boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Saturday, October 3, 2026 · all times UTC← 2026-10-02 · archive

Security Box Score — October 3, 2026

114 CVEs published, led by Legion of the Bouncy Castle Inc. (12).

114 CVEs published October 3, 2026: 5 critical, 45 high, 56 medium, 8 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 89 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published90750895——
KEV catalog size1733

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

3324 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux06205530264072611560.17.8.0019-32 ▼
microsoft12902201199369216290311.17.8.0047-8 ▼
google112842358110212471318090.37.5.0026-27 ▼
red hat219205438842553200.06.8.0035-6 ▼
apple056467166317148991.66.5.00190
suse053827162000.07.5.0036-9 ▼
canonical2521612195000.07.8.0022+2 ▲
freebsd04823673000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco0182547255160179.37.8.0046-11 ▼
ubiquiti065362810334.69.1.00500
palo alto networks0461426151324.34.7.00220
fortinet142121017330819.07.2.0040+1 ▲
netgear03400277000.04.3.00270
f502671441527.78.7.0050-7 ▼
ivanti0246162025520.88.8.01520
sonicwall019784019421.18.3.0050-2 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache97804165365249183320.27.5.0057+96 ▲
mozilla0379122169870900.08.8.0031-34 ▼
gitlab11058246211532.95.3.0035+1 ▲
drupal094119668411.15.7.0027-26 ▼
github023211100000.07.4.0054-3 ▼
docker0121830000.08.4.00170
wordpress0614103350.08.7.03920
eclipse022000000.09.3.00500
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle0290558116605631012840.17.8.00360
ibm0102319647333618610.17.5.0037-6 ▼
adobe08308236437592150.67.5.0036-2 ▼
progress0661540110611.58.1.0045-2 ▼
zohocorp04262970000.08.3.0117-1 ▼
solarwinds0261853010415.49.1.00670
veeam01961030100.08.6.00420
servicenow0107300200.09.4.00360
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link07422281212300.08.5.0164-3 ▼
siemens052633103000.07.3.0026-1 ▼
synology046510256000.05.6.00320
rockwell automation04353260000.08.6.0029-18 ▼
advantech02021710000.08.6.00710
schneider electric01821150000.08.5.0044-4 ▼
hitachi energy0122460000.07.0.0025-4 ▼
abb0111640000.07.2.00180
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell03783417015222210.37.2.0027-19 ▼
nvidia030125206700000.07.8.0019-30 ▼
sourcecodester22390014396000.05.5.0042+2 ▲
openclaw022341148421000.07.1.00310
spring017013608314000.06.5.00330
mongodb0169699604100.07.1.0038-10 ▼
hewlett packard enterprise (hpe)01662280559110.67.2.0042-86 ▼
itsourcecode51580037121000.02.1.00330

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-85706.929699.810.0
CVE-2026-87902.455098.88.1
CVE-2026-76461.282798.19.8
CVE-2026-93616.196597.39.8
CVE-2026-76460.140396.510.0
CVE-2026-86218.129396.210.0
CVE-2026-85102.075594.39.8
CVE-2026-12269.069994.08.8
CVE-2026-67276.064593.59.2
CVE-2026-86060.063993.59.2
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.9296KEV
CVE-2026-7646010.0.1403KEV
CVE-2026-8621810.0.1293KEV
CVE-2026-7565010.0.0395KEV
CVE-2026-8200410.0.0325
CVE-2026-8615210.0.0288
CVE-2026-8597810.0.0144
CVE-2026-7336910.0.0125
CVE-2026-7569910.0.0125
CVE-2026-7570310.0.0125
Most disclosures (vendor)
VendorCVEs
linux2083
microsoft994
google635
oracle634
ibm398
apache291
red hat258
apple247
adobe222
dell188
Most KEV additions (YTD)
VendorKEV
microsoft31
cisco17
apple9
google9
fortinet8
linux6
adobe5
ivanti5
berriai4
checkpoint4
Most-affected ecosystems
EcosystemAdvisories
Maven123
NuGet24
Packagist24
npm24
PyPI14
crates.io10
Go9
RubyGems5
Fastest to KEV
CVEVendorDays
CVE-2026-58704Google0
CVE-2026-75650Adobe0
CVE-2026-85046Google0
CVE-2026-86950Apple0
CVE-2026-87491Google0
CVE-2026-93952Arista Networks0
CVE-2026-102489Zammad GmbH1
CVE-2026-102490Zammad GmbH1
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171781
CVE-2021-27102n/a2021-11-171781
CVE-2021-27101n/a2021-11-171781
CVE-2021-27103n/a2021-11-171781
CVE-2021-21017Adobe2021-11-171781
CVE-2021-28550Adobe2021-11-171781
CVE-2021-42013Apache Software Foundation2021-11-171781
CVE-2021-41773Apache Software Foundation2021-11-171781
CVE-2021-30858Apple2021-11-171781
CVE-2021-30860Apple2021-11-171781

