AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H H 9.1 .0088 57.7 —
AFFECTED Product Versions Fixed VikAppointments Services Booking Calendar unspecified —
TIMELINE Sep 8 Reserved by CNA Oct 3 Published (CNA: Wordfence)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
114 CVEs published, led by Legion of the Bouncy Castle Inc. (12).
114 CVEs published October 3, 2026: 5 critical, 45 high, 56 medium, 8 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 89 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 907 | 50895 | — | — |
| KEV catalog size | 1733 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
3324 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 0 | 6205 | 530 | 2640 | 726 | 1 | 15 | 6 | 0.1 | 7.8 | .0019 | -32 ▼ |
| microsoft | 1 | 2902 | 201 | 1993 | 692 | 16 | 290 | 31 | 1.1 | 7.8 | .0047 | -8 ▼ |
| 11 | 2842 | 358 | 1102 | 1247 | 131 | 80 | 9 | 0.3 | 7.5 | .0026 | -27 ▼ | |
| red hat | 21 | 920 | 54 | 388 | 425 | 53 | 2 | 0 | 0.0 | 6.8 | .0035 | -6 ▼ |
| apple | 0 | 564 | 67 | 166 | 317 | 14 | 89 | 9 | 1.6 | 6.5 | .0019 | 0 |
| suse | 0 | 53 | 8 | 27 | 16 | 2 | 0 | 0 | 0.0 | 7.5 | .0036 | -9 ▼ |
| canonical | 2 | 52 | 16 | 12 | 19 | 5 | 0 | 0 | 0.0 | 7.8 | .0022 | +2 ▲ |
| freebsd | 0 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 0 | 182 | 54 | 72 | 55 | 1 | 60 | 17 | 9.3 | 7.8 | .0046 | -11 ▼ |
| ubiquiti | 0 | 65 | 36 | 28 | 1 | 0 | 3 | 3 | 4.6 | 9.1 | .0050 | 0 |
| palo alto networks | 0 | 46 | 1 | 4 | 26 | 15 | 13 | 2 | 4.3 | 4.7 | .0022 | 0 |
| fortinet | 1 | 42 | 12 | 10 | 17 | 3 | 30 | 8 | 19.0 | 7.2 | .0040 | +1 ▲ |
| netgear | 0 | 34 | 0 | 0 | 27 | 7 | 0 | 0 | 0.0 | 4.3 | .0027 | 0 |
| f5 | 0 | 26 | 7 | 14 | 4 | 1 | 5 | 2 | 7.7 | 8.7 | .0050 | -7 ▼ |
| ivanti | 0 | 24 | 6 | 16 | 2 | 0 | 25 | 5 | 20.8 | 8.8 | .0152 | 0 |
| sonicwall | 0 | 19 | 7 | 8 | 4 | 0 | 19 | 4 | 21.1 | 8.3 | .0050 | -2 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 97 | 804 | 165 | 365 | 249 | 18 | 33 | 2 | 0.2 | 7.5 | .0057 | +96 ▲ |
| mozilla | 0 | 379 | 122 | 169 | 87 | 0 | 9 | 0 | 0.0 | 8.8 | .0031 | -34 ▼ |
| gitlab | 1 | 105 | 8 | 24 | 62 | 11 | 5 | 3 | 2.9 | 5.3 | .0035 | +1 ▲ |
| drupal | 0 | 94 | 11 | 9 | 66 | 8 | 4 | 1 | 1.1 | 5.7 | .0027 | -26 ▼ |
| github | 0 | 23 | 2 | 11 | 10 | 0 | 0 | 0 | 0.0 | 7.4 | .0054 | -3 ▼ |
| docker | 0 | 12 | 1 | 8 | 3 | 0 | 0 | 0 | 0.0 | 8.4 | .0017 | 0 |
| wordpress | 0 | 6 | 1 | 4 | 1 | 0 | 3 | 3 | 50.0 | 8.7 | .0392 | 0 |
| eclipse | 0 | 2 | 2 | 0 | 0 | 0 | 0 | 0 | 0.0 | 9.3 | .0050 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 2905 | 581 | 1660 | 563 | 101 | 28 | 4 | 0.1 | 7.8 | .0036 | 0 |
| ibm | 0 | 1023 | 196 | 473 | 336 | 18 | 6 | 1 | 0.1 | 7.5 | .0037 | -6 ▼ |
| adobe | 0 | 830 | 82 | 364 | 375 | 9 | 21 | 5 | 0.6 | 7.5 | .0036 | -2 ▼ |
| progress | 0 | 66 | 15 | 40 | 11 | 0 | 6 | 1 | 1.5 | 8.1 | .0045 | -2 ▼ |
| zohocorp | 0 | 42 | 6 | 29 | 7 | 0 | 0 | 0 | 0.0 | 8.3 | .0117 | -1 ▼ |
| solarwinds | 0 | 26 | 18 | 5 | 3 | 0 | 10 | 4 | 15.4 | 9.1 | .0067 | 0 |
| veeam | 0 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0042 | 0 |
| servicenow | 0 | 10 | 7 | 3 | 0 | 0 | 2 | 0 | 0.0 | 9.4 | .0036 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 0 | 74 | 22 | 28 | 12 | 12 | 3 | 0 | 0.0 | 8.5 | .0164 | -3 ▼ |
