{
  "day": "2026-09-19",
  "boundary": "UTC calendar day",
  "published_count": 103,
  "by_severity": {
    "CRITICAL": 7,
    "HIGH": 23,
    "MEDIUM": 62,
    "LOW": 10
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 1,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-93742",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0188,
      "epss_percentile": 0.78509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A3002MU",
      "cwe": "CWE-74",
      "title": "Totolink A3002MU formWsc command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93742"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-84434",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00697,
      "epss_percentile": 0.51604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gravity Forms",
      "product": "Gravity Forms",
      "cwe": "CWE-434",
      "title": "Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84434"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-4327",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00696,
      "epss_percentile": 0.51578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sebwordpress",
      "product": "The Welcomizer",
      "cwe": "CWE-94",
      "title": "The Welcomizer <= 2.8.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'twiz_custom_logic' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4327"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-93741",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00644,
      "epss_percentile": 0.49421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "A3002MU",
      "cwe": "CWE-119",
      "title": "Totolink A3002MU formWlWds buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93741"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-87909",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00525,
      "epss_percentile": 0.43452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opajaap",
      "product": "WP Photo Album Plus",
      "cwe": "CWE-74",
      "title": "WP Photo Album Plus <= 9.2.09.002 - Authenticated (Subscriber+) Remote Code Execution via Multipart Upload Filename via ImageMagick Argument Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87909"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-92229",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.34216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmudev",
      "product": "Forminator Forms – Contact Form, Payment Form & Custom Form Builder",
      "cwe": "CWE-94",
      "title": "Forminator Forms <= 1.57.2 - Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92229"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-89334",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00399,
      "epss_percentile": 0.33917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wordplus",
      "product": "Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots",
      "cwe": "CWE-862",
      "title": "Better Messages <= 2.15.33 - Missing Authorization to Authenticated (Custom+) Chat-Room Transcript Disclosure via '/thread/<id>' REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89334"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-15664",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.32572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mdmag",
      "product": "Quill Forms | Conversational Multi Step Forms, Surveys & quizzes",
      "cwe": "CWE-79",
      "title": "Quill Forms | Conversational Multi Step Forms, Surveys & quizzes <= 5.7.1 - Unauthenticated Stored Cross-Site Scripting via Multiple Choice 'Other' Value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15664"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-89274",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00379,
      "epss_percentile": 0.31839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "brechtvds",
      "product": "WP Recipe Maker",
      "cwe": "CWE-94",
      "title": "WP Recipe Maker <= 10.8.1 - Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89274"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-85658",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "properfraction",
      "product": "Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress",
      "cwe": "CWE-94",
      "title": "Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'eup_bio' Biography Field (Entity-Encoded Shortcode Bracket)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85658"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-9289",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00356,
      "epss_percentile": 0.29379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wordlift",
      "product": "WordLift – AI powered SEO – Schema",
      "cwe": "CWE-200",
      "title": "WordLift <= 3.54.10 - Unauthenticated Sensitive Information Exposure in JSON-LD REST API Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9289"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-9855",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00344,
      "epss_percentile": 0.28051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hiroaki-miyashita",
      "product": "Custom Field Template",
      "cwe": "CWE-89",
      "title": "Custom Field Template <= 2.7.8 - Authenticated (Contributor+) SQL Injection via 'post_ID' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9855"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-9613",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "datalogics",
      "product": "Datalogics Ecommerce Delivery – Datalogics",
      "cwe": "CWE-862",
      "title": "Datalogics Ecommerce Delivery <= 2.6.65 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions (datalogics_create_shipping / datalogics_cancel_shipping)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9613"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-11608",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00332,
      "epss_percentile": 0.26582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bompus",
      "product": "WP Customer Reviews",
      "cwe": "CWE-79",
      "title": "WP Customer Reviews <= 3.7.8 - Reflected Cross-Site Scripting via 'wpcr3_fname' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11608"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-4792",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.26532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "radius314",
      "product": "Bread",
      "cwe": "CWE-862",
      "title": "Bread <= 2.9.12 - Missing Authorization to Unauthenticated Information Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4792"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-89093",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.25752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wordplus",
