{
  "day": "2026-10-03",
  "boundary": "UTC calendar day",
  "published_count": 114,
  "by_severity": {
    "CRITICAL": 5,
    "HIGH": 45,
    "MEDIUM": 56,
    "LOW": 8
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-87115",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00881,
      "epss_percentile": 0.57736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e4jvikwp",
      "product": "VikAppointments Services Booking Calendar",
      "cwe": "CWE-22",
      "title": "VikAppointments Services Booking Calendar <= 1.2.21 - Unauthenticated Arbitrary File Deletion via 'old_vapcfN' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87115"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-75028",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.007,
      "epss_percentile": 0.51531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "arraytics",
      "product": "WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System",
      "cwe": "CWE-98",
      "title": "WPCafe <= 3.0.18 - Authenticated (Contributor+) Local File Inclusion via 'food_menu_style' Elementor Widget Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75028"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-92536",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00634,
      "epss_percentile": 0.48578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "properfraction",
      "product": "Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress",
      "cwe": "CWE-94",
      "title": "Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.4 - Authenticated (Subscriber+) Sensitive Information Exposure via Shortcode Injection via Nickname and Biographical Info Profile Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92536"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-92084",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00531,
      "epss_percentile": 0.42877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "beaverbuilder",
      "product": "Beaver Builder Page Builder – Drag and Drop Website Builder",
      "cwe": "CWE-94",
      "title": "Beaver Builder Page Builder <= 2.11.0.5 - Unauthenticated Arbitrary Shortcode Execution via Sidebar Module Widget Output",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92084"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-97644",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00496,
      "epss_percentile": 0.40412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "trainingbusinesspros",
      "product": "Groundhogg — CRM, Newsletters, and Marketing Automation",
      "cwe": "CWE-269",
      "title": "Groundhogg <= 4.9 - Authenticated (Sales Person+) Privilege Escalation via Contact Identity Rebinding leading to Administrator Account Takeover to 'user_id' Parameter (v3 /contacts) chained with v4 /emails/test",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97644"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-104982",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00435,
      "epss_percentile": 0.35603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux Mint",
      "product": "Xreader",
      "cwe": "CWE-22",
      "title": "Linux Mint Xreader EPUB File epub-document.c g_strdup_printf path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104982"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-93428",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.3231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ultimatemember",
      "product": "Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin",
      "cwe": "CWE-862",
      "title": "Ultimate Member <= 2.13.1 - Missing Authorization to Unauthenticated Sensitive Profile Field Disclosure via Member Directory Field Privacy Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93428"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-103913",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.30146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "paoltaia",
      "product": "GeoDirectory – WP Business Directory Plugin and Classified Listings Directory",
      "cwe": "CWE-89",
      "title": "GeoDirectory <= 2.8.186 - Unauthenticated SQL Injection via 'latitude' Parameter via Stored Pending Listing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103913"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-97337",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00374,
      "epss_percentile": 0.29021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpinsider-1",
      "product": "Simple Membership",
      "cwe": "CWE-862",
      "title": "Simple Membership <= 4.8.3 - Missing Authorization to Unauthenticated Account Takeover and Sensitive Information Disclosure via 'email' Parameter on Activation Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97337"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-18443",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.28576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "storeapps",
      "product": "Smart Manager – WooCommerce Bulk Edit: Products, Orders, Users & More (Spreadsheet)",
      "cwe": "CWE-89",
      "title": "Smart Manager <= 8.97.0 - Authenticated (Subscriber+) SQL Injection to Privilege Escalation via 'access_privileges' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18443"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-100152",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00356,
      "epss_percentile": 0.27092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)",
      "cwe": "CWE-94",
      "title": "All in One SEO <= 5.0.2 - Unauthenticated Arbitrary Shortcode Execution via 's' Search Query Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100152"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-11601",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00355,
      "epss_percentile": 0.26927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "arraytics",
      "product": "WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System",
      "cwe": "CWE-862",
      "title": "WPCafe <= 3.0.19 - Missing Authorization to Unauthenticated Arbitrary Email Notification Flow Read/Create/Update/Delete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11601"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-101923",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.25403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "villatheme",
      "product": "Photo Reviews for WooCommerce",
      "cwe": "CWE-862",
      "title": "Photo Reviews for WooCommerce <= 1.2.30 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'wcpr_image_upload_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101923"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-105080",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00333,