| siemens | 0 | 52 | 6 | 33 | 10 | 3 | 0 | 0 | 0.0 | 7.3 | .0026 | -1 ▼ |
| synology | 0 | 46 | 5 | 10 | 25 | 6 | 0 | 0 | 0.0 | 5.6 | .0032 | 0 |
| rockwell automation | 0 | 43 | 5 | 32 | 6 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | -18 ▼ |
| advantech | 0 | 20 | 2 | 17 | 1 | 0 | 0 | 0 | 0.0 | 8.6 | .0071 | 0 |
| schneider electric | 0 | 18 | 2 | 11 | 5 | 0 | 0 | 0 | 0.0 | 8.5 | .0044 | -4 ▼ |
| hitachi energy | 0 | 12 | 2 | 4 | 6 | 0 | 0 | 0 | 0.0 | 7.0 | .0025 | -4 ▼ |
| abb | 0 | 11 | 1 | 6 | 4 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dell | 0 | 378 | 34 | 170 | 152 | 22 | 2 | 1 | 0.3 | 7.2 | .0027 | -19 ▼ |
| nvidia | 0 | 301 | 25 | 206 | 70 | 0 | 0 | 0 | 0.0 | 7.8 | .0019 | -30 ▼ |
| sourcecodester | 2 | 239 | 0 | 0 | 143 | 96 | 0 | 0 | 0.0 | 5.5 | .0042 | +2 ▲ |
| openclaw | 0 | 223 | 4 | 114 | 84 | 21 | 0 | 0 | 0.0 | 7.1 | .0031 | 0 |
| spring | 0 | 170 | 13 | 60 | 83 | 14 | 0 | 0 | 0.0 | 6.5 | .0033 | 0 |
| mongodb | 0 | 169 | 6 | 99 | 60 | 4 | 1 | 0 | 0.0 | 7.1 | .0038 | -10 ▼ |
| hewlett packard enterprise (hpe) | 0 | 166 | 22 | 80 | 55 | 9 | 1 | 1 | 0.6 | 7.2 | .0042 | -86 ▼ |
| itsourcecode | 5 | 158 | 0 | 0 | 37 | 121 | 0 | 0 | 0.0 | 2.1 | .0033 | 0 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-85706 | .9296 | 99.8 | 10.0 |
| CVE-2026-87902 | .4550 | 98.8 | 8.1 |
| CVE-2026-76461 | .2827 | 98.1 | 9.8 |
| CVE-2026-93616 | .1965 | 97.3 | 9.8 |
| CVE-2026-76460 | .1403 | 96.5 | 10.0 |
| CVE-2026-86218 | .1293 | 96.2 | 10.0 |
| CVE-2026-85102 | .0755 | 94.3 | 9.8 |
| CVE-2026-12269 | .0699 | 94.0 | 8.8 |
| CVE-2026-67276 | .0645 | 93.5 | 9.2 |
| CVE-2026-86060 | .0639 | 93.5 | 9.2 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-85706 | 10.0 | .9296 | KEV |
| CVE-2026-76460 | 10.0 | .1403 | KEV |
| CVE-2026-86218 | 10.0 | .1293 | KEV |
| CVE-2026-75650 | 10.0 | .0395 | KEV |
| CVE-2026-82004 | 10.0 | .0325 | |
| CVE-2026-86152 | 10.0 | .0288 | |
| CVE-2026-85978 | 10.0 | .0144 | |
| CVE-2026-73369 | 10.0 | .0125 | |
| CVE-2026-75699 | 10.0 | .0125 | |
| CVE-2026-75703 | 10.0 | .0125 |
| Vendor | CVEs |
|---|---|
| linux | 2083 |
| microsoft | 994 |
| 635 | |
| oracle | 634 |
| ibm | 398 |
| apache | 291 |
| red hat | 258 |
| apple | 247 |
| adobe | 222 |
| dell | 188 |
| Vendor | KEV |
|---|---|
| microsoft | 31 |
| cisco | 17 |
| apple | 9 |
| 9 | |
| fortinet | 8 |
| linux | 6 |
| adobe | 5 |
| ivanti | 5 |
| berriai | 4 |
| checkpoint | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 123 |
| NuGet | 24 |
| Packagist | 24 |
| npm | 24 |
| PyPI | 14 |
| crates.io | 10 |
| Go | 9 |
| RubyGems | 5 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-58704 | 0 | |
| CVE-2026-75650 | Adobe | 0 |
| CVE-2026-85046 | 0 | |
| CVE-2026-86950 | Apple | 0 |
| CVE-2026-87491 | 0 | |
| CVE-2026-93952 | Arista Networks | 0 |
| CVE-2026-102489 | Zammad GmbH | 1 |
| CVE-2026-102490 | Zammad GmbH | 1 |
| CVE-2026-84869 | ConnectWise | 2 |
| CVE-2026-86218 | N-able | 2 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1781 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1781 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1781 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1781 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1781 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1781 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1781 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1781 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1781 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1781 |