      "product": "Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots",
      "cwe": "CWE-287",
      "title": "Better Messages <= 2.15.33 - Unauthenticated Information Exposure Spoofing via 'X-Real-IP' Header via /guests/register",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89093"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-6295",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.23138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sh1zen",
      "product": "WP Optimizer – PageSpeed, Cache, Minify & Core Web Vitals",
      "cwe": "CWE-89",
      "title": "WP Optimizer <= 2.5.0 - Authenticated (Administrator+) SQL Injection via 's' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6295"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-1255",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ysinnovations",
      "product": "YS LeadGen – Popup Builder, Popup Maker & Form Builder for WordPress | Lead Generation, Email Marketing, Sales, Conversions, Opt-Ins & Subscribers",
      "cwe": "CWE-200",
      "title": "YS LeadGen – Popups, Opt-ins & Lead Capture <= 2.1.4 - Unauthenticated Information Disclosure in 'ysleadgen_get_captured_data' AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1255"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-13191",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mischiefmarmot",
      "product": "Create",
      "cwe": "CWE-89",
      "title": "Create <= 2.5.3 - Authenticated (Author+) SQL Injection via 'order_by' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13191"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-88944",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Tutor LMS – eLearning and online course solution",
      "cwe": "CWE-862",
      "title": "Tutor LMS <= 4.0.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'lesson_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88944"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-1641",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.20272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wowelements",
      "product": "Wow Elements Addons for Elementor",
      "cwe": "CWE-918",
      "title": "Wow Elements Addons for Elementor <= 1.11.2 - Authenticated (Contributor+) Server-Side Request Forgery via Changelog File Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1641"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-9232",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "easyappointments",
      "product": "Easy Appointments",
      "cwe": "CWE-862",
      "title": "Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Contributor+) Sensitive Customer Information Exposure via ea_get_customers_ajax AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9232"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-89333",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Tutor LMS – eLearning and online course solution",
      "cwe": "CWE-639",
      "title": "Tutor LMS <= 4.0.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'student_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89333"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-75959",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.19066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gopayplugins",
      "product": "GoPay for WooCommerce",
      "cwe": "CWE-89",
      "title": "GoPay for WooCommerce <= 1.0.36 - Authenticated (Shop Manager+) SQL Injection via 'log_table_filter' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75959"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-18346",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.18135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tiktokbusinessplugin",
      "product": "TikTok",
      "cwe": "CWE-862",
      "title": "TikTok <= 1.4.1 - Missing Authorization to Unauthenticated TikTok Integration Takeover via 'auth_code' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18346"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-92807",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.17227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pdfcrowd",
      "product": "Save as PDF Plugin by PDFCrowd",
      "cwe": "CWE-94",
      "title": "Save as PDF Plugin by PDFCrowd <= 4.6.1 - Authenticated (Contributor+) Arbitrary Function Invocation / Code Injection via 'pdf_created_callback' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92807"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-9615",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flextheme",
      "product": "Flex Import",
      "cwe": "CWE-862",
      "title": "Flex Import <= 3.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via 'license_activate_fleximp' and 'license_deactivate_fleximp' AJAX Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9615"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-13200",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mischiefmarmot",
      "product": "Create",
      "cwe": "CWE-89",
      "title": "Create <= 2.5.3 - Authenticated (Author+) SQL Injection via 'order' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13200"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-77820",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.1569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stellarwp",
      "product": "WPComplete",
      "cwe": "CWE-79",
      "title": "WPComplete <= 2.9.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'empty' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77820"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-13354",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gabelivan",
      "product": "Asset CleanUp: Page Speed Booster",
      "cwe": "CWE-79",
      "title": "Asset CleanUp: Page Speed Booster <= 1.4.0.5 - Unauthenticated Stored Cross-Site Scripting via Comment Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13354"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-5400",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "davidanderson",
      "product": "Redux Framework",
      "cwe": "CWE-79",
      "title": "Redux Framework <= 4.5.13 - Authenticated (Subscriber+) Cross-Site Scripting via User Input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5400"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-9766",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "empik",
      "product": "Empik for Woocommerce",
      "cwe": "CWE-862",
      "title": "Empik for Woocommerce <= 1.5.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Product Meta Update via empik_csv_process_emp_log_classes AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9766"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-15946",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shahrukhlinkgraph",
