{
  "query": {
    "page": "16"
  },
  "count": 20,
  "total": 46749,
  "page": 16,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T10:45:36.976Z",
    "kev": "2026-10-06T11:44:39.558Z",
    "epss": "2026-10-06T06:57:27.860Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T11:45:39.554Z"
  },
  "links": {
    "web": "https://spydr.io/threats?page=16",
    "next": "https://spydr.io/threats.json?page=17"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2026-32577",
      "url": "https://spydr.io/cve/CVE-2026-32577",
      "published": "2026-10-06T09:17:43.297Z",
      "modified": "2026-10-06T09:17:43.297Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "N-Media"
      ],
      "products": [
        "N-Media Frontend File Manager"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Frontend File Manager <= 23.6 versions."
    },
    {
      "id": "CVE-2026-32575",
      "url": "https://spydr.io/cve/CVE-2026-32575",
      "published": "2026-10-06T09:17:43.150Z",
      "modified": "2026-10-06T09:17:43.150Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Fantastic Plugins"
      ],
      "products": [
        "Fantastic Plugins SUMO Affiliates Pro"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in SUMO Affiliates Pro <= 11.7.0 versions."
    },
    {
      "id": "CVE-2026-32574",
      "url": "https://spydr.io/cve/CVE-2026-32574",
      "published": "2026-10-06T09:17:43.000Z",
      "modified": "2026-10-06T09:17:43.000Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "EDGARROJAS"
      ],
      "products": [
        "EDGARROJAS Smart Forms"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Smart Forms <= 2.6.104 versions."
    },
    {
      "id": "CVE-2026-32572",
      "url": "https://spydr.io/cve/CVE-2026-32572",
      "published": "2026-10-06T09:17:42.847Z",
      "modified": "2026-10-06T09:17:42.847Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "weDevs"
      ],
      "products": [
        "weDevs WP User Frontend Pro"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in WP User Frontend Pro <= 4.2.13 versions."
    },
    {
      "id": "CVE-2026-32571",
      "url": "https://spydr.io/cve/CVE-2026-32571",
      "published": "2026-10-06T09:17:42.703Z",
      "modified": "2026-10-06T09:17:42.703Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Colabrio"
      ],
      "products": [
        "Colabrio Ohio Extra"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Subscriber Cross Site Scripting (XSS) in Ohio Extra <= 3.6.8 versions."
    },
    {
      "id": "CVE-2026-32570",
      "url": "https://spydr.io/cve/CVE-2026-32570",
      "published": "2026-10-06T09:17:42.550Z",
      "modified": "2026-10-06T09:17:42.550Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "DaftPlug"
      ],
      "products": [
        "DaftPlug Progressify - Progressive Web App (PWA)"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Progressify - Progressive Web App (PWA) <= 1.6.0 versions."
    },
    {
      "id": "CVE-2026-32569",
      "url": "https://spydr.io/cve/CVE-2026-32569",
      "published": "2026-10-06T09:17:42.397Z",
      "modified": "2026-10-06T09:17:42.397Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Joomunited"
      ],
      "products": [
        "Joomunited WP Media folder"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in WP Media folder <= 6.2.2 versions."
    },
    {
      "id": "CVE-2026-32568",
      "url": "https://spydr.io/cve/CVE-2026-32568",
      "published": "2026-10-06T09:17:42.230Z",
      "modified": "2026-10-06T09:17:42.230Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "JMAPlugins"
      ],
      "products": [
        "JMAPlugins WooCommerce Designer Pro"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Subscriber Remote Code Execution (RCE) in WooCommerce Designer Pro <= 1.9.33 versions."
    },
    {
      "id": "CVE-2026-32557",
      "url": "https://spydr.io/cve/CVE-2026-32557",
      "published": "2026-10-06T09:17:42.080Z",
      "modified": "2026-10-06T09:17:42.080Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Bot Verification bookingwp.com: Verifying that you are not a robot..."
      ],
      "products": [
        "Bot Verification bookingwp.com: Verifying that you are not a robot... WooCommerce Appointments"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Unauthenticated SQL Injection in WooCommerce Appointments <= 5.3.2 versions."
    },
    {
      "id": "CVE-2026-25434",
      "url": "https://spydr.io/cve/CVE-2026-25434",
      "published": "2026-10-06T09:17:41.930Z",
      "modified": "2026-10-06T09:17:41.930Z",
      "score": 8.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Tobias @Saleswonder.biz"
      ],
      "products": [
        "Tobias @Saleswonder.biz WP2LEADS"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Subscriber SQL Injection in WP2LEADS <= 3.5.7 versions."
    },
    {
      "id": "CVE-2026-25433",
      "url": "https://spydr.io/cve/CVE-2026-25433",
      "published": "2026-10-06T09:17:41.777Z",
      "modified": "2026-10-06T09:17:41.777Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Tobias @Saleswonder.biz"
      ],
      "products": [
        "Tobias @Saleswonder.biz WP2LEADS"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Subscriber Broken Access Control in WP2LEADS <= 3.5.7 versions."