EXPLOIT PUBLISHED — CVE-2026-53359 (Linux). Public exploit reference added.
DUE DATE PASSED — CVE-2026-86950 (Apple iOS and iPadOS). CISA remediation deadline was October 2, 2026; still in catalog.
ENRICHED — Linux: 8 CVEs (CVE-2023-53538, CVE-2023-53574, CVE-2024-26948, CVE-2024-41082, CVE-2024-41085, CVE-2024-42282, CVE-2024-46775, CVE-2024-49922). Received CVSS/CPE analysis.
How to read these box scores · glossary
114 CVEs published. 25 box scores, 89 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H H 9.1 .0088 57.7 —
AFFECTED Product Versions Fixed VikAppointments Services Booking Calendar unspecified —
TIMELINE Sep 8 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H H H 7.5 .0070 51.5 —
AFFECTED Product Versions Fixed WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System unspecified —
TIMELINE Aug 17 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0063 48.6 —
AFFECTED Product Versions Fixed Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress unspecified —
TIMELINE Sep 16 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0053 42.9 —
AFFECTED Product Versions Fixed Beaver Builder Page Builder – Drag and Drop Website Builder unspecified —
TIMELINE Sep 15 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0050 40.4 —
AFFECTED Product Versions Fixed Groundhogg — CRM, Newsletters, and Marketing Automation unspecified —
TIMELINE Sep 24 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P L N N 2.1 .0043 35.6 —
AFFECTED Product Versions Fixed Xreader 4.6.0 – 4.6.6
TIMELINE Oct 2 Reserved by CNA Oct 3 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0040 32.3 —
AFFECTED Product Versions Fixed Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin unspecified —
TIMELINE Sep 17 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0038 30.1 —
AFFECTED Product Versions Fixed GeoDirectory – WP Business Directory Plugin and Classified Listings Directory unspecified —
TIMELINE Oct 1 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0037 29.0 —
AFFECTED Product Versions Fixed Simple Membership unspecified —
TIMELINE Sep 24 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0037 28.6 —
AFFECTED Product Versions Fixed Smart Manager – WooCommerce Bulk Edit: Products, Orders, Users & More (Spreadsheet) unspecified —
TIMELINE Jul 30 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L L N 6.5 .0036 27.1 —
AFFECTED Product Versions Fixed All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) unspecified —
TIMELINE Sep 25 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N L N 5.3 .0036 26.9 —
AFFECTED Product Versions Fixed WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System unspecified —
TIMELINE Jun 8 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U N H H 8.1 .0034 25.4 —
AFFECTED Product Versions Fixed Photo Reviews for WooCommerce unspecified —
TIMELINE Sep 28 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 9.4 .0033 24.2 —
AFFECTED Product Versions Fixed ConvertX unspecified —
