boxscore/security
Saturday, July 11, 2026 · all times UTC← 2026-07-10 · archive · 2026-07-12 →

79 CVEs published July 11, 2026: 5 critical, 23 high, 48 medium, 3 low; 0 in KEV; 2 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 54 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published23981471612952563
KEV catalog size1670

651 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux38151812186652812730.27.5.0013-58
google791343149604549387460.47.8.0023-511
microsoft53764585081774378283.77.8.0044-154
red hat36228149211012400.06.5.0026-3
apple0991236629377.16.5.0031-14
canonical1212685000.05.5.0011+1
suse61941140000.08.6.0036+6
freebsd01601240000.07.8.00150
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ubiquiti2536142110438.38.8.0036+25
cisco83141280961135.57.5.0056+5
palo alto networks1425021471428.04.7.0021+5
netgear01700161800.04.3.0024-17
checkpoint0915303111.17.5.0410-3
f50943107111.18.9.02210
ivanti09230033555.68.8.5187-4
fortinet08132028337.57.3.0066-2
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache61214418477114010.57.3.0048+5
mozilla35912182901300.07.3.0025-2
drupal465165355512.05.9.0018+46
gitlab74005276425.04.7.0024-4
github171150000.06.0.0026+1
docker070520100.08.2.0016-2
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle02701311161844020.78.8.0040-2
adobe314913527927542.75.8.0021-120
ibm21263842460700.07.5.0025-8
progress101931420900.07.5.0034+5
solarwinds07122011457.17.5.0835-3
veeam042200400.09.0.0046-1
zohocorp031110000.08.4.01700
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology02325133000.05.6.0025-5
d-link11405352617.16.0.0058-7
siemens4130760100.07.1.0019-3
rockwell automation071510000.08.7.00300
abb060420000.07.2.0018-5
schneider electric060420100.07.8.0024-1
moxa050320000.07.0.00290
dahua030111200.06.9.0036-3
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester2899005346000.05.5.0026-7
dell3389441403211.17.0.0020+26
capgo1576238351000.07.0.0029+15
spring073231391000.06.5.0024-68
openclaw1680362210000.07.0.0021-13
edimax065039026100.07.4.00590
itsourcecode1063001944000.02.1.0020-12
themerex26055410000.08.1.0043+2

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-48282.992499.910.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-48908.881399.810.0
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-56290.832599.710.0
CVE-2026-20230.832199.78.6
CVE-2026-48939.825099.610.0
CVE-2026-56291.760799.510.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4828210.0.9924KEV
CVE-2026-4890810.0.8813KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-4890710.0.6883KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-5016010.0.1775
Most disclosures (vendor)
VendorCVEs
google579
linux456
oracle241
apache126
red hat125
capgo76
ibm67
microsoft67
dell64
themerex60
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco11
apple7
google6
ivanti5
adobe4
solarwinds4
synacor4
fortinet3
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven71
npm6
PyPI5
NuGet3
Fastest to KEV
CVEVendorDays
CVE-2025-67038Lantronix0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
CVE-2026-34910Ubiquiti Inc0
CVE-2026-35273Oracle Corporation0
CVE-2026-45659Microsoft0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171697
CVE-2021-27102Accellion2021-11-171697
CVE-2021-27101Accellion2021-11-171697
CVE-2021-27103Accellion2021-11-171697
CVE-2021-21017Adobe2021-11-171697
CVE-2021-28550Adobe2021-11-171697
CVE-2021-42013Apache2021-11-171697
CVE-2021-41773Apache2021-11-171697
CVE-2021-30858Apple2021-11-171697
CVE-2021-30860Apple2021-11-171697

Transactions

EXPLOIT PUBLISHEDCVE-2026-57827 (rsjoomla.com RSFiles extension for Joomla). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-57828 (phoca.cz Phoca Download extension for Joomla). Public exploit reference added.

DUE DATE PASSEDCVE-2026-48282 (Adobe ColdFusion). CISA remediation deadline was July 10, 2026; still in catalog.

DUE DATE PASSEDCVE-2026-48908 (joomshaper.net SP Page Builder extension for Joomla). CISA remediation deadline was July 10, 2026; still in catalog.

DUE DATE PASSEDCVE-2026-55255 (langflow-ai langflow). CISA remediation deadline was July 10, 2026; still in catalog.

DUE DATE PASSEDCVE-2026-56290 (JoomlaCK.fr Page Builder CK extension for Joomla). CISA remediation deadline was July 10, 2026; still in catalog.