Transactions

EXPLOIT PUBLISHED — CVE-2026-53359 (Linux). Public exploit reference added.

DUE DATE PASSED — CVE-2026-86950 (Apple iOS and iPadOS). CISA remediation deadline was October 2, 2026; still in catalog.

ENRICHED — Linux: 8 CVEs (CVE-2023-53538, CVE-2023-53574, CVE-2024-26948, CVE-2024-41082, CVE-2024-41085, CVE-2024-42282, CVE-2024-46775, CVE-2024-49922). Received CVSS/CPE analysis.

Yesterday's Results

How to read these box scores · glossary

114 CVEs published. 25 box scores, 89 table rows — nothing truncated.

e4jvikwp VikAppointments Services Booking Calendar — VikAppointments Services Booking Calendar <= 1.2.21 - Unauthenticated Arbitrary File Deletion via 'old_vapcfN' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0088   57.7     —
AFFECTED
  Product                                    Versions     Fixed
  VikAppointments Services Booking Calendar  unspecified  —
TIMELINE
  Sep 8   Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Received
arraytics WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System — WPCafe <= 3.0.18 - Authenticated (Contributor+) Local File Inclusion via 'food_menu_style' Elementor Widget Setting
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0070   51.5     —
AFFECTED
  Product                                                                Versions     Fixed
  WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System  unspecified  —
TIMELINE
  Aug 17  Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · CVSS v3.1 · 16 references · NVD status: Received
properfraction Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.4 - Authenticated (Subscriber+) Sensitive Information Exposure via Shortcode Injection via Nickname and Biographical Info Profile Fields
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0063   48.6     —
AFFECTED
  Product                                                                                                                Versions     Fixed
  Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress  unspecified  —
TIMELINE
  Sep 16  Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · CVSS v3.1 · 9 references · NVD status: Received
beaverbuilder Beaver Builder Page Builder – Drag and Drop Website Builder — Beaver Builder Page Builder <= 2.11.0.5 - Unauthenticated Arbitrary Shortcode Execution via Sidebar Module Widget Output
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0053   42.9     —
AFFECTED
  Product                                                      Versions     Fixed
  Beaver Builder Page Builder – Drag and Drop Website Builder  unspecified  —
TIMELINE
  Sep 15  Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Received
trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing Automation — Groundhogg <= 4.9 - Authenticated (Sales Person+) Privilege Escalation via Contact Identity Rebinding leading to Administrator Account Takeover to 'user_id' Parameter (v3 /contacts) chained with v4 /emails/test
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0050   40.4     —
AFFECTED
  Product                                                  Versions     Fixed
  Groundhogg — CRM, Newsletters, and Marketing Automation  unspecified  —
TIMELINE
  Sep 24  Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 9 references · NVD status: Received
Linux Mint Xreader EPUB File epub-document.c g_strdup_printf path traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   L   N   N    2.1   .0043   35.6     —
AFFECTED
  Product  Versions  Fixed
  Xreader  4.6.0 –   4.6.6
TIMELINE
  Oct 2   Reserved by CNA
  Oct 3   Published (CNA: VulDB)
CWE-22 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Received
ultimatemember Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin — Ultimate Member <= 2.13.1 - Missing Authorization to Unauthenticated Sensitive Profile Field Disclosure via Member Directory Field Privacy Bypass
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0040   32.3     —
AFFECTED
  Product                                                                                                         Versions     Fixed
  Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin  unspecified  —
TIMELINE
  Sep 17  Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Received