      "product": "Search Atlas SEO – OTTO AI SEO Automation for WordPress",
      "cwe": "CWE-862",
      "title": "Search Atlas SEO <= 2.6.23 - Missing Authorization to Authenticated (Subscriber+) Whitelabel Password Modification via handle_whitelabel_password_early Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15946"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-76579",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "litespeedtech",
      "product": "LiteSpeed Cache",
      "cwe": "CWE-79",
      "title": "LiteSpeed Cache <= 7.9 - Reflected Cross-Site Scripting via ESI 'esi' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76579"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-1984",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.1377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vowelweb",
      "product": "Ibtana – Ecommerce Product Addons",
      "cwe": "CWE-862",
      "title": "Ibtana – Ecommerce Product Addons <= 0.4.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'iepa_use_gt_editor' AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1984"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-9832",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.13606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themehigh",
      "product": "Payment Gateway of Stripe for WooCommerce",
      "cwe": "CWE-347",
      "title": "Payment Gateway of Stripe for WooCommerce <= 5.0.8 - Unauthenticated Improper Verification of Cryptographic Signature via woocommerce_api_wt_stripe Webhook Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9832"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-7527",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "johndarrel",
      "product": "Hide My WP Ghost – Security & Firewall",
      "cwe": "CWE-601",
      "title": "WP Ghost (Hide My WP Ghost) <= 7.0.02 - Unauthenticated Open Redirect via 'redirect_to' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7527"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-15760",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Divi Essential",
      "product": "Divi Essentials",
      "cwe": "CWE-862",
      "title": "Divi Essentials <= 5.8.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via dnxte_get_database_data AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15760"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-5410",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "davidanderson",
      "product": "Redux Framework",
      "cwe": "CWE-79",
      "title": "Redux Framework <= 4.5.13 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Spinner Field Input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5410"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-87917",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dvankooten",
      "product": "MC4WP: Mailchimp for WordPress",
      "cwe": "CWE-79",
      "title": "MC4WP: Mailchimp for WordPress <= 4.14.0 - Reflected Cross-Site Scripting via 'data' Dynamic Content Tag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87917"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-89081",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Tutor LMS – eLearning and online course solution",
      "cwe": "CWE-79",
      "title": "Tutor LMS <= 4.0.8 - Reflected Cross-Site Scripting via 'back_url' and 'search' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89081"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-92967",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wppochipp",
      "product": "Pochipp",
      "cwe": "CWE-79",
      "title": "Pochipp <= 1.20.2 - Reflected Cross-Site Scripting via 'keyword' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92967"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-9858",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpexpertshub",
      "product": "Partial Shipment for WooCommerce",
      "cwe": "CWE-862",
      "title": "Partial Shipment for Woocommerce <= 3.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Settings Modification via wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped AJAX Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9858"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-11899",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "edgarrojas",
      "product": "PDF Builder for WooCommerce. Create invoices,packing slips and more",
      "cwe": "CWE-862",
      "title": "PDF Builder for WooCommerce. Create invoices,packing slips and more <= 2.0.11 - Missing Authorization to Authenticated (Subscriber+) Sensitive Invoice Data Disclosure via GetInvoiceDetail AJAX Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11899"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-15947",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shahrukhlinkgraph",
      "product": "Search Atlas SEO – OTTO AI SEO Automation for WordPress",
      "cwe": "CWE-862",
      "title": "Search Atlas SEO <= 2.6.23 - Missing Authorization to Authenticated (Subscriber+) Site-Wide Option Modification via 'metasync_post_types' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15947"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-12042",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "f1logic",
      "product": "WP2Social Auto Publish",
      "cwe": "CWE-79",
      "title": "WP2Social Auto Publish <= 2.4.12 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'pages' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12042"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-2422",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ghozylab",
      "product": "WP Composer – The Easiest Page Builder",
      "cwe": "CWE-79",
      "title": "WP Composer <= 1.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pbwp_raw_shortcode' Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2422"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-1256",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ysinnovations",
      "product": "YS LeadGen – Popup Builder, Popup Maker & Form Builder for WordPress | Lead Generation, Email Marketing, Sales, Conversions, Opt-Ins & Subscribers",
      "cwe": "CWE-79",
      "title": "YS LeadGen – Popups, Opt-ins & Lead Capture <= 2.1.4 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via User Input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1256"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-84750",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ultra Addons for Contact Form 7",
      "cwe": "CWE-434",