Yesterday's Results

79 CVEs published. 25 box scores, 54 table rows — nothing truncated.

boldgrid W3 Total Cache — W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0277   85.1     —
AFFECTED
  Product         Versions     Fixed
  W3 Total Cache  unspecified  —
TIMELINE
  May 22  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 6 references · NVD status: Deferred
MervinPraison PraisonAI — PraisonAI before 1.6.78 Remote Code Execution via CodeAgent
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0223   81.2     —
AFFECTED
  Product    Versions     Fixed
  PraisonAI  unspecified  1.6.78
TIMELINE
  Jul 9   Reserved by CNA
  Jul 11  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · 2 references · NVD status: Deferred
xtreeme Planyo online reservation system — Planyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0113   63.7     —
AFFECTED
  Product                           Versions     Fixed
  Planyo online reservation system  unspecified  —
TIMELINE
  Mar 4   Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-20 · CNA: Wordfence · 12 references · NVD status: Deferred
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   R  C  H  H  H    8.3   .0070   50.3     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 11  Published (CNA: microsoft)
CWE-502 · CNA: microsoft · 1 reference · NVD status: Analyzed
smackcoders WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel — WP Ultimate CSV Importer <= 8.0.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'MappedFields' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0062   47.0     —
AFFECTED
  Product                                                                    Versions     Fixed
  WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel  unspecified  —
TIMELINE
  Jun 25  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · 6 references · NVD status: Deferred
choijun LA-Studio Element Kit for Elementor — LA-Studio Element Kit for Elementor <= 1.6.1 - Authenticated (Contributor+) Local File Inclusion via 'progress_type' Widget Setting
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0055   43.4     —
AFFECTED
  Product                              Versions     Fixed
  LA-Studio Element Kit for Elementor  unspecified  —
TIMELINE
  Jul 9   Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · 7 references · NVD status: Deferred
MervinPraison PraisonAI — PraisonAI before 4.6.78 Arbitrary File Write and Command Execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0054   42.8     —
AFFECTED
  Product    Versions     Fixed
  PraisonAI  unspecified  4.6.78
TIMELINE
  Jul 9   Reserved by CNA
  Jul 11  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · 2 references · NVD status: Deferred
wpmessiah Swiss Toolkit For WP — Swiss Toolkit For WP <= 1.4.6 - Authenticated (Author+) Arbitrary File Upload via upload_extension_files()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0054   42.8     —
AFFECTED
  Product               Versions     Fixed
  Swiss Toolkit For WP  unspecified  —
TIMELINE
  Feb 11  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 5 references · NVD status: Deferred
masaakitanaka Booking Package — Booking Package <= 1.7.20 - Unauthenticated SQL Injection via 'email' Form Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0048   39.4     —
AFFECTED
  Product          Versions     Fixed
  Booking Package  unspecified  —
TIMELINE
  Jul 9   Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · 10 references · NVD status: Deferred
tigroumeow Code Engine – PHP Snippets, AI Functions & Automation for WordPress — Code Engine <= 0.3.5 - Authenticated (Contributor+) Remote Code Execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0047   38.6     —
AFFECTED
  Product                                                              Versions     Fixed
  Code Engine – PHP Snippets, AI Functions & Automation for WordPress  unspecified  —
TIMELINE
  Jun 27  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-77 · CNA: Wordfence · 2 references · NVD status: Deferred
MervinPraison PraisonAI — PraisonAI before 4.6.78 SQL/CQL Injection via vector dimension
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0041   34.2     —
AFFECTED
  Product    Versions     Fixed
  PraisonAI  unspecified  4.6.78
TIMELINE
  Jul 8   Reserved by CNA
  Jul 11  Published (CNA: VulnCheck)
CWE-89 · CNA: VulnCheck · 3 references · NVD status: Deferred
rsjoomla.com rsjoomla.com RSFiles extension for Joomla — Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0040   33.7     —
AFFECTED
  Product                                    Versions       Fixed