paoltaia GeoDirectory – WP Business Directory Plugin and Classified Listings Directory — GeoDirectory <= 2.8.186 - Unauthenticated SQL Injection via 'latitude' Parameter via Stored Pending Listing
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0038   30.1     —
AFFECTED
  Product                                                                        Versions     Fixed
  GeoDirectory – WP Business Directory Plugin and Classified Listings Directory  unspecified  —
TIMELINE
  Oct 1   Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Received
wpinsider-1 Simple Membership — Simple Membership <= 4.8.3 - Missing Authorization to Unauthenticated Account Takeover and Sensitive Information Disclosure via 'email' Parameter on Activation Endpoints
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0037   29.0     —
AFFECTED
  Product            Versions     Fixed
  Simple Membership  unspecified  —
TIMELINE
  Sep 24  Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Received
storeapps Smart Manager – WooCommerce Bulk Edit: Products, Orders, Users & More (Spreadsheet) — Smart Manager <= 8.97.0 - Authenticated (Subscriber+) SQL Injection to Privilege Escalation via 'access_privileges' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0037   28.6     —
AFFECTED
  Product                                                                              Versions     Fixed
  Smart Manager – WooCommerce Bulk Edit: Products, Orders, Users & More (Spreadsheet)  unspecified  —
TIMELINE
  Jul 30  Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Received
smub All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) — All in One SEO <= 5.0.2 - Unauthenticated Arbitrary Shortcode Execution via 's' Search Query Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  N    6.5   .0036   27.1     —
AFFECTED
  Product                                                                                                     Versions     Fixed
  All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)  unspecified  —
TIMELINE
  Sep 25  Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Received
arraytics WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System — WPCafe <= 3.0.19 - Missing Authorization to Unauthenticated Arbitrary Email Notification Flow Read/Create/Update/Delete
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0036   26.9     —
AFFECTED
  Product                                                                Versions     Fixed
  WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System  unspecified  —
TIMELINE
  Jun 8   Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 16 references · NVD status: Received
villatheme Photo Reviews for WooCommerce — Photo Reviews for WooCommerce <= 1.2.30 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'wcpr_image_upload_id' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  N  H  H    8.1   .0034   25.4     —
AFFECTED
  Product                        Versions     Fixed
  Photo Reviews for WooCommerce  unspecified  —
TIMELINE
  Sep 28  Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Received
C4illin ConvertX — In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to th…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0033   24.2     —
AFFECTED
  Product   Versions     Fixed
  ConvertX  unspecified  —
TIMELINE
  Oct 3   Reserved by CNA
  Oct 3   Published (CNA: mitre)
CWE-829 · CNA: mitre · CVSS v4.0 · 3 references · NVD status: Received
osamaesh WP Visitor Statistics (Real Time Traffic) — WP Visitor Statistics (Real Time Traffic) <= 8.7 - Unauthenticated SQL Injection via 'fullRef' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0033   23.8     —
AFFECTED
  Product                                    Versions     Fixed
  WP Visitor Statistics (Real Time Traffic)  unspecified  —
TIMELINE
  Sep 22  Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Received
WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons <= 4.7.3 - Unauthenticated Sensitive Information Disclosure via HMAC Signature Collision (Missing Domain Separation) in HMAC Signature Domain-Separation Flaw in `/yamidoo/v1/customer`…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0032   22.9     —
