{
  "query": {
    "page": "15"
  },
  "count": 20,
  "total": 46749,
  "page": 15,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T10:45:36.976Z",
    "kev": "2026-10-06T10:44:36.922Z",
    "epss": "2026-10-06T06:57:27.860Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T10:45:36.976Z"
  },
  "links": {
    "web": "https://spydr.io/threats?page=15",
    "next": "https://spydr.io/threats.json?page=16"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2026-39749",
      "url": "https://spydr.io/cve/CVE-2026-39749",
      "published": "2026-10-06T09:17:46.333Z",
      "modified": "2026-10-06T09:17:46.333Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "digitalpoint"
      ],
      "products": [
        "digitalpoint App for Cloudflare®"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Subscriber Broken Access Control in App for Cloudflare® <= 1.10.1 versions."
    },
    {
      "id": "CVE-2026-39748",
      "url": "https://spydr.io/cve/CVE-2026-39748",
      "published": "2026-10-06T09:17:46.180Z",
      "modified": "2026-10-06T09:17:46.180Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "ThemeMove"
      ],
      "products": [
        "ThemeMove EduMall"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in EduMall <= 4.5.3 versions."
    },
    {
      "id": "CVE-2026-39747",
      "url": "https://spydr.io/cve/CVE-2026-39747",
      "published": "2026-10-06T09:17:46.033Z",
      "modified": "2026-10-06T09:17:46.033Z",
      "score": 8.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "WofficeIO"
      ],
      "products": [
        "WofficeIO Woffice"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Subscriber SQL Injection in Woffice <= 5.4.35 versions."
    },
    {
      "id": "CVE-2026-39746",
      "url": "https://spydr.io/cve/CVE-2026-39746",
      "published": "2026-10-06T09:17:45.883Z",
      "modified": "2026-10-06T09:17:45.883Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "fs-code"
      ],
      "products": [
        "fs-code Booknetic"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Unauthenticated SQL Injection in Booknetic <= 4.8.5 versions."
    },
    {
      "id": "CVE-2026-39745",
      "url": "https://spydr.io/cve/CVE-2026-39745",
      "published": "2026-10-06T09:17:45.730Z",
      "modified": "2026-10-06T09:17:45.730Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "bestweblayout"
      ],
      "products": [
        "bestweblayout Contact Form to DB by BestWebSoft"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Contact Form to DB by BestWebSoft <= 1.7.6 versions."
    },
    {
      "id": "CVE-2026-39731",
      "url": "https://spydr.io/cve/CVE-2026-39731",
      "published": "2026-10-06T09:17:45.583Z",
      "modified": "2026-10-06T09:17:45.583Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "code4life"
      ],
      "products": [
        "code4life Database for CF7"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Database for CF7 <= 1.2.6 versions."
    },
    {
      "id": "CVE-2026-39730",
      "url": "https://spydr.io/cve/CVE-2026-39730",
      "published": "2026-10-06T09:17:45.433Z",
      "modified": "2026-10-06T10:16:45.703Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Marcin"
      ],
      "products": [
        "Marcin Wise Chat"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Missing Authorization vulnerability in Marcin Wise Chat wise-chat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wise Chat: from n/a through 3.4.2."
    },
    {
      "id": "CVE-2026-39729",
      "url": "https://spydr.io/cve/CVE-2026-39729",
      "published": "2026-10-06T09:17:45.287Z",
      "modified": "2026-10-06T09:17:45.287Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "WisdmLabs"
      ],
      "products": [
        "WisdmLabs Edwiser Bridge"
      ],
      "cwes": [
        "CWE-201"
      ],
      "description": "Unauthenticated Sensitive Data Exposure in Edwiser Bridge <= 4.3.4 versions."
    },
    {
      "id": "CVE-2026-39728",
      "url": "https://spydr.io/cve/CVE-2026-39728",
      "published": "2026-10-06T09:17:45.140Z",
      "modified": "2026-10-06T09:17:45.140Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "instapagedev"
      ],
      "products": [
        "instapagedev Instapage Plugin"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "Unauthenticated Server Side Request Forgery (SSRF) in Instapage Plugin <= 3.7.2 versions."