TIMELINE Oct 3 Reserved by CNA Oct 3 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0033 23.8 —
AFFECTED Product Versions Fixed WP Visitor Statistics (Real Time Traffic) unspecified —
TIMELINE Sep 22 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L N N 5.3 .0032 22.9 —
AFFECTED Product Versions Fixed WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons unspecified —
TIMELINE Sep 25 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0032 22.6 —
AFFECTED Product Versions Fixed Magic Tooltips For Contact Form 7 unspecified —
TIMELINE Sep 28 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0031 22.1 —
AFFECTED Product Versions Fixed Welcart e-Commerce unspecified —
TIMELINE Sep 8 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C L L N 6.1 .0031 21.5 —
AFFECTED Product Versions Fixed WPC Smart Quick View for WooCommerce unspecified —
TIMELINE Oct 1 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N L N 4.3 .0030 20.5 —
AFFECTED Product Versions Fixed Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) unspecified —
TIMELINE Sep 24 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C L L N 6.4 .0030 20.3 —
AFFECTED Product Versions Fixed Rich Showcase for Google Reviews unspecified —
TIMELINE Sep 25 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N H H 8.1 .0029 19.6 —
AFFECTED Product Versions Fixed Nelio Content – Editorial Calendar & Social Media Auto-Posting unspecified —
TIMELINE Sep 21 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0029 19.3 —
AFFECTED Product Versions Fixed WPC Product Options for WooCommerce unspecified —
TIMELINE Sep 24 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L L N 6.5 .0028 18.6 —
AFFECTED Product Versions Fixed WP Ultimate Review unspecified —
TIMELINE Sep 25 Reserved by CNA Oct 3 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0027 18.1 —
AFFECTED Product Versions Fixed SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent unspecified —
TIMELINE Sep 21 Reserved by CNA Oct 3 Published (CNA: Wordfence)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-95865 | 6.5 | 18.1 | beaverbuilder | Beaver Builder Page Builder – Drag and Drop Website Builder | CWE-89 | Beaver Builder Page Builder <= 2.11.0.5 - Authenticated (Contributor+) SQL In… |
| CVE-2026-103909 | 6.1 | 18.0 | codepeople | Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More | CWE-79 | Calculated Fields Form <= 5.5.1.5 - Reflected DOM-Based Cross-Site Scripting … |
| CVE-2026-93430 | 7.2 | 17.8 | gdragon | GD Rating System | CWE-79 | GD Rating System <= 3.7.1 - Unauthenticated Stored Cross-Site Scripting via '… |
| CVE-2026-97341 | 7.2 | 17.8 | wp-buy | Visitor Traffic Real Time Statistics | CWE-79 | Visitor Traffic Real Time Statistics <= 8.16 - Unauthenticated Stored DOM-Bas… |
| CVE-2026-103519 | 5.4 | 16.7 | roxnor | WP Ultimate Review | CWE-94 | WP Ultimate Review <= 2.4.3 - Authenticated (Subscriber+) Arbitrary Shortcode… |
| CVE-2026-97873 | 5.3 | 16.4 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-770 | Legacy PBES1 and PKCS#12 PBE iteration count honoured unbounded in the raw JC… |
| CVE-2026-105090 | 5.1 | 16.5 | Formbricks | Formbricks | CWE-863 | Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-leve… |