      "epss_percentile": 0.24224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "C4illin",
      "product": "ConvertX",
      "cwe": "CWE-829",
      "title": "In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105080"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-96267",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.23797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "osamaesh",
      "product": "WP Visitor Statistics (Real Time Traffic)",
      "cwe": "CWE-89",
      "title": "WP Visitor Statistics (Real Time Traffic) <= 8.7 - Unauthenticated SQL Injection via 'fullRef' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96267"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-100149",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00321,
      "epss_percentile": 0.22867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpzoom",
      "product": "WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons",
      "cwe": "CWE-200",
      "title": "WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons <= 4.7.3 - Unauthenticated Sensitive Information Disclosure via HMAC Signature Collision (Missing Domain Separation) in HMAC Signature Domain-Separation Flaw in `/yamidoo/v1/customer`…",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100149"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-101928",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.22631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "magicplugins",
      "product": "Magic Tooltips For Contact Form 7",
      "cwe": "CWE-79",
      "title": "Magic Tooltips For Contact Form 7 <= 1.0.34 - Unauthenticated Stored Cross-Site Scripting via 'esc_html' Filter Override via Comment Author",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101928"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-87091",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.22099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uscnanbu",
      "product": "Welcart e-Commerce",
      "cwe": "CWE-79",
      "title": "Welcart e-Commerce <= 2.12.2 - Unauthenticated Stored Cross-Site Scripting via Settlement Notification Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87091"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-103888",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.21458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpclever",
      "product": "WPC Smart Quick View for WooCommerce",
      "cwe": "CWE-79",
      "title": "WPC Smart Quick View for WooCommerce <= 4.4.0 - Reflected Cross-Site Scripting via 'woosq-redirect' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103888"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-97343",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.2054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "burstbv",
      "product": "Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative)",
      "cwe": "CWE-287",
      "title": "Burst Statistics <= 3.7.1 - Improper Authentication to Account Persistence via Share-Link Authentication Bypass via 'burst_share_token'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97343"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-100148",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00297,
      "epss_percentile": 0.20338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "widgetpack",
      "product": "Rich Showcase for Google Reviews",
      "cwe": "CWE-79",
      "title": "Rich Showcase for Google Reviews <= 7.1.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Google Review Text (imported via Places API)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100148"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-94505",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.19633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nelio",
      "product": "Nelio Content – Editorial Calendar & Social Media Auto-Posting",
      "cwe": "CWE-862",
      "title": "Nelio Content <= 4.5.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Reusable Message Deletion via 'id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94505"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-97660",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.19287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpclever",
      "product": "WPC Product Options for WooCommerce",
      "cwe": "CWE-79",
      "title": "WPC Product Options for WooCommerce <= 4.0.5 - Unauthenticated Stored Cross-Site Scripting via wpcpo-* Array Key via Multipart Field Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97660"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-100157",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.18588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "roxnor",
      "product": "WP Ultimate Review",
      "cwe": "CWE-94",
      "title": "WP Ultimate Review <= 2.4.3 - Unauthenticated Arbitrary Shortcode Execution via 'xs_reviw_summery' Parameter (Split-Shortcode / Late-Registered Shortcode)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100157"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-94539",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.18058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "psmplugins",
      "product": "SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent",
      "cwe": "CWE-89",
      "title": "SupportCandy <= 3.5.3 - Authenticated (Custom+) SQL Injection via 'sort_by' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94539"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-95865",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.18057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "beaverbuilder",
      "product": "Beaver Builder Page Builder – Drag and Drop Website Builder",
      "cwe": "CWE-89",
      "title": "Beaver Builder Page Builder <= 2.11.0.5 - Authenticated (Contributor+) SQL Injection via 'fields[][value]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95865"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-103909",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.17953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codepeople",
      "product": "Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More",
      "cwe": "CWE-79",
      "title": "Calculated Fields Form <= 5.5.1.5 - Reflected DOM-Based Cross-Site Scripting via URL Parameter Substitution in Calculated Field Equation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103909"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-93430",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.17752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gdragon",
      "product": "GD Rating System",
      "cwe": "CWE-79",