AFFECTED
  Product                                                               Versions     Fixed
  WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons  unspecified  —
TIMELINE
  Sep 25  Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-200 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Received
magicplugins Magic Tooltips For Contact Form 7 — Magic Tooltips For Contact Form 7 <= 1.0.34 - Unauthenticated Stored Cross-Site Scripting via 'esc_html' Filter Override via Comment Author
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0032   22.6     —
AFFECTED
  Product                            Versions     Fixed
  Magic Tooltips For Contact Form 7  unspecified  —
TIMELINE
  Sep 28  Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 4 references · NVD status: Received
uscnanbu Welcart e-Commerce — Welcart e-Commerce <= 2.12.2 - Unauthenticated Stored Cross-Site Scripting via Settlement Notification Parameters
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0031   22.1     —
AFFECTED
  Product             Versions     Fixed
  Welcart e-Commerce  unspecified  —
TIMELINE
  Sep 8   Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 11 references · NVD status: Received
wpclever WPC Smart Quick View for WooCommerce — WPC Smart Quick View for WooCommerce <= 4.4.0 - Reflected Cross-Site Scripting via 'woosq-redirect' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  L  N    6.1   .0031   21.5     —
AFFECTED
  Product                               Versions     Fixed
  WPC Smart Quick View for WooCommerce  unspecified  —
TIMELINE
  Oct 1   Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Received
burstbv Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) — Burst Statistics <= 3.7.1 - Improper Authentication to Account Persistence via Share-Link Authentication Bypass via 'burst_share_token'
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0030   20.5     —
AFFECTED
  Product                                                                       Versions     Fixed
  Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative)  unspecified  —
TIMELINE
  Sep 24  Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-287 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Received
widgetpack Rich Showcase for Google Reviews — Rich Showcase for Google Reviews <= 7.1.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Google Review Text (imported via Places API)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0030   20.3     —
AFFECTED
  Product                           Versions     Fixed
  Rich Showcase for Google Reviews  unspecified  —
TIMELINE
  Sep 25  Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Received
Nelio Content <= 4.5.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Reusable Message Deletion via 'id' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  H    8.1   .0029   19.6     —
AFFECTED
  Product                                                         Versions     Fixed
  Nelio Content – Editorial Calendar & Social Media Auto-Posting  unspecified  —
TIMELINE
  Sep 21  Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Received
wpclever WPC Product Options for WooCommerce — WPC Product Options for WooCommerce <= 4.0.5 - Unauthenticated Stored Cross-Site Scripting via wpcpo-* Array Key via Multipart Field Name
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0029   19.3     —
AFFECTED
  Product                              Versions     Fixed
  WPC Product Options for WooCommerce  unspecified  —
TIMELINE
  Sep 24  Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Received
roxnor WP Ultimate Review — WP Ultimate Review <= 2.4.3 - Unauthenticated Arbitrary Shortcode Execution via 'xs_reviw_summery' Parameter (Split-Shortcode / Late-Registered Shortcode)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  N    6.5   .0028   18.6     —
AFFECTED
  Product             Versions     Fixed
  WP Ultimate Review  unspecified  —
TIMELINE
  Sep 25  Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Received
psmplugins SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent — SupportCandy <= 3.5.3 - Authenticated (Custom+) SQL Injection via 'sort_by' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0027   18.1     —