      "title": "Ultimate Addons for Contact Form 7 3.2.4 - 3.5.50 - Unauthenticated Arbitrary File Upload via Signature Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84750"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-8354",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "celomitan",
      "product": "Gum Addon for Elementor",
      "cwe": "CWE-79",
      "title": "Gum Addon for Elementor <= 1.3.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pop_tag' Widget Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8354"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-13770",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "appmysite",
      "product": "AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker)",
      "cwe": "CWE-79",
      "title": "AppMySite <= 3.15.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via save_ams_license_key AJAX Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13770"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-2278",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vowelweb",
      "product": "VW Writer Blog",
      "cwe": "CWE-862",
      "title": "VW Writer Blog <= 1.3.8 - Missing Authorization to Authenticated (Subscriber+) Theme Settings Reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2278"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-15660",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.0962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cleverplugins",
      "product": "SEO Booster",
      "cwe": "CWE-862",
      "title": "SEO Booster <= 7.4.7 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Options Modification via handle_oauth_callback()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15660"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-12402",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xootix",
      "product": "OTP Login & Register Woocommerce",
      "cwe": "CWE-79",
      "title": "OTP Login & Register Woocommerce <= 2.7.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'fb-config' Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12402"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-15098",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "creativeinteractivemedia",
      "product": "Real3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder",
      "cwe": "CWE-79",
      "title": "Real 3D Flipbook <= 5.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lightboxtext' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15098"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-86591",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00184,
      "epss_percentile": 0.08209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Botiga Pro",
      "cwe": "CWE-862",
      "title": "Botiga Pro < 1.6.5 - Unauthenticated Arbitrary Blog Options Update via Templates Builder REST Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86591"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-92430",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit",
      "cwe": "CWE-862",
      "title": "Rede Itaú for WooCommerce < 5.4.7 - Unauthenticated Order Status Manipulation via PIX Webhook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92430"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-88926",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00177,
      "epss_percentile": 0.07512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "VikRentItems Flexible Rental Management System",
      "cwe": "CWE-89",
      "title": "VikRentItems Flexible Rental Management System < 1.2.4 - Unauthenticated SQLi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88926"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-1242",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "blockspare",
      "product": "BlockSpare – Gutenberg Blocks for News, Magazine, Blog & Business Websites",
      "cwe": "CWE-863",
      "title": "BlockSpare - Gutenberg Site Builder Blocks & Starter Sites <= 4.2.6 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1242"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-85680",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ultimate Member",
      "cwe": "CWE-79",
      "title": "Ultimate Member < 2.13.1 - Unauthenticated Stored XSS via Profile Page Title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85680"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-88824",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Master Blocks",
      "cwe": "CWE-79",
      "title": "Master Blocks 1.4.1 - 1.4.1.4 - Unauthenticated Stored XSS via White Label Settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88824"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-19860",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "JetFormBuilder — Dynamic Blocks Form Builder",
      "cwe": "CWE-73",
      "title": "JetFormBuilder 3.5.6.2 - 3.6.5.2 - Admin+ Arbitrary File Deletion via Server-Side Validation Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19860"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-76790",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00158,
      "epss_percentile": 0.05422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Estatik Real Estate Plugin",
      "cwe": "CWE-79",
      "title": "Estatik < 4.3.5 - Reflected XSS via get_listings hash Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76790"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2025-15698",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00152,
      "epss_percentile": 0.04767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Business Name Generator",
      "cwe": "CWE-79",
      "title": "Business Name Generator <= 1.3 - Admin+ Stored XSS via Button Color Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15698"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-92404",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.04214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MgoSync",
      "cwe": "CWE-200",
      "title": "MgoSync 2.1.5 - 2.1.6 - Unauthenticated WooCommerce API Credential Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92404"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-16557",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Nimble Page Builder",
      "cwe": "CWE-200",
      "title": "Nimble Builder <= 3.3.8 - Subscriber+ Non-Public Content Disclosure via sek_get_nimble_content_for_seo_plugins",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16557"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-86814",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.03436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "UsersWP",
      "cwe": "CWE-269",