      "title": "GD Rating System <= 3.7.1 - Unauthenticated Stored Cross-Site Scripting via 'title' and 'url' Render Args in gdrts_live_handler AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93430"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-97341",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.17752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wp-buy",
      "product": "Visitor Traffic Real Time Statistics",
      "cwe": "CWE-79",
      "title": "Visitor Traffic Real Time Statistics <= 8.16 - Unauthenticated Stored DOM-Based Cross-Site Scripting via 'X-Real-IP' HTTP Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97341"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-103519",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.16736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "roxnor",
      "product": "WP Ultimate Review",
      "cwe": "CWE-94",
      "title": "WP Ultimate Review <= 2.4.3 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_reviw_summery' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103519"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-97873",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.16428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-770",
      "title": "Legacy PBES1 and PKCS#12 PBE iteration count honoured unbounded in the raw JCA provider",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97873"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-105090",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.16487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Formbricks",
      "product": "Formbricks",
      "cwe": "CWE-863",
      "title": "Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A workspace member holding only readWrite permission could configure Custom Head Scripts on a survey, an operation the documentation restricts to the Manage role. Because the configured scripts execute in the authenticated browser session of any user who opens the affected survey, a lower-privileged member can run arbitrary JavaScript (stored cross-site scripting) in the session of higher-privileged users. Fixed versions require Manage access to modify survey Custom Head Scripts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105090"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-96650",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.15508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpchill",
      "product": "Strong Testimonials",
      "cwe": "CWE-79",
      "title": "Strong Testimonials <= 3.3.11 - Unauthenticated Stored Cross-Site Scripting via 'platform_user_photo' Custom Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96650"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-71883",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.15227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-LTS-JAVA",
      "cwe": "CWE-200",
      "title": "Native AES packet cipher returns the raw AES key on an alias",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71883"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-71890",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.1471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-863",
      "title": "MLS external commit can remove an arbitrary group member",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71890"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-96270",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.14483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ultimatemember",
      "product": "Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin",
      "cwe": "CWE-79",
      "title": "Ultimate Member <= 2.13.1 - Unauthenticated Stored Cross-Site Scripting via 'form_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96270"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-92977",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.13882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "devowl",
      "product": "Real Cookie Banner: GDPR & ePrivacy Cookie Consent",
      "cwe": "CWE-79",
      "title": "Real Cookie Banner: GDPR & ePrivacy Cookie Consent <= 5.3.5 - Unauthenticated Stored Cross-Site Scripting via Comment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92977"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-93889",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.13845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wardee",
      "product": "Mail logging & Catcher",
      "cwe": "CWE-79",
      "title": "Mail logging <= 2.1.12 - Unauthenticated Stored Cross-Site Scripting via PHPMailer 'wp_mail_failed' Error Message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93889"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-101357",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.13864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rainbowgeek",
      "product": "SEOPress – AI SEO Plugin & On-site SEO",
      "cwe": "CWE-79",
      "title": "SEOPress <= 10.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'seopress_google_analytics_matomo_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101357"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-100180",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.13737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jegtheme",
      "product": "Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress",
      "cwe": "CWE-79",
      "title": "Jeg Kit for Elementor <= 3.2.19 - Unauthenticated Stored Cross-Site Scripting via Comment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-100180"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-96564",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.13301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rainbowgeek",
      "product": "SEOPress – AI SEO Plugin & On-site SEO",
      "cwe": "CWE-79",
      "title": "SEOPress <= 10.2 - Unauthenticated Stored Cross-Site Scripting via Author Display Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96564"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-96575",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.13301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ivijanstefan",
      "product": "Transliterator – Multilingual and Multi-script Text Conversion",
      "cwe": "CWE-79",
      "title": "Transliterator <= 2.5.8 - Unauthenticated Stored Cross-Site Scripting via Comment Content via Predictable {rstr_keep} Placeholder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96575"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-92974",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.12265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10web",
      "product": "Photo Gallery by 10Web – Mobile-Friendly Image Gallery",
      "cwe": "CWE-79",