  rsjoomla.com RSFiles extension for Joomla  1.0-1.17.11 –  —
TIMELINE
  Jun 25  Reserved by CNA
  Jul 11  Public exploit reference published
  Jul 11  Published (CNA: Joomla)
CWE-434 · CNA: Joomla · 2 references · NVD status: Modified
nicu_m Simple JWT Login – Allows you to use JWT on REST endpoints. — Simple JWT Login <= 3.6.6 - Authenticated (Subscriber+) Authentication Bypass to Privilege Escalation via 'payload' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0038   31.4     —
AFFECTED
  Product                                                      Versions     Fixed
  Simple JWT Login – Allows you to use JWT on REST endpoints.  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · 6 references · NVD status: Deferred
phoca.cz phoca.cz Phoca Download extension for Joomla — Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   H   H    9.0   .0037   30.3     —
AFFECTED
  Product                                       Versions     Fixed
  phoca.cz Phoca Download extension for Joomla  1.0-6.1.2 –  —
TIMELINE
  Jun 25  Reserved by CNA
  Jul 11  Public exploit reference published
  Jul 11  Published (CNA: Joomla)
CWE-434 · CNA: Joomla · 2 references · NVD status: Modified
stylemix Cost Calculator Builder — Cost Calculator Builder <= 4.0.11 - Unauthenticated Sensitive Information Exposure of Payment Gateway Secret Keys
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0037   30.1     —
AFFECTED
  Product                  Versions     Fixed
  Cost Calculator Builder  unspecified  —
TIMELINE
  Jun 4   Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-200 · CNA: Wordfence · 10 references · NVD status: Deferred
wclovers WCFM – Frontend Manager for WooCommerce — WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Missing Authorization to Unauthenticated Arbitrary Inquiry Reply Injection via wcfm-my-account-enquiry-manage Controller
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0036   29.2     —
AFFECTED
  Product                                  Versions     Fixed
  WCFM – Frontend Manager for WooCommerce  unspecified  —
TIMELINE
  Jun 23  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 12 references · NVD status: Deferred
wpdevteam Essential Addons for Elementor – Popular Elementor Templates & Widgets — Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeover via Email Header Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0036   28.7     —
AFFECTED
  Product                                                                 Versions     Fixed
  Essential Addons for Elementor – Popular Elementor Templates & Widgets  unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-640 · CNA: Wordfence · 9 references · NVD status: Deferred
wupsales AI Copilot – Content Generator — AI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Modification via 'publishTasks' and 'unpublishTasks' AJAX Actions
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0035   28.5     —
AFFECTED
  Product                         Versions     Fixed
  AI Copilot – Content Generator  unspecified  —
TIMELINE
  Apr 21  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 10 references · NVD status: Deferred
ahmadmj Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin — Majestic Support <= 1.1.9 - Authenticated (Subscriber+) SQL Injection via 'val' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0035   28.3     —
AFFECTED
  Product                                                                  Versions     Fixed
  Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin  unspecified  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · 10 references · NVD status: Deferred
wpswings Points and Rewards for WooCommerce — Points and Rewards for WooCommerce <= 2.10.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0035   28.0     —
AFFECTED
  Product                             Versions     Fixed
  Points and Rewards for WooCommerce  unspecified  —
TIMELINE
  Jun 2   Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 12 references · NVD status: Deferred
blendmedia WP CTA – Call Now Button, Sticky Button & Call to Action Builder — WP CTA <= 2.2.2 - Unauthenticated Time-Based Blind SQL Injection via 'fildname' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0033   25.5     —
AFFECTED
  Product                                                           Versions     Fixed
  WP CTA – Call Now Button, Sticky Button & Call to Action Builder  unspecified  —
TIMELINE
  Mar 23  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · 5 references · NVD status: Deferred
