuilder 3.5.6.2 - 3.6.5.2 - Admin+ Arbitrary File Deletion via Server-…
CVE-2026-767907.15.4UnknownEstatik Real Estate PluginCWE-79Estatik < 4.3.5 - Reflected XSS via get_listings hash Parameter
CVE-2025-156983.54.8UnknownBusiness Name GeneratorCWE-79Business Name Generator <= 1.3 - Admin+ Stored XSS via Button Color Setting
CVE-2026-924047.54.2UnknownMgoSyncCWE-200MgoSync 2.1.5 - 2.1.6 - Unauthenticated WooCommerce API Credential Disclosure
CVE-2026-165574.33.7UnknownNimble Page BuilderCWE-200Nimble Builder <= 3.3.8 - Subscriber+ Non-Public Content Disclosure via sek_g…
CVE-2026-868148.13.4UnknownUsersWPCWE-269UsersWP - Social Login < 1.5.10 - Unauthenticated Account Takeover via Unveri…
CVE-2026-920996.53.4UnknownWPGraphQL Smart CacheCWE-284WPGraphQL Smart Cache < 2.3.2 - Unauthenticated Persisted Query Registration …
CVE-2026-154636.13.4sslzenSSL Zen — SSL Certificate Installer & HTTPS RedirectsCWE-79SSL Zen <= 4.7.42 - Reflected Cross-Site Scripting via 'uri' and 'host' Param…
CVE-2026-924355.33.4UnknownMailchimp for WooCommerceCWE-862Mailchimp for WooCommerce < 6.1.1 - Unauthenticated Broken Access Control in …
CVE-2026-924033.73.4UnknownSecure Custom FieldsCWE-863Secure Custom Fields < 6.9.4 - Unauthenticated Post Modification via Front-En…
CVE-2026-855748.03.2UnknownUnbounce Landing PagesCWE-862Unbounce Landing Pages 1.1.1 - 1.1.4 - Subscriber+ Reverse-Proxy Target Hijac…
CVE-2026-765547.23.2UnknownWP Import Export LiteCWE-269WP Import Export Lite < 3.9.35 - Authenticated Privilege Escalation via User …
CVE-2026-924255.53.2UnknownHydra Booking — Appointment Scheduling & Booking CalendarCWE-639Hydra Booking < 1.2.4 - Hydra Host+ Cross-Host Account Modification and Delet…
CVE-2026-918474.83.2UnknownOnline Scheduling and Appointment Booking SystemCWE-639Bookly < 28.2 - Unauthenticated AI Assistant Conversation Disclosure and Mess…
CVE-2026-924214.73.2UnknownHydra Booking — Appointment Scheduling & Booking CalendarCWE-639Hydra Booking 1.1.0 - < 1.2.3 - Hydra Host+ Host Profile Takeover via IDOR
CVE-2026-924203.83.2UnknownHydra Booking — Appointment Scheduling & Booking CalendarCWE-639Hydra Booking < 1.2.2 - Hydra Host+ Cross-Host Booking Deletion and Modificat…
CVE-2026-780309.8——DBICWE-470DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm…
CVE-2026-939859.4—Openpanel-devopenpanelCWE-94OpenPanel js-runtime JavaScript Template Sandbox Escape RCE
CVE-2026-939908.7—libexpatlibexpatCWE-176Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate
CVE-2026-939938.6—mistralaimistral-vibeCWE-829Mistral Vibe before 2.25.5 Remote Code Execution via git post-checkout
CVE-2026-939918.3—argoprojargo-workflowsCWE-639Argo Workflows 4.1.0 through 4.1.3 Cross-Namespace Disclosure via Negated Sel…
CVE-2026-940567.5—EximEximCWE-908Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled …
CVE-2026-939887.1—webkulqloappsCWE-22QloApps through 1.7.0 Arbitrary File Read via getEmailHTML
CVE-2026-939927.0—GopeedLabgopeedCWE-22Gopeed through 2.0.0-beta.3 Arbitrary File Write via Path Traversal
CVE-2026-940547.0—EximEximCWE-787Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled …
CVE-2026-939846.9—Openpanel-devopenpanelCWE-287OpenPanel API Authentication Bypass via Unverified Client Secret
CVE-2026-940006.6—Red HatRed Hat Build of KeycloakCWE-862Keycloak-services: keycloak-services: delegated admin with manage-users can e…
CVE-2026-940016.5—Red HatRed Hat Build of KeycloakCWE-862Keycloak-services: keycloak-services: admin credential delete bypasses denied…
CVE-2026-826726.3—elixir-mintmintCWE-444Unvalidated chunk-size line tail in Mint HTTP/1 client enables response smugg…
CVE-2026-939835.3—Openpanel-devopenpanelCWE-89OpenPanel SQL Injection via ClickHouse Property Key Filter
CVE-2026-939824.8—Openpanel-devopenpanelCWE-532OpenPanel MCP Authentication Token in Query Parameter Logged Plaintext
CVE-2026-939874.6—rclonercloneCWE-73rclone serve docker Path Traversal via Volume Name
CVE-2026-939994.2—Red HatRed Hat Build of KeycloakCWE-862Keycloak-services: keycloak-services: token refresh continues issuing tokens …
CVE-2026-940574.0—EximEximCWE-93Exim before 4.100.1 allows SMTP smuggling in which the received message does …
CVE-2026-940553.7—EximEximCWE-416Exim before 4.100.1, when certain non-default TLS settings are used with GnuT…
CVE-2026-939812.3—honojshonoCWE-79hono/jsx before 4.13.7 Cross-Site Scripting via Unescaped Strings
CVE-2026-939862.3—rclonercloneCWE-22rclone before 1.75.1 Path Traversal via Directory Listing Names
CVE-2026-939892.3—vllm-projectvllmCWE-129vLLM through 0.29.0 Cross-Request Logits Corruption via bad_words
CVE-2026-939542.1—grimmory-toolsgrimmoryCWE-285grimmory-tools grimmory Settings API Endpoint AppSettingController.java AppSe…
CVE-2026-939552.1—grimmory-toolsgrimmoryCWE-285grimmory-tools grimmory Download Endpoint KoboController.java streamFileToRes…
CVE-2026-939562.0—olivier-lsPHP-FTSCWE-79olivier-ls PHP-FTS Search SearchEngine.php buildHighlights cross site scripting
CVE-2026-82560await——podlatorsCWE-835Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion form…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-19 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.