    },
    {
      "id": "CVE-2026-39727",
      "url": "https://spydr.io/cve/CVE-2026-39727",
      "published": "2026-10-06T09:17:44.987Z",
      "modified": "2026-10-06T09:17:44.987Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Saravana Kumar K"
      ],
      "products": [
        "Saravana Kumar K WC Fields Factory"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Subscriber Cross Site Scripting (XSS) in WC Fields Factory <= 4.1.12 versions."
    },
    {
      "id": "CVE-2026-39726",
      "url": "https://spydr.io/cve/CVE-2026-39726",
      "published": "2026-10-06T09:17:44.833Z",
      "modified": "2026-10-06T09:17:44.833Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Lumise NEO"
      ],
      "products": [
        "Lumise NEO Lumise Product Designer"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Lumise Product Designer <= 2.1.1 versions."
    },
    {
      "id": "CVE-2026-39725",
      "url": "https://spydr.io/cve/CVE-2026-39725",
      "published": "2026-10-06T09:17:44.683Z",
      "modified": "2026-10-06T09:17:44.683Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Jonathan Horowitz"
      ],
      "products": [
        "Jonathan Horowitz Content Visibility for Divi Builder"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Contributor Remote Code Execution (RCE) in Content Visibility for Divi Builder <= 5.03 versions."
    },
    {
      "id": "CVE-2026-39724",
      "url": "https://spydr.io/cve/CVE-2026-39724",
      "published": "2026-10-06T09:17:44.533Z",
      "modified": "2026-10-06T09:17:44.533Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "veppa"
      ],
      "products": [
        "veppa HTTP Requests Manager"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in HTTP Requests Manager <= 1.3.11 versions."
    },
    {
      "id": "CVE-2026-39722",
      "url": "https://spydr.io/cve/CVE-2026-39722",
      "published": "2026-10-06T09:17:44.380Z",
      "modified": "2026-10-06T09:17:44.380Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "VibeThemes"
      ],
      "products": [
        "VibeThemes WPLMS"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in WPLMS <= 4.972 versions."
    },
    {
      "id": "CVE-2026-39720",
      "url": "https://spydr.io/cve/CVE-2026-39720",
      "published": "2026-10-06T09:17:44.227Z",
      "modified": "2026-10-06T09:17:44.227Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "mapster"
      ],
      "products": [
        "Mapster WP Maps"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Mapster WP Maps <= 2.0.4 versions."
    },
    {
      "id": "CVE-2026-39719",
      "url": "https://spydr.io/cve/CVE-2026-39719",
      "published": "2026-10-06T09:17:44.077Z",
      "modified": "2026-10-06T09:17:44.077Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "DeKnows"
      ],
      "products": [
        "DeKnows PDF Smart Viewer for Elementor"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions."
    },
    {
      "id": "CVE-2026-32581",
      "url": "https://spydr.io/cve/CVE-2026-32581",
      "published": "2026-10-06T09:17:43.930Z",
      "modified": "2026-10-06T09:17:43.930Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "mooberrydreams"
      ],
      "products": [
        "mooberrydreams Mooberry Book Manager"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Subscriber SQL Injection in Mooberry Book Manager 4.16.2 versions."
    },
    {
      "id": "CVE-2026-32580",
      "url": "https://spydr.io/cve/CVE-2026-32580",
      "published": "2026-10-06T09:17:43.780Z",
      "modified": "2026-10-06T09:17:43.780Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "wpgenie"
      ],
      "products": [
        "wpgenie WooCommerce Lottery"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Unauthenticated SQL Injection in WooCommerce Lottery <= 2.2.9 versions."
    },
    {
      "id": "CVE-2026-32579",
      "url": "https://spydr.io/cve/CVE-2026-32579",
      "published": "2026-10-06T09:17:43.613Z",
      "modified": "2026-10-06T09:17:43.613Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "kognetiks"
      ],
      "products": [
        "Kognetiks Chatbot for WordPress"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions."
    },
    {
      "id": "CVE-2026-32578",
      "url": "https://spydr.io/cve/CVE-2026-32578",
      "published": "2026-10-06T09:17:43.460Z",
      "modified": "2026-10-06T09:17:43.460Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "techsupport"
      ],
      "products": [
        "techsupport ECPay Ecommerce for WooCommerce"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Subscriber Broken Access Control in ECPay Ecommerce for WooCommerce <= 1.1.2606090 versions."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