      "title": "Photo Gallery by 10Web <= 1.8.46 - Reflected Cross-Site Scripting via 'thumb_url' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92974"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-92826",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.11941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nosilver4u",
      "product": "EWWW Image Optimizer",
      "cwe": "CWE-79",
      "title": "EWWW Image Optimizer <= 8.7.7 - Reflected Cross-Site Scripting via REQUEST_URI Parameter Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92826"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-93896",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.11724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "syammohanm",
      "product": "WPFront Notification Bar",
      "cwe": "CWE-79",
      "title": "WPFront Notification Bar <= 3.5.1 - Reflected Cross-Site Scripting via REQUEST_URI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93896"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-103421",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.11523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "amauric",
      "product": "WPMobile.App – Android and iOS App Builder",
      "cwe": "CWE-79",
      "title": "WPMobile.App <= 11.84 - Unauthenticated Stored Cross-Site Scripting via '/android_json/search/<value>/0' Path Segment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103421"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-85015",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.11259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Unlimited Elements for Elementor",
      "cwe": "CWE-22",
      "title": "Unlimited Elements For Elementor < 2.0.21 - Authenticated Arbitrary File Write via Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85015"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-92551",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.11261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "properfraction",
      "product": "Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress",
      "cwe": "CWE-79",
      "title": "Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.4 - Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92551"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-91108",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.10545,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alttextai",
      "product": "Alt Text AI – Automatically generate image alt text for SEO and accessibility",
      "cwe": "CWE-862",
      "title": "Alt Text AI <= 1.10.41 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Content Modification via atai_enrich_post_content AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91108"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-92243",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.10313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vinod-dalvi",
      "product": "Ivory Search – WordPress Search Plugin",
      "cwe": "CWE-79",
      "title": "Ivory Search <= 5.5.18 - Reflected DOM-Based Cross-Site Scripting via 's' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92243"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-92538",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.10314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thimpress",
      "product": "LearnPress – WordPress LMS Plugin for Create and Sell Online Courses",
      "cwe": "CWE-79",
      "title": "LearnPress <= 4.4.7 - Reflected DOM-Based Cross-Site Scripting via 'orderby' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92538"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-104313",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.10315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpclever",
      "product": "WPC Estimated Delivery Date for WooCommerce",
      "cwe": "CWE-79",
      "title": "WPC Estimated Delivery Date for WooCommerce <= 4.0.1 - Reflected Cross-Site Scripting via 'rule_data' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104313"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-94378",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.09014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "psmplugins",
      "product": "SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent",
      "cwe": "CWE-79",
      "title": "SupportCandy <= 3.5.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'name' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94378"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-92727",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.08536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevteam",
      "product": "EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents",
      "cwe": "CWE-79",
      "title": "EmbedPress <= 4.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'slidesShow' Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92727"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-15795",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.0812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cyberchimps",
      "product": "Responsive Starter Templates – Elementor Templates & Starter Sites",
      "cwe": "CWE-79",
      "title": "Responsive Plus <= 3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15795"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-92767",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.08118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zayedbaloch",
      "product": "Twenty20 Image Before-After",
      "cwe": "CWE-79",
      "title": "Twenty20 Image Before-After <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'offset' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92767"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-97344",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.0812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "roxnor",
      "product": "Wp Social Login and Register Social Counter",
      "cwe": "CWE-79",
      "title": "Wp Social Login and Register Social Counter <= 3.2.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Avatar Alt Attribute via Arbitrary User Meta Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97344"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-103514",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00192,
      "epss_percentile": 0.08012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP 2FA",
      "cwe": "CWE-287",
      "title": "WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via TOTP Code Replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103514"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2025-12828",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.07805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ultrapressorg",