      "title": "UsersWP - Social Login < 1.5.10 - Unauthenticated Account Takeover via Unverified Provider Email",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86814"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-92099",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPGraphQL Smart Cache",
      "cwe": "CWE-284",
      "title": "WPGraphQL Smart Cache < 2.3.2 - Unauthenticated Persisted Query Registration and Alias Squatting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92099"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-15463",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sslzen",
      "product": "SSL Zen — SSL Certificate Installer & HTTPS Redirects",
      "cwe": "CWE-79",
      "title": "SSL Zen <= 4.7.42 - Reflected Cross-Site Scripting via 'uri' and 'host' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15463"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-92435",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Mailchimp for WooCommerce",
      "cwe": "CWE-862",
      "title": "Mailchimp for WooCommerce < 6.1.1 - Unauthenticated Broken Access Control in REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92435"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-92403",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00136,
      "epss_percentile": 0.03437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Secure Custom Fields",
      "cwe": "CWE-863",
      "title": "Secure Custom Fields < 6.9.4 - Unauthenticated Post Modification via Front-End Form ID Substitution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92403"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-85574",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Unbounce Landing Pages",
      "cwe": "CWE-862",
      "title": "Unbounce Landing Pages 1.1.1 - 1.1.4 - Subscriber+ Reverse-Proxy Target Hijack via set_unbounce_domains",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85574"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-76554",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.0316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Import Export Lite",
      "cwe": "CWE-269",
      "title": "WP Import Export Lite < 3.9.35 - Authenticated Privilege Escalation via User Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76554"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-92425",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.0316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Hydra Booking — Appointment Scheduling & Booking Calendar",
      "cwe": "CWE-639",
      "title": "Hydra Booking < 1.2.4 - Hydra Host+ Cross-Host Account Modification and Deletion via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92425"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-91847",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.0316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Online Scheduling and Appointment Booking System",
      "cwe": "CWE-639",
      "title": "Bookly < 28.2 - Unauthenticated AI Assistant Conversation Disclosure and Message Injection via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91847"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-92421",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Hydra Booking — Appointment Scheduling & Booking Calendar",
      "cwe": "CWE-639",
      "title": "Hydra Booking 1.1.0 - < 1.2.3 - Hydra Host+ Host Profile Takeover via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92421"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-92420",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.0316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Hydra Booking — Appointment Scheduling & Booking Calendar",
      "cwe": "CWE-639",
      "title": "Hydra Booking < 1.2.2 - Hydra Host+ Cross-Host Booking Deletion and Modification via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92420"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-78030",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "DBI",
      "cwe": "CWE-470",
      "title": "DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78030"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-93985",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Openpanel-dev",
      "product": "openpanel",
      "cwe": "CWE-94",
      "title": "OpenPanel js-runtime JavaScript Template Sandbox Escape RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93985"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-93990",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libexpat",
      "product": "libexpat",
      "cwe": "CWE-176",
      "title": "Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93990"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-93993",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mistralai",
      "product": "mistral-vibe",
      "cwe": "CWE-829",
      "title": "Mistral Vibe before 2.25.5 Remote Code Execution via git post-checkout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93993"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-93991",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "argoproj",
      "product": "argo-workflows",
      "cwe": "CWE-639",
      "title": "Argo Workflows 4.1.0 through 4.1.3 Cross-Namespace Disclosure via Negated Selector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93991"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-94056",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Exim",
      "product": "Exim",
      "cwe": "CWE-908",
      "title": "Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94056"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-93988",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webkul",
      "product": "qloapps",
      "cwe": "CWE-22",
      "title": "QloApps through 1.7.0 Arbitrary File Read via getEmailHTML",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93988"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-93992",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GopeedLab",
      "product": "gopeed",
      "cwe": "CWE-22",
      "title": "Gopeed through 2.0.0-beta.3 Arbitrary File Write via Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93992"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-94054",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Exim",
      "product": "Exim",
      "cwe": "CWE-787",
      "title": "Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94054"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-93984",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Openpanel-dev",
      "product": "openpanel",
      "cwe": "CWE-287",