| CVE-2026-96650 | 7.2 | 15.5 | wpchill | Strong Testimonials | CWE-79 | Strong Testimonials <= 3.3.11 - Unauthenticated Stored Cross-Site Scripting v… |
| CVE-2026-71883 | 8.2 | 15.2 | Legion of the Bouncy Castle Inc. | BC-LTS-JAVA | CWE-200 | Native AES packet cipher returns the raw AES key on an alias |
| CVE-2026-71890 | 8.7 | 14.7 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-863 | MLS external commit can remove an arbitrary group member |
| CVE-2026-96270 | 7.2 | 14.5 | ultimatemember | Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin | CWE-79 | Ultimate Member <= 2.13.1 - Unauthenticated Stored Cross-Site Scripting via '… |
| CVE-2026-92977 | 7.2 | 13.9 | devowl | Real Cookie Banner: GDPR & ePrivacy Cookie Consent | CWE-79 | Real Cookie Banner: GDPR & ePrivacy Cookie Consent <= 5.3.5 - Unauthenticated… |
| CVE-2026-93889 | 7.2 | 13.8 | wardee | Mail logging & Catcher | CWE-79 | Mail logging <= 2.1.12 - Unauthenticated Stored Cross-Site Scripting via PHPM… |
| CVE-2026-101357 | 4.9 | 13.9 | rainbowgeek | SEOPress – AI SEO Plugin & On-site SEO | CWE-79 | SEOPress <= 10.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting vi… |
| CVE-2026-100180 | 5.4 | 13.7 | jegtheme | Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress | CWE-79 | Jeg Kit for Elementor <= 3.2.19 - Unauthenticated Stored Cross-Site Scripting… |
| CVE-2026-96564 | 7.2 | 13.3 | rainbowgeek | SEOPress – AI SEO Plugin & On-site SEO | CWE-79 | SEOPress <= 10.2 - Unauthenticated Stored Cross-Site Scripting via Author Dis… |
| CVE-2026-96575 | 7.2 | 13.3 | ivijanstefan | Transliterator – Multilingual and Multi-script Text Conversion | CWE-79 | Transliterator <= 2.5.8 - Unauthenticated Stored Cross-Site Scripting via Com… |
| CVE-2026-92974 | 6.1 | 12.3 | 10web | Photo Gallery by 10Web – Mobile-Friendly Image Gallery | CWE-79 | Photo Gallery by 10Web <= 1.8.46 - Reflected Cross-Site Scripting via 'thumb_… |
| CVE-2026-92826 | 6.1 | 11.9 | nosilver4u | EWWW Image Optimizer | CWE-79 | EWWW Image Optimizer <= 8.7.7 - Reflected Cross-Site Scripting via REQUEST_UR… |
| CVE-2026-93896 | 6.1 | 11.7 | syammohanm | WPFront Notification Bar | CWE-79 | WPFront Notification Bar <= 3.5.1 - Reflected Cross-Site Scripting via REQUES… |
| CVE-2026-103421 | 5.4 | 11.5 | amauric | WPMobile.App – Android and iOS App Builder | CWE-79 | WPMobile.App <= 11.84 - Unauthenticated Stored Cross-Site Scripting via '/and… |
| CVE-2026-85015 | 6.6 | 11.3 | Unknown | Unlimited Elements for Elementor | CWE-22 | Unlimited Elements For Elementor < 2.0.21 - Authenticated Arbitrary File Writ… |
| CVE-2026-92551 | 6.1 | 11.3 | properfraction | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress | CWE-79 | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User P… |
| CVE-2026-91108 | 4.3 | 10.5 | alttextai | Alt Text AI – Automatically generate image alt text for SEO and accessibility | CWE-862 | Alt Text AI <= 1.10.41 - Missing Authorization to Authenticated (Subscriber+)… |
| CVE-2026-92243 | 6.1 | 10.3 | vinod-dalvi | Ivory Search – WordPress Search Plugin | CWE-79 | Ivory Search <= 5.5.18 - Reflected DOM-Based Cross-Site Scripting via 's' Par… |
| CVE-2026-92538 | 6.1 | 10.3 | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | CWE-79 | LearnPress <= 4.4.7 - Reflected DOM-Based Cross-Site Scripting via 'orderby' … |