      "product": "Ultra Addons Lite for Elementor",
      "cwe": "CWE-79",
      "title": "Ultra Addons Lite for Elementor <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Type Out Widget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12828"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-71885",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00188,
      "epss_percentile": 0.07555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-287",
      "title": "MLS X.509 credential not bound to the LeafNode signature key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71885"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-85568",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.06564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Unlimited Elements for Elementor",
      "cwe": "CWE-89",
      "title": "Unlimited Elements For Elementor 1.5.139 - 2.0.20 - Unauthenticated SQLi via 'ucs' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85568"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-92437",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.06542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Mailchimp for WooCommerce",
      "cwe": "CWE-862",
      "title": "Mailchimp for WooCommerce < 6.3 - Unauthenticated Abandoned Cart Modification and Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92437"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-71891",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.06222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-347",
      "title": "BLS12-381 key validation accepts a public key built on a foreign curve",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71891"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-71892",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.06073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-697",
      "title": "CMS key-transport recipient key-size validation never runs for RFC 9709 HKDF-derived keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71892"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-88783",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Kubio AI Page Builder",
      "cwe": "CWE-79",
      "title": "Kubio AI Page Builder < 2.9.3 - Unauthenticated Stored XSS via Comment Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88783"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-89236",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "SaveTo Wishlist Lite",
      "cwe": "CWE-89",
      "title": "SaveTo Wishlist Lite < 1.1.5 - Unauthenticated SQLi via 'sort_column' and 'sort_order' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89236"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-101159",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.05723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Ultimate Review",
      "cwe": "CWE-79",
      "title": "WP Ultimate Review < 2.4.4 - Unauthenticated Stored XSS via Review Submission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101159"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-71889",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00167,
      "epss_percentile": 0.05371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-295",
      "title": "PKIXCertPathReviewer does not apply X.509 name constraints to the target certificate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71889"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-71886",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00167,
      "epss_percentile": 0.05371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-285",
      "title": "OpenPGP certification accepted from a subkey without certification authority",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71886"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-101162",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.04991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Ultimate Review",
      "cwe": "CWE-79",
      "title": "WP Ultimate Review < 2.4.4 - Author+ Stored XSS via Review Overview Settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101162"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-103293",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.04587,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MPG",
      "cwe": "CWE-22",
      "title": "MPG < 4.2.3 - Editor+ Arbitrary File Read via Project Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103293"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-11399",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.04317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpcodefactory",
      "product": "Helpdesk Support Ticket System for WooCommerce",
      "cwe": "CWE-639",
      "title": "Helpdesk Support Ticket System for WooCommerce <= 2.1.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Ticket Response Deletion via 'id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11399"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-85515",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00157,
      "epss_percentile": 0.04193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-345",
      "title": "OpenPGP message truncation not reported, bypassing the SEIPDv1 integrity check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85515"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-94238",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.04251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Loco Translate",
      "cwe": "CWE-22",
      "title": "Loco Translate < 2.8.9 - Translator+ Limited File Read via 'path' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94238"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-101160",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.04157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Ultimate Review",
      "cwe": "CWE-400",
      "title": "WP Ultimate Review < 2.4.4 - Unauthenticated DoS via Non-Numeric Review Rating",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101160"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-101161",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.04157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Ultimate Review",
      "cwe": "CWE-400",
      "title": "WP Ultimate Review < 2.4.4 - Unauthenticated DoS via Unset Display Settings in wp-reviews Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-101161"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-92923",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.04147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Unlimited Elements for Elementor",
      "cwe": "CWE-89",