AFFECTED
  Product                                                                Versions     Fixed
  SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent  unspecified  —
TIMELINE
  Sep 21  Reserved by CNA
  Oct 3   Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-958656.518.1beaverbuilderBeaver Builder Page Builder – Drag and Drop Website BuilderCWE-89Beaver Builder Page Builder <= 2.11.0.5 - Authenticated (Contributor+) SQL In…
CVE-2026-1039096.118.0codepeopleCalculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & MoreCWE-79Calculated Fields Form <= 5.5.1.5 - Reflected DOM-Based Cross-Site Scripting …
CVE-2026-934307.217.8gdragonGD Rating SystemCWE-79GD Rating System <= 3.7.1 - Unauthenticated Stored Cross-Site Scripting via '…
CVE-2026-973417.217.8wp-buyVisitor Traffic Real Time StatisticsCWE-79Visitor Traffic Real Time Statistics <= 8.16 - Unauthenticated Stored DOM-Bas…
CVE-2026-1035195.416.7roxnorWP Ultimate ReviewCWE-94WP Ultimate Review <= 2.4.3 - Authenticated (Subscriber+) Arbitrary Shortcode…
CVE-2026-978735.316.4Legion of the Bouncy Castle Inc.BC-JAVACWE-770Legacy PBES1 and PKCS#12 PBE iteration count honoured unbounded in the raw JC…
CVE-2026-1050905.116.5FormbricksFormbricksCWE-863Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-leve…
CVE-2026-966507.215.5wpchillStrong TestimonialsCWE-79Strong Testimonials <= 3.3.11 - Unauthenticated Stored Cross-Site Scripting v…
CVE-2026-718838.215.2Legion of the Bouncy Castle Inc.BC-LTS-JAVACWE-200Native AES packet cipher returns the raw AES key on an alias
CVE-2026-718908.714.7Legion of the Bouncy Castle Inc.BC-JAVACWE-863MLS external commit can remove an arbitrary group member
CVE-2026-962707.214.5ultimatememberUltimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership PluginCWE-79Ultimate Member <= 2.13.1 - Unauthenticated Stored Cross-Site Scripting via '…
CVE-2026-929777.213.9devowlReal Cookie Banner: GDPR & ePrivacy Cookie ConsentCWE-79Real Cookie Banner: GDPR & ePrivacy Cookie Consent <= 5.3.5 - Unauthenticated…
CVE-2026-938897.213.8wardeeMail logging & CatcherCWE-79Mail logging <= 2.1.12 - Unauthenticated Stored Cross-Site Scripting via PHPM…
CVE-2026-1013574.913.9rainbowgeekSEOPress – AI SEO Plugin & On-site SEOCWE-79SEOPress <= 10.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting vi…
CVE-2026-1001805.413.7jegthemeJeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPressCWE-79Jeg Kit for Elementor <= 3.2.19 - Unauthenticated Stored Cross-Site Scripting…
CVE-2026-965647.213.3rainbowgeekSEOPress – AI SEO Plugin & On-site SEOCWE-79SEOPress <= 10.2 - Unauthenticated Stored Cross-Site Scripting via Author Dis…
CVE-2026-965757.213.3ivijanstefanTransliterator – Multilingual and Multi-script Text ConversionCWE-79Transliterator <= 2.5.8 - Unauthenticated Stored Cross-Site Scripting via Com…
CVE-2026-929746.112.310webPhoto Gallery by 10Web – Mobile-Friendly Image GalleryCWE-79Photo Gallery by 10Web <= 1.8.46 - Reflected Cross-Site Scripting via 'thumb_…
CVE-2026-928266.111.9nosilver4uEWWW Image OptimizerCWE-79EWWW Image Optimizer <= 8.7.7 - Reflected Cross-Site Scripting via REQUEST_UR…
CVE-2026-938966.111.7syammohanmWPFront Notification BarCWE-79WPFront Notification Bar <= 3.5.1 - Reflected Cross-Site Scripting via REQUES…
CVE-2026-1034215.411.5amauricWPMobile.App – Android and iOS App BuilderCWE-79WPMobile.App <= 11.84 - Unauthenticated Stored Cross-Site Scripting via '/and…
CVE-2026-850156.611.3UnknownUnlimited Elements for ElementorCWE-22Unlimited Elements For Elementor < 2.0.21 - Authenticated Arbitrary File Writ…
CVE-2026-925516.111.3properfractionPaid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePressCWE-79Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User P…
CVE-2026-911084.310.5alttextaiAlt Text AI – Automatically generate image alt text for SEO and accessibilityCWE-862Alt Text AI <= 1.10.41 - Missing Authorization to Authenticated (Subscriber+)…
CVE-2026-922436.110.3vinod-dalviIvory Search – WordPress Search PluginCWE-79Ivory Search <= 5.5.18 - Reflected DOM-Based Cross-Site Scripting via 's' Par…
CVE-2026-925386.110.3thimpressLearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-79LearnPress <= 4.4.7 - Reflected DOM-Based Cross-Site Scripting via 'orderby' …