wupsales AI Copilot – Content Generator — AI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via AJAX Actions 'removeGroup' and 'clear'
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0032   25.3     —
AFFECTED
  Product                         Versions     Fixed
  AI Copilot – Content Generator  unspecified  —
TIMELINE
  Apr 21  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 12 references · NVD status: Deferred
corvusinfo CorvusPay WooCommerce Payment Gateway — CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Stored Cross-Site Scripting via 'approval_code' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0032   25.2     —
AFFECTED
  Product                                Versions     Fixed
  CorvusPay WooCommerce Payment Gateway  unspecified  —
TIMELINE
  Apr 23  Reserved by CNA
  Jul 11  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 11 references · NVD status: Deferred
ImageMagick before 7.1.2-26 Use-After-Free in FormatMagickCaption
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   N   N   N   L    6.3   .0032   25.1     —
AFFECTED
  Product      Versions     Fixed
  ImageMagick  unspecified  7.1.2-26
  ImageMagick  unspecified  6.9.13-51
TIMELINE
  Jul 10  Reserved by CNA
  Jul 11  Published (CNA: VulnCheck)
CWE-416 · CNA: VulnCheck · 2 references · NVD status: Analyzed
MervinPraison PraisonAI — PraisonAI before 1.7.3 Unauthenticated Agent Access via Insecure Defaults
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   L   L    8.8   .0032   25.0     —
AFFECTED
  Product    Versions     Fixed
  PraisonAI  unspecified  1.7.3
TIMELINE
  Jul 9   Reserved by CNA
  Jul 11  Published (CNA: VulnCheck)
CWE-200 · CNA: VulnCheck · 2 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-76558.124.8surecartSureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & PaymentsCWE-640SureCart <= 4.2.3 - Unauthenticated Linked WordPress Account Takeover via For…
CVE-2026-13598.823.1genolveGenolve – Genolve AI Business Graphics, AI ImagesCWE-863Genolve – AI image AI video generation <= 5.0.5 - Authenticated (Contributor+…
CVE-2026-75594.323.0redefiningthewebAffiliate Program & Referral Tracking for WooCommerce & WordPress – AffiliaCWE-862Affilia <= 3.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbit…
CVE-2026-563038.722.8CapgoCapgoCWE-200Capgo - Unauthenticated API Key Metadata Disclosure via SECURITY DEFINER RPC …
CVE-2026-137568.822.6WP Grid BuilderWP Grid BuilderCWE-269WP Grid Builder <= 2.3.3 - Authenticated (Subscriber+) Privilege Escalation v…
CVE-2026-114266.522.5WebFactoryUnder Construction Page (Pro)CWE-22UnderConstructionPage PRO <= 5.76 - Authenticated (Subscriber+) Arbitrary Fil…
CVE-2026-132505.322.4solacewpSolace ExtraCWE-862Solace Extra <= 1.5.3 - Missing Authorization to Unauthenticated Arbitrary Co…
CVE-2026-121034.321.2subratamalWallet for WooCommerceCWE-862Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Sub…
CVE-2026-124265.319.8supercleanseMembers – Membership & User Role Editor PluginCWE-200Members <= 3.2.22 - Unauthenticated Sensitive Information Disclosure via REST…
CVE-2026-150726.519.7iqonicdesignKiviCare – Clinic & Patient Management System (EHR)CWE-89KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Param…
CVE-2026-90175.319.7webawaysNEX-Forms – Ultimate Forms Plugin for WordPressCWE-862NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Arbitrary Form …
CVE-2026-76204.319.6rainafaraiNotification for TelegramCWE-862Notification for Telegram <= 3.5.1 - Missing Authorization to Authenticated (…
CVE-2026-618576.318.5ImageMagickImageMagickCWE-252ImageMagick before 7.1.2-26 Heap Use-After-Free via XMP
CVE-2026-614398.717.8MervinPraisonPraisonAICWE-1188PraisonAI before 4.6.78 Prompt Injection Defense Bypass
CVE-2026-133787.217.7wpvibesForm Vibes – Save Contact Form 7 & Elementor Form Entries to DatabaseCWE-79Form Vibes <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting via Contact…
CVE-2025-50174.917.6catalyst2020Catalyst Connect Zoho CRM Client PortalCWE-89Catalyst Connect Zoho CRM Client Portal <= 2.2.0 - Authenticated (Administrat…
CVE-2026-614427.117.4MervinPraisonPraisonAICWE-862PraisonAI Platform before 0.1.9 Authorization Bypass via PATCH
CVE-2026-33674.417.4lustmoredLockme calendars integrationCWE-79Lockme OAuth2 calendars integration <= 2.11.0 - Authenticated (Administrator+…
CVE-2026-57436.416.8gallerycreatorSimpLy GalleryCWE-79Mixed Media Gallery Blocks <= 3.3.3.1 - Authenticated (Author+) Stored Cross-…
CVE-2026-115914.416.8trustindexWidgets for Google ReviewsCWE-79Widgets for Google Reviews <= 13.3 - Authenticated (Editor+) Stored Cross-Sit…