| CVE-2026-104313 | 6.1 | 10.3 | wpclever | WPC Estimated Delivery Date for WooCommerce | CWE-79 | WPC Estimated Delivery Date for WooCommerce <= 4.0.1 - Reflected Cross-Site S… |
| CVE-2026-94378 | 6.4 | 9.0 | psmplugins | SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent | CWE-79 | SupportCandy <= 3.5.3 - Authenticated (Subscriber+) Stored Cross-Site Scripti… |
| CVE-2026-92727 | 6.4 | 8.5 | wpdevteam | EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents | CWE-79 | EmbedPress <= 4.6.6 - Authenticated (Contributor+) Stored Cross-Site Scriptin… |
| CVE-2026-15795 | 6.4 | 8.1 | cyberchimps | Responsive Starter Templates – Elementor Templates & Starter Sites | CWE-79 | Responsive Plus <= 3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scr… |
| CVE-2026-92767 | 6.4 | 8.1 | zayedbaloch | Twenty20 Image Before-After | CWE-79 | Twenty20 Image Before-After <= 2.0.5 - Authenticated (Contributor+) Stored Cr… |
| CVE-2026-97344 | 6.4 | 8.1 | roxnor | Wp Social Login and Register Social Counter | CWE-79 | Wp Social Login and Register Social Counter <= 3.2.1 - Authenticated (Subscri… |
| CVE-2026-103514 | 7.5 | 8.0 | Unknown | WP 2FA | CWE-287 | WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via TOTP Code Replay |
| CVE-2025-12828 | 6.4 | 7.8 | ultrapressorg | Ultra Addons Lite for Elementor | CWE-79 | Ultra Addons Lite for Elementor <= 1.3.2 - Authenticated (Contributor+) Store… |
| CVE-2026-71885 | 9.2 | 7.6 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-287 | MLS X.509 credential not bound to the LeafNode signature key |
| CVE-2026-85568 | 6.8 | 6.6 | Unknown | Unlimited Elements for Elementor | CWE-89 | Unlimited Elements For Elementor 1.5.139 - 2.0.20 - Unauthenticated SQLi via … |
| CVE-2026-92437 | 5.3 | 6.5 | Unknown | Mailchimp for WooCommerce | CWE-862 | Mailchimp for WooCommerce < 6.3 - Unauthenticated Abandoned Cart Modification… |
| CVE-2026-71891 | 7.1 | 6.2 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-347 | BLS12-381 key validation accepts a public key built on a foreign curve |
| CVE-2026-71892 | 6.9 | 6.1 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-697 | CMS key-transport recipient key-size validation never runs for RFC 9709 HKDF-… |
| CVE-2026-88783 | 8.8 | 6.0 | Unknown | Kubio AI Page Builder | CWE-79 | Kubio AI Page Builder < 2.9.3 - Unauthenticated Stored XSS via Comment Content |
| CVE-2026-89236 | 8.6 | 6.0 | Unknown | SaveTo Wishlist Lite | CWE-89 | SaveTo Wishlist Lite < 1.1.5 - Unauthenticated SQLi via 'sort_column' and 'so… |
| CVE-2026-101159 | 7.5 | 5.7 | Unknown | WP Ultimate Review | CWE-79 | WP Ultimate Review < 2.4.4 - Unauthenticated Stored XSS via Review Submission |
| CVE-2026-71889 | 8.7 | 5.4 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-295 | PKIXCertPathReviewer does not apply X.509 name constraints to the target cert… |
| CVE-2026-71886 | 8.2 | 5.4 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-285 | OpenPGP certification accepted from a subkey without certification authority |
| CVE-2026-101162 | 6.4 | 5.0 | Unknown | WP Ultimate Review | CWE-79 | WP Ultimate Review < 2.4.4 - Author+ Stored XSS via Review Overview Settings |