      "title": "OpenPanel API Authentication Bypass via Unverified Client Secret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93984"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-94000",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: delegated admin with manage-users can escalate to realm-admin via group membership",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94000"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-94001",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: admin credential delete bypasses denied reset-password permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94001"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-82672",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-mint",
      "product": "mint",
      "cwe": "CWE-444",
      "title": "Unvalidated chunk-size line tail in Mint HTTP/1 client enables response smuggling against strict intermediaries on pooled connections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82672"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-93983",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Openpanel-dev",
      "product": "openpanel",
      "cwe": "CWE-89",
      "title": "OpenPanel SQL Injection via ClickHouse Property Key Filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93983"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-93982",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Openpanel-dev",
      "product": "openpanel",
      "cwe": "CWE-532",
      "title": "OpenPanel MCP Authentication Token in Query Parameter Logged Plaintext",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93982"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-93987",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rclone",
      "product": "rclone",
      "cwe": "CWE-73",
      "title": "rclone serve docker Path Traversal via Volume Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93987"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-93999",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: token refresh continues issuing tokens for disabled audience clients",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93999"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-94057",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Exim",
      "product": "Exim",
      "cwe": "CWE-93",
      "title": "Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94057"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-94055",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Exim",
      "product": "Exim",
      "cwe": "CWE-416",
      "title": "Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94055"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-93981",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "hono",
      "cwe": "CWE-79",
      "title": "hono/jsx before 4.13.7 Cross-Site Scripting via Unescaped Strings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93981"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-93986",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rclone",
      "product": "rclone",
      "cwe": "CWE-22",
      "title": "rclone before 1.75.1 Path Traversal via Directory Listing Names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93986"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-93989",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-129",
      "title": "vLLM through 0.29.0 Cross-Request Logits Corruption via bad_words",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93989"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-93954",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grimmory-tools",
      "product": "grimmory",
      "cwe": "CWE-285",
      "title": "grimmory-tools grimmory Settings API Endpoint AppSettingController.java AppSettingController.getAppSettings authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93954"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-93955",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grimmory-tools",
      "product": "grimmory",
      "cwe": "CWE-285",
      "title": "grimmory-tools grimmory Download Endpoint KoboController.java streamFileToResponse authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93955"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-93956",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "olivier-ls",
      "product": "PHP-FTS",
      "cwe": "CWE-79",
      "title": "olivier-ls PHP-FTS Search SearchEngine.php buildHighlights cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93956"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-82560",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "podlators",
      "cwe": "CWE-835",
      "title": "Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82560"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-12910",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-12910 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13210",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13210 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-61516",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-61516 (Netis Systems NX10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82536",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82536 (RooCodeInc Roo-Code). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82837",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82837 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86749",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86749 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90509",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90509 (dromara orion-visor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90515",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90515 (SourceCodester School Registration and Fee System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90520",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90520 (jaychouchannel Tourism-Management-System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90525",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90525 (itsourcecode Sales and Inventory System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90940",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90940 (201206030 novel-plus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91836",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91836 (OpenClaw ClawScan). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-85046",
      "detail": "DUE DATE PASSED — CVE-2026-85046 (Google Chrome). CISA remediation deadline was September 18, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39964",
      "detail": "RESCORED — CVE-2025-39964 (Linux). CVSS 3.3 → 5.5 (NVD)."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