CVE-2026-1043136.110.3wpcleverWPC Estimated Delivery Date for WooCommerceCWE-79WPC Estimated Delivery Date for WooCommerce <= 4.0.1 - Reflected Cross-Site S…
CVE-2026-943786.49.0psmpluginsSupportCandy – AI Customer Support Ticket System & Live Chatbot AgentCWE-79SupportCandy <= 3.5.3 - Authenticated (Subscriber+) Stored Cross-Site Scripti…
CVE-2026-927276.48.5wpdevteamEmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documentsCWE-79EmbedPress <= 4.6.6 - Authenticated (Contributor+) Stored Cross-Site Scriptin…
CVE-2026-157956.48.1cyberchimpsResponsive Starter Templates – Elementor Templates & Starter SitesCWE-79Responsive Plus <= 3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scr…
CVE-2026-927676.48.1zayedbalochTwenty20 Image Before-AfterCWE-79Twenty20 Image Before-After <= 2.0.5 - Authenticated (Contributor+) Stored Cr…
CVE-2026-973446.48.1roxnorWp Social Login and Register Social CounterCWE-79Wp Social Login and Register Social Counter <= 3.2.1 - Authenticated (Subscri…
CVE-2026-1035147.58.0UnknownWP 2FACWE-287WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via TOTP Code Replay
CVE-2025-128286.47.8ultrapressorgUltra Addons Lite for ElementorCWE-79Ultra Addons Lite for Elementor <= 1.3.2 - Authenticated (Contributor+) Store…
CVE-2026-718859.27.6Legion of the Bouncy Castle Inc.BC-JAVACWE-287MLS X.509 credential not bound to the LeafNode signature key
CVE-2026-855686.86.6UnknownUnlimited Elements for ElementorCWE-89Unlimited Elements For Elementor 1.5.139 - 2.0.20 - Unauthenticated SQLi via …
CVE-2026-924375.36.5UnknownMailchimp for WooCommerceCWE-862Mailchimp for WooCommerce < 6.3 - Unauthenticated Abandoned Cart Modification…
CVE-2026-718917.16.2Legion of the Bouncy Castle Inc.BC-JAVACWE-347BLS12-381 key validation accepts a public key built on a foreign curve
CVE-2026-718926.96.1Legion of the Bouncy Castle Inc.BC-JAVACWE-697CMS key-transport recipient key-size validation never runs for RFC 9709 HKDF-…
CVE-2026-887838.86.0UnknownKubio AI Page BuilderCWE-79Kubio AI Page Builder < 2.9.3 - Unauthenticated Stored XSS via Comment Content
CVE-2026-892368.66.0UnknownSaveTo Wishlist LiteCWE-89SaveTo Wishlist Lite < 1.1.5 - Unauthenticated SQLi via 'sort_column' and 'so…
CVE-2026-1011597.55.7UnknownWP Ultimate ReviewCWE-79WP Ultimate Review < 2.4.4 - Unauthenticated Stored XSS via Review Submission
CVE-2026-718898.75.4Legion of the Bouncy Castle Inc.BC-JAVACWE-295PKIXCertPathReviewer does not apply X.509 name constraints to the target cert…
CVE-2026-718868.25.4Legion of the Bouncy Castle Inc.BC-JAVACWE-285OpenPGP certification accepted from a subkey without certification authority
CVE-2026-1011626.45.0UnknownWP Ultimate ReviewCWE-79WP Ultimate Review < 2.4.4 - Author+ Stored XSS via Review Overview Settings
CVE-2026-1032936.84.6UnknownMPGCWE-22MPG < 4.2.3 - Editor+ Arbitrary File Read via Project Import
CVE-2026-113994.34.3wpcodefactoryHelpdesk Support Ticket System for WooCommerceCWE-639Helpdesk Support Ticket System for WooCommerce <= 2.1.6 - Insecure Direct Obj…
CVE-2026-855158.24.2Legion of the Bouncy Castle Inc.BC-JAVACWE-345OpenPGP message truncation not reported, bypassing the SEIPDv1 integrity check
CVE-2026-942386.84.3UnknownLoco TranslateCWE-22Loco Translate < 2.8.9 - Translator+ Limited File Read via 'path' Parameter
CVE-2026-1011607.54.2UnknownWP Ultimate ReviewCWE-400WP Ultimate Review < 2.4.4 - Unauthenticated DoS via Non-Numeric Review Rating
CVE-2026-1011617.54.2UnknownWP Ultimate ReviewCWE-400WP Ultimate Review < 2.4.4 - Unauthenticated DoS via Unset Display Settings i…
CVE-2026-929236.34.1UnknownUnlimited Elements for ElementorCWE-89Unlimited Elements For Elementor 1.5.142 - 2.0.20 - Subscriber+ SQLi via get_…
CVE-2026-887826.83.8UnknownKubio AI Page BuilderCWE-79Kubio AI Page Builder < 2.9.3 - Contributor+ Stored XSS via Image Gallery Ite…
CVE-2026-942396.83.7UnknownLoco TranslateCWE-79Loco Translate < 2.8.9 - Translator+ Stored XSS via Bundle Configuration
CVE-2026-805173.53.8UnknownWP Ultimate CSV ImporterCWE-79WP Ultimate CSV Importer 7.17 - 9.1 - Admin+ Stored XSS via ZIP Import SVG Up…