      "title": "Unlimited Elements For Elementor 1.5.142 - 2.0.20 - Subscriber+ SQLi via get_addon_output_data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92923"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-88782",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.0375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Kubio AI Page Builder",
      "cwe": "CWE-79",
      "title": "Kubio AI Page Builder < 2.9.3 - Contributor+ Stored XSS via Image Gallery Item URL Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88782"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-94239",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.03749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Loco Translate",
      "cwe": "CWE-79",
      "title": "Loco Translate < 2.8.9 - Translator+ Stored XSS via Bundle Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94239"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-80517",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00152,
      "epss_percentile": 0.0375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Ultimate CSV Importer",
      "cwe": "CWE-79",
      "title": "WP Ultimate CSV Importer 7.17 - 9.1 - Admin+ Stored XSS via ZIP Import SVG Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80517"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-86832",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.03248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MetForm",
      "cwe": "CWE-200",
      "title": "MetForm < 4.3.1 - Unauthenticated Form Entry Data Disclosure via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86832"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-80518",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00145,
      "epss_percentile": 0.03248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Ultimate CSV Importer",
      "cwe": "CWE-200",
      "title": "WP Ultimate CSV Importer < 9.2 - Unauthenticated Imported Data Disclosure via Predictable Log Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80518"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-86834",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00145,
      "epss_percentile": 0.03248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MetForm",
      "cwe": "CWE-200",
      "title": "MetForm 2.2.1 - 4.3.0 - Unauthenticated Debug File Disclosure via HubSpot Forms Integration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86834"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-79113",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.02781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aswf",
      "product": "OpenAPV",
      "cwe": "CWE-190",
      "title": "OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79113"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-96962",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00139,
      "epss_percentile": 0.02763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Pie Register",
      "cwe": "CWE-200",
      "title": "Pie Register < 3.8.4.14 - Unauthenticated User Email Disclosure via Invitation Code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96962"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-91078",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.02567,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "TillKit",
      "cwe": "CWE-287",
      "title": "TillKit < 1.0.5 - Unauthenticated POS Takeover via Hard-Coded Default Manager PIN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91078"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-105083",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00117,
      "epss_percentile": 0.01519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-693",
      "title": "ImageMagick before 7.1.2-32 and 6.9.13-57 Security Policy Bypass via policy.xml DOCTYPE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105083"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-71888",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-354",
      "title": "CMS AuthenticatedData exposes attacker-inserted authAttrs when digestAlgorithm is absent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71888"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-18040",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-208",
      "title": "HQC leaks private key information through secret-indexed GF(2^8) tables and a secret-dependent fixed-weight sampler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18040"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-71887",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0009,
      "epss_percentile": 0.00414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-345",
      "title": "OpenPGP data signature accepted from a signing subkey without cross-certification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71887"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-105105",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NASA-AMMOS",
      "product": "AIT-Core",
      "cwe": "CWE-306",
      "title": "Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105105"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-96451",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ultimate Member",
      "product": "Ultimate Member",
      "cwe": "CWE-639",
      "title": "WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96451"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-105115",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenIdentityPlatform",
      "product": "OpenAM",
      "cwe": "CWE-306",
      "title": "OpenAM before 16.1.3 Unauthenticated Arbitrary Class Instantiation via JAX-RPC Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105115"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-105123",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vincent-peugnet",
      "product": "wcms",
      "cwe": "CWE-434",
      "title": "W (wcms) through 3.18.0 RCE and Arbitrary File Write via Media Upload API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105123"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-105126",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laradashboard",
      "product": "laradashboard",
      "cwe": "CWE-269",
      "title": "LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105126"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-103065",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeum",
      "product": "Kirki",
      "cwe": "CWE-1284",
      "title": "WordPress Kirki plugin <= 6.3.1 - Arbitrary Code Execution vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103065"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-105119",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenIdentityPlatform",
      "product": "OpenAM",
      "cwe": "CWE-285",