    },
    {
      "id": "CVE-2026-105879",
      "url": "https://spydr.io/cve/CVE-2026-105879",
      "published": "2026-10-06T09:17:41.620Z",
      "modified": "2026-10-06T09:17:41.620Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Crocoblock"
      ],
      "products": [
        "Crocoblock JetElements For Elementor"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows Stored XSS.This issue affects JetElements For Elementor: from n/a through 2.9.2.2."
    },
    {
      "id": "CVE-2026-105809",
      "url": "https://spydr.io/cve/CVE-2026-105809",
      "published": "2026-10-06T09:17:41.410Z",
      "modified": "2026-10-06T09:17:41.410Z",
      "score": 2.1,
      "severity": "low",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "SourceCodester"
      ],
      "products": [
        "SourceCodester Simple Student Information System"
      ],
      "cwes": [
        "CWE-79",
        "CWE-94"
      ],
      "description": "A vulnerability was identified in SourceCodester Simple Student Information System 1.0. This issue affects some unknown processing of the file /register.php of the component Profile Field Handler. The manipulation of the argument firstname/lastname leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used."
    },
    {
      "id": "CVE-2026-105808",
      "url": "https://spydr.io/cve/CVE-2026-105808",
      "published": "2026-10-06T09:17:41.193Z",
      "modified": "2026-10-06T09:17:41.193Z",
      "score": 2,
      "severity": "low",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "SourceCodester"
      ],
      "products": [
        "SourceCodester Simple Student Information System"
      ],
      "cwes": [
        "CWE-79",
        "CWE-94"
      ],
      "description": "A vulnerability was determined in SourceCodester Simple Student Information System 1.0. This vulnerability affects the function clean of the file searchresults.php. Executing a manipulation of the argument searchbox can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized."
    },
    {
      "id": "CVE-2026-105317",
      "url": "https://spydr.io/cve/CVE-2026-105317",
      "published": "2026-10-06T09:17:41.043Z",
      "modified": "2026-10-06T09:17:41.043Z",
      "score": 8.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Cozmoslabs"
      ],
      "products": [
        "Cozmoslabs Paid Member Subscriptions"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Subscriber SQL Injection in Paid Member Subscriptions <= 3.1.1 versions."
    },
    {
      "id": "CVE-2026-105071",
      "url": "https://spydr.io/cve/CVE-2026-105071",
      "published": "2026-10-06T09:17:40.893Z",
      "modified": "2026-10-06T09:17:40.893Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Royal Plugins"
      ],
      "products": [
        "Royal Plugins SiteVault – Backup, Restore, Migration &amp; Cloning"
      ],
      "cwes": [
        "CWE-201"
      ],
      "description": "Unauthenticated Sensitive Data Exposure in SiteVault – Backup, Restore, Migration &amp; Cloning <= 1.5.17 versions."
    },
    {
      "id": "CVE-2026-105070",
      "url": "https://spydr.io/cve/CVE-2026-105070",
      "published": "2026-10-06T09:17:40.743Z",
      "modified": "2026-10-06T09:17:40.743Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Dimitri Grassi"
      ],
      "products": [
        "Dimitri Grassi Salon booking system"
      ],
      "cwes": [
        "CWE-266"
      ],
      "description": "Unauthenticated Privilege Escalation in Salon booking system <= 10.31.7 versions."
    },
    {
      "id": "CVE-2026-105061",
      "url": "https://spydr.io/cve/CVE-2026-105061",
      "published": "2026-10-06T09:17:40.597Z",
      "modified": "2026-10-06T09:17:40.597Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Bởi brandtoss"
      ],
      "products": [
        "Bởi brandtoss WP Mailster"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in WP Mailster <= 1.9.0.0 versions."
    },
    {
      "id": "CVE-2026-105059",
      "url": "https://spydr.io/cve/CVE-2026-105059",
      "published": "2026-10-06T09:17:40.440Z",
      "modified": "2026-10-06T09:17:40.440Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "royalnavneet"
      ],
      "products": [
        "royalnavneet Delete All Comments of wordpress"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Subscriber Broken Access Control in Delete All Comments of wordpress <= 7.1 versions."
    },
    {
      "id": "CVE-2026-105058",
      "url": "https://spydr.io/cve/CVE-2026-105058",
      "published": "2026-10-06T09:17:40.293Z",
      "modified": "2026-10-06T09:17:40.293Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "John James Jacoby"
      ],
      "products": [
        "John James Jacoby WP User Profiles"
      ],
      "cwes": [
        "CWE-266"
      ],
      "description": "Subscriber Privilege Escalation in WP User Profiles <= 2.7.3 versions."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