CVE-2026-868325.33.2UnknownMetFormCWE-200MetForm < 4.3.1 - Unauthenticated Form Entry Data Disclosure via REST API
CVE-2026-805183.73.2UnknownWP Ultimate CSV ImporterCWE-200WP Ultimate CSV Importer < 9.2 - Unauthenticated Imported Data Disclosure via…
CVE-2026-868343.73.2UnknownMetFormCWE-200MetForm 2.2.1 - 4.3.0 - Unauthenticated Debug File Disclosure via HubSpot For…
CVE-2026-791135.12.8aswfOpenAPVCWE-190OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow.
CVE-2026-969623.72.8UnknownPie RegisterCWE-200Pie Register < 3.8.4.14 - Unauthenticated User Email Disclosure via Invitatio…
CVE-2026-910788.22.6UnknownTillKitCWE-287TillKit < 1.0.5 - Unauthenticated POS Takeover via Hard-Coded Default Manager…
CVE-2026-1050831.81.5ImageMagickImageMagickCWE-693ImageMagick before 7.1.2-32 and 6.9.13-57 Security Policy Bypass via policy.x…
CVE-2026-718888.71.3Legion of the Bouncy Castle Inc.BC-JAVACWE-354CMS AuthenticatedData exposes attacker-inserted authAttrs when digestAlgorith…
CVE-2026-180405.91.1Legion of the Bouncy Castle Inc.BC-JAVACWE-208HQC leaks private key information through secret-indexed GF(2^8) tables and a…
CVE-2026-718878.20.4Legion of the Bouncy Castle Inc.BC-JAVACWE-345OpenPGP data signature accepted from a signing subkey without cross-certifica…
CVE-2026-1051059.8—NASA-AMMOSAIT-CoreCWE-306Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacec…
CVE-2026-964518.8—Ultimate MemberUltimate MemberCWE-639WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability
CVE-2026-1051158.8—OpenIdentityPlatformOpenAMCWE-306OpenAM before 16.1.3 Unauthenticated Arbitrary Class Instantiation via JAX-RP…
CVE-2026-1051238.7—vincent-peugnetwcmsCWE-434W (wcms) through 3.18.0 RCE and Arbitrary File Write via Media Upload API
CVE-2026-1051268.6—laradashboardlaradashboardCWE-269LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering
CVE-2026-1030658.2—ThemeumKirkiCWE-1284WordPress Kirki plugin <= 6.3.1 - Arbitrary Code Execution vulnerability
CVE-2026-1051197.6—OpenIdentityPlatformOpenAMCWE-285OpenAM before 16.1.3 PKCE Enforcement Bypass via OAuth 2.0 Hybrid Flows
CVE-2026-1033427.1—Unlimited ElementsUnlimited Elements For Elementor (Free Widgets, Addons, Templates)CWE-79WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) …
CVE-2026-1051137.1—nezhahqnezhaCWE-667Nezha 1.8.0 before 2.3.13 Denial of Service via Notification Mutex Deadlock
CVE-2026-1051297.1—laradashboardlaradashboardCWE-863LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settin…
CVE-2026-1051206.9—OpenIdentityPlatformOpenAMCWE-200OpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpoint
CVE-2026-1051216.9—OpenIdentityPlatformOpenAMCWE-285OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Real…
CVE-2026-1051276.9—laradashboardlaradashboardCWE-770LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery En…
CVE-2026-1051256.3—laradashboardlaradashboardCWE-22LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint
CVE-2026-1051306.3—laradashboardlaradashboardCWE-367LaraDashboard 1.4.0 before 1.4.8 Race Condition Bypasses Per-IP Registration …
CVE-2026-1051126.0—nezhahqnezhaCWE-362Nezha 1.8.0 before 2.3.13 Deadlock DoS via notification-group endpoints
CVE-2026-1051145.3—OpenIdentityPlatformOpenAMCWE-79OpenAM before 16.1.3 Reflected XSS via OAuth2 Authorization Error Page
CVE-2026-1051175.3—OpenIdentityPlatformOpenAMCWE-20OpenAM before 16.1.3 Email Content Injection via Users REST Self-Service Actions
CVE-2026-1051225.3—OpenIdentityPlatformOpenAMCWE-918OpenAM before 16.1.3 SSRF via OpenID Connect Client jwks_uri
CVE-2026-1051245.3—vincent-peugnetwcmsCWE-79W (wcms) through 3.18.0 Unauthenticated Stored XSS via Login Username and Com…
CVE-2026-1051285.3—laradashboardlaradashboardCWE-601LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url
CVE-2026-1051165.1—OpenIdentityPlatformOpenAMCWE-79OpenAM before 16.1.3 Latent XSS in SAML Load-Balancer Cookie Bounce Page
CVE-2026-1051182.3—OpenIdentityPlatformOpenAMCWE-347OpenAM before 16.1.3 Open Redirect via Unverified id_token_hint in endSession
CVE-2026-1049832.1—Linux MintXreaderCWE-22Linux Mint Xreader PDF Attachment Saving ev-window.c g_file_get_child path tr…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-10-03 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.