      "title": "OpenAM before 16.1.3 PKCE Enforcement Bypass via OAuth 2.0 Hybrid Flows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105119"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-103342",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unlimited Elements",
      "product": "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)",
      "cwe": "CWE-79",
      "title": "WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-103342"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-105113",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nezhahq",
      "product": "nezha",
      "cwe": "CWE-667",
      "title": "Nezha 1.8.0 before 2.3.13 Denial of Service via Notification Mutex Deadlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105113"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-105129",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laradashboard",
      "product": "laradashboard",
      "cwe": "CWE-863",
      "title": "LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105129"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-105120",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenIdentityPlatform",
      "product": "OpenAM",
      "cwe": "CWE-200",
      "title": "OpenAM before 16.1.3 Cross-Realm Session Disclosure via Sessions REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105120"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-105121",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenIdentityPlatform",
      "product": "OpenAM",
      "cwe": "CWE-285",
      "title": "OpenAM before 16.1.3 Improper Authorization in Delegated Session-Destroy Realm Scoping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105121"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-105127",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laradashboard",
      "product": "laradashboard",
      "cwe": "CWE-770",
      "title": "LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105127"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-105125",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laradashboard",
      "product": "laradashboard",
      "cwe": "CWE-22",
      "title": "LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105125"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-105130",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laradashboard",
      "product": "laradashboard",
      "cwe": "CWE-367",
      "title": "LaraDashboard 1.4.0 before 1.4.8 Race Condition Bypasses Per-IP Registration Limit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105130"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-105112",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nezhahq",
      "product": "nezha",
      "cwe": "CWE-362",
      "title": "Nezha 1.8.0 before 2.3.13 Deadlock DoS via notification-group endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105112"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-105114",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenIdentityPlatform",
      "product": "OpenAM",
      "cwe": "CWE-79",
      "title": "OpenAM before 16.1.3 Reflected XSS via OAuth2 Authorization Error Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105114"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-105117",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenIdentityPlatform",
      "product": "OpenAM",
      "cwe": "CWE-20",
      "title": "OpenAM before 16.1.3 Email Content Injection via Users REST Self-Service Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105117"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-105122",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenIdentityPlatform",
      "product": "OpenAM",
      "cwe": "CWE-918",
      "title": "OpenAM before 16.1.3 SSRF via OpenID Connect Client jwks_uri",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105122"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-105124",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vincent-peugnet",
      "product": "wcms",
      "cwe": "CWE-79",
      "title": "W (wcms) through 3.18.0 Unauthenticated Stored XSS via Login Username and Comments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105124"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-105128",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "laradashboard",
      "product": "laradashboard",
      "cwe": "CWE-601",
      "title": "LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105128"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-105116",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenIdentityPlatform",
      "product": "OpenAM",
      "cwe": "CWE-79",
      "title": "OpenAM before 16.1.3 Latent XSS in SAML Load-Balancer Cookie Bounce Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105116"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-105118",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenIdentityPlatform",
      "product": "OpenAM",
      "cwe": "CWE-347",
      "title": "OpenAM before 16.1.3 Open Redirect via Unverified id_token_hint in endSession",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-105118"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-104983",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux Mint",
      "product": "Xreader",
      "cwe": "CWE-22",
      "title": "Linux Mint Xreader PDF Attachment Saving ev-window.c g_file_get_child path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-104983"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-53359",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-53359 (Linux). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-86950",
      "detail": "DUE DATE PASSED — CVE-2026-86950 (Apple iOS and iPadOS). CISA remediation deadline was October 2, 2026; still in catalog."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2023-53538",
      "detail": "ENRICHED — CVE-2023-53538 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2023-53574",
      "detail": "ENRICHED — CVE-2023-53574 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2024-26948",
      "detail": "ENRICHED — CVE-2024-26948 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2024-41082",
      "detail": "ENRICHED — CVE-2024-41082 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2024-41085",
      "detail": "ENRICHED — CVE-2024-41085 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2024-42282",
      "detail": "ENRICHED — CVE-2024-42282 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2024-46775",
      "detail": "ENRICHED — CVE-2024-46775 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2024-49922",
      "detail": "ENRICHED — CVE-2024-49922 (Linux). Received CVSS 5.5 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