CVE-2026-100414.316.7wcloversWCFM – Frontend Manager for WooCommerceCWE-639WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Authenticated (Subscriber…
CVE-2026-131147.216.2stylemixMotors – Car Dealership & Classified Listings PluginCWE-79Motors <= 1.4.112 - Unauthenticated Stored Cross-Site Scripting via Comment C…
CVE-2026-614286.916.1MervinPraisonPraisonAICWE-290PraisonAI AgentMail before 4.6.78 Message Injection via Webhook
CVE-2026-618584.816.2ImageMagickImageMagickCWE-59ImageMagick before 7.1.2-26 Policy Bypass via APNG encoder
CVE-2026-118984.416.2videousermanualsWhite Label CMSCWE-79White Label CMS <= 2.7.12 - Authenticated (Administrator+) Stored Cross-Site …
CVE-2026-614482.115.9parse-communityparse-serverCWE-434Parse Server 9.0.0 Stored XSS via malformed Content-Type
CVE-2026-150736.515.6iqonicdesignKiviCare – Clinic & Patient Management System (EHR)CWE-89KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Param…
CVE-2026-614548.715.2getgravgravCWE-200Grav before 2.0.4 Information Disclosure via __GRAV_CONFIG__
CVE-2026-562966.915.2Cap-gocapgoCWE-203Cap-go - App Existence Oracle via Unauthenticated transfer_app RPC
CVE-2026-68015.315.2postmagthemesContext BlogCWE-200Context Blog <= 1.3.5 - Unauthenticated Sensitive Information Exposure via 'p…
CVE-2026-75444.315.02codersMux Video UploaderCWE-200Mux Video Uploader <= 1.1.4 - Authenticated (Subscriber+) Information Exposure
CVE-2026-131164.314.8wpovernightPDF Invoices & Packing Slips for WooCommerceCWE-639PDF Invoices & Packing Slips for WooCommerce <= 5.14.0 - Insecure Direct Obje…
CVE-2026-86784.314.3richardperdaanMyParcelCWE-862MyParcel <= 4.25.1 - Missing Authorization to Authenticated (Subscriber+) Arb…
CVE-2026-614298.412.9MervinPraisonPraisonAICWE-918PraisonAI before 1.6.78 SSRF via Crawl4AI Chromium backend
CVE-2026-35524.311.9surflabtechSurfLink – Link Manager & Backup RestoreCWE-862SurfLink < 2.6.0 - Missing Authorization to Authenticated (Subscriber+) 410 G…
CVE-2026-127384.311.9saadiqbalWP Easy Pay – Payment and Donation form Builder for SquareCWE-862WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) A…
CVE-2026-97384.411.2printfriendlyPrint, PDF & Email by PrintFriendlyCWE-79Print, PDF, Email by PrintFriendly <= 5.5.10 - Authenticated (Administrator+)…
CVE-2026-154702.111.1EleveoCall Recording SoftwareCWE-266Eleveo Call Recording Software group.jsp improper authorization
CVE-2026-121266.410.7wcloversWCFM Marketplace – Multivendor Marketplace for WooCommerceCWE-79WCFM Marketplace <= 3.7.3 - Authenticated (Vendor+) Stored Cross-Site Scripti…
CVE-2026-18324.310.7thrivedeskAgentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDeskCWE-862ThriveDesk <= 2.1.7 - Missing Authorization to Authenticated (Subscriber+) Ca…
CVE-2026-150106.410.5robin-wbbp style packCWE-79bbp style pack <= 6.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scrip…
CVE-2026-563724.89.9ImageMagickImageMagickCWE-122ImageMagick - Heap Buffer Overflow Read via Unrecognized Magnify Method
CVE-2025-139686.49.6starboardsuiteStarboard Suite Reservation CalendarsCWE-79Starboard Suite Reservation Calendars <= 3.1.4 - Authenticated (Contributor+)…
CVE-2026-150976.49.6themifymeThemify BuilderCWE-79Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scr…
CVE-2026-121414.99.3leap13Premium Addons for Elementor – Powerful Elementor Templates & WidgetsCWE-79Premium Addons for Elementor <= 4.11.84 - Authenticated (Contributor+) Stored…
CVE-2026-618702.19.1ImageMagickImageMagickCWE-401ImageMagick before 7.1.2-26 Memory Leak via VIFF Encoder
CVE-2026-13826.48.7freshlabsfresh PodcasterCWE-79fresh Podcaster <= 1.0.7 - Authenticated (Contributor+) Stored Cross-Site Scr…
CVE-2026-150966.48.7themifymeThemify BuilderCWE-79Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scr…
CVE-2026-562405.38.1CapgoCapgoCWE-285Capgo - Billing Authorization Bypass via Exhausted Usage Credits
CVE-2026-119015.37.6thimpressWP Hotel BookingCWE-345WP Hotel Booking <= 2.3.1 - Unauthenticated Insufficient Verification of Data…
CVE-2026-567636.37.5HonoHonoCWE-1321Hono - Prototype Pollution via __proto__ Key in parseBody with dot Option
CVE-2026-614654.87.0ImageMagickImageMagickCWE-770ImageMagick before 7.1.2-26 Memory Allocation Policy Bypass
CVE-2026-106606.45.6zephyrprojectzephyrCWE-787Shared reassembly buffer in Bluetooth BAP Broadcast Assistant enables cross-c…
CVE-2026-600886.84.4MervinPraisonPraisonAICWE-22PraisonAI before 4.6.78 Path Traversal via Custom Commands

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-11 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.