| CVE-2026-103293 | 6.8 | 4.6 | Unknown | MPG | CWE-22 | MPG < 4.2.3 - Editor+ Arbitrary File Read via Project Import |
| CVE-2026-11399 | 4.3 | 4.3 | wpcodefactory | Helpdesk Support Ticket System for WooCommerce | CWE-639 | Helpdesk Support Ticket System for WooCommerce <= 2.1.6 - Insecure Direct Obj… |
| CVE-2026-85515 | 8.2 | 4.2 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-345 | OpenPGP message truncation not reported, bypassing the SEIPDv1 integrity check |
| CVE-2026-94238 | 6.8 | 4.3 | Unknown | Loco Translate | CWE-22 | Loco Translate < 2.8.9 - Translator+ Limited File Read via 'path' Parameter |
| CVE-2026-101160 | 7.5 | 4.2 | Unknown | WP Ultimate Review | CWE-400 | WP Ultimate Review < 2.4.4 - Unauthenticated DoS via Non-Numeric Review Rating |
| CVE-2026-101161 | 7.5 | 4.2 | Unknown | WP Ultimate Review | CWE-400 | WP Ultimate Review < 2.4.4 - Unauthenticated DoS via Unset Display Settings i… |
| CVE-2026-92923 | 6.3 | 4.1 | Unknown | Unlimited Elements for Elementor | CWE-89 | Unlimited Elements For Elementor 1.5.142 - 2.0.20 - Subscriber+ SQLi via get_… |
| CVE-2026-88782 | 6.8 | 3.8 | Unknown | Kubio AI Page Builder | CWE-79 | Kubio AI Page Builder < 2.9.3 - Contributor+ Stored XSS via Image Gallery Ite… |
| CVE-2026-94239 | 6.8 | 3.7 | Unknown | Loco Translate | CWE-79 | Loco Translate < 2.8.9 - Translator+ Stored XSS via Bundle Configuration |
| CVE-2026-80517 | 3.5 | 3.8 | Unknown | WP Ultimate CSV Importer | CWE-79 | WP Ultimate CSV Importer 7.17 - 9.1 - Admin+ Stored XSS via ZIP Import SVG Up… |
| CVE-2026-86832 | 5.3 | 3.2 | Unknown | MetForm | CWE-200 | MetForm < 4.3.1 - Unauthenticated Form Entry Data Disclosure via REST API |
| CVE-2026-80518 | 3.7 | 3.2 | Unknown | WP Ultimate CSV Importer | CWE-200 | WP Ultimate CSV Importer < 9.2 - Unauthenticated Imported Data Disclosure via… |
| CVE-2026-86834 | 3.7 | 3.2 | Unknown | MetForm | CWE-200 | MetForm 2.2.1 - 4.3.0 - Unauthenticated Debug File Disclosure via HubSpot For… |
| CVE-2026-79113 | 5.1 | 2.8 | aswf | OpenAPV | CWE-190 | OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow. |
| CVE-2026-96962 | 3.7 | 2.8 | Unknown | Pie Register | CWE-200 | Pie Register < 3.8.4.14 - Unauthenticated User Email Disclosure via Invitatio… |
| CVE-2026-91078 | 8.2 | 2.6 | Unknown | TillKit | CWE-287 | TillKit < 1.0.5 - Unauthenticated POS Takeover via Hard-Coded Default Manager… |
| CVE-2026-105083 | 1.8 | 1.5 | ImageMagick | ImageMagick | CWE-693 | ImageMagick before 7.1.2-32 and 6.9.13-57 Security Policy Bypass via policy.x… |
| CVE-2026-71888 | 8.7 | 1.3 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-354 | CMS AuthenticatedData exposes attacker-inserted authAttrs when digestAlgorith… |
| CVE-2026-18040 | 5.9 | 1.1 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-208 | HQC leaks private key information through secret-indexed GF(2^8) tables and a… |
| CVE-2026-71887 | 8.2 | 0.4 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-345 | OpenPGP data signature accepted from a signing subkey without cross-certifica… |
| CVE-2026-105105 | 9.8 | — | NASA-AMMOS | AIT-Core | CWE-306 | Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacec… |
| CVE-2026-96451 | 8.8 | — | Ultimate Member | Ultimate Member | CWE-639 | WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability |
| CVE-2026-105115 | 8.8 | — | OpenIdentityPlatform | OpenAM | CWE-306 | OpenAM before 16.1.3 Unauthenticated Arbitrary Class Instantiation via JAX-RP… |
| CVE-2026-105123 | 8.7 | — | vincent-peugnet | wcms | CWE-434 | W (wcms) through 3.18.0 RCE and Arbitrary File Write via Media Upload API |
| CVE-2026-105126 | 8.6 | — | laradashboard | laradashboard | CWE-269 | LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering |
| CVE-2026-103065 | 8.2 | — | Themeum | Kirki | CWE-1284 | WordPress Kirki plugin <= 6.3.1 - Arbitrary Code Execution vulnerability |
| CVE-2026-105119 | 7.6 | — | OpenIdentityPlatform | OpenAM | CWE-285 | OpenAM before 16.1.3 PKCE Enforcement Bypass via OAuth 2.0 Hybrid Flows |
| CVE-2026-103342 | 7.1 | — | Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | CWE-79 | WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) … |
| CVE-2026-105113 | 7.1 | — | nezhahq | nezha | CWE-667 | Nezha 1.8.0 before 2.3.13 Denial of Service via Notification Mutex Deadlock |
| CVE-2026-105129 | 7.1 | — | laradashboard | laradashboard | CWE-863 | LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settin… |
| CVE-2026-105120 | 6.9 | — | OpenIdentityPlatform | OpenAM | CWE-200 | OpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpoint |
| CVE-2026-105121 | 6.9 | — | OpenIdentityPlatform | OpenAM | CWE-285 | OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Real… |
| CVE-2026-105127 | 6.9 | — | laradashboard | laradashboard | CWE-770 | LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery En… |
| CVE-2026-105125 | 6.3 | — | laradashboard | laradashboard | CWE-22 | LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint |
| CVE-2026-105130 | 6.3 | — | laradashboard | laradashboard | CWE-367 | LaraDashboard 1.4.0 before 1.4.8 Race Condition Bypasses Per-IP Registration … |
| CVE-2026-105112 | 6.0 | — | nezhahq | nezha | CWE-362 | Nezha 1.8.0 before 2.3.13 Deadlock DoS via notification-group endpoints |
| CVE-2026-105114 | 5.3 | — | OpenIdentityPlatform | OpenAM | CWE-79 | OpenAM before 16.1.3 Reflected XSS via OAuth2 Authorization Error Page |
| CVE-2026-105117 | 5.3 | — | OpenIdentityPlatform | OpenAM | CWE-20 | OpenAM before 16.1.3 Email Content Injection via Users REST Self-Service Actions |
| CVE-2026-105122 | 5.3 | — | OpenIdentityPlatform | OpenAM | CWE-918 | OpenAM before 16.1.3 SSRF via OpenID Connect Client jwks_uri |
| CVE-2026-105124 | 5.3 | — | vincent-peugnet | wcms | CWE-79 | W (wcms) through 3.18.0 Unauthenticated Stored XSS via Login Username and Com… |
| CVE-2026-105128 | 5.3 | — | laradashboard | laradashboard | CWE-601 | LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url |
| CVE-2026-105116 | 5.1 | — | OpenIdentityPlatform | OpenAM | CWE-79 | OpenAM before 16.1.3 Latent XSS in SAML Load-Balancer Cookie Bounce Page |
| CVE-2026-105118 | 2.3 | — | OpenIdentityPlatform | OpenAM | CWE-347 | OpenAM before 16.1.3 Open Redirect via Unverified id_token_hint in endSession |
| CVE-2026-104983 | 2.1 | — | Linux Mint | Xreader | CWE-22 | Linux Mint Xreader PDF Attachment Saving ev-window.c g_file_get_child path tr… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-10-03 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.