{
  "query": {
    "page": "60"
  },
  "count": 20,
  "total": 47696,
  "page": 60,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T02:48:45.529Z",
    "kev": "2026-10-08T03:49:47.849Z",
    "epss": "2026-10-08T01:00:40.923Z",
    "breaches": "2026-10-08T00:48:40.536Z",
    "posts": "2026-10-08T03:48:47.954Z"
  },
  "links": {
    "web": "https://spydr.io/threats?page=60",
    "next": "https://spydr.io/threats.json?page=61"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2026-41562",
      "url": "https://spydr.io/cve/CVE-2026-41562",
      "published": "2026-10-06T09:17:54.023Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00316,
      "epss_percentile": 0.22485,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "norvisgabriel"
      ],
      "products": [
        "norvisgabriel Norvis Backup"
      ],
      "cwes": [
        "CWE-201"
      ],
      "description": "Unauthenticated Sensitive Data Exposure in Norvis Backup <= 1.1.0 versions."
    },
    {
      "id": "CVE-2026-41561",
      "url": "https://spydr.io/cve/CVE-2026-41561",
      "published": "2026-10-06T09:17:53.873Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00316,
      "epss_percentile": 0.22484,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Adrian Lin"
      ],
      "products": [
        "Adrian Lin Museder RestoreOne"
      ],
      "cwes": [
        "CWE-201"
      ],
      "description": "Unauthenticated Sensitive Data Exposure in Museder RestoreOne <= 2.7.276 versions."
    },
    {
      "id": "CVE-2026-41560",
      "url": "https://spydr.io/cve/CVE-2026-41560",
      "published": "2026-10-06T09:17:53.730Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00299,
      "epss_percentile": 0.2073,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "wxdlabs"
      ],
      "products": [
        "wxdlabs WXD Backup Lite"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Unauthenticated Broken Access Control in WXD Backup Lite <= 1.0.2 versions."
    },
    {
      "id": "CVE-2026-41559",
      "url": "https://spydr.io/cve/CVE-2026-41559",
      "published": "2026-10-06T09:17:53.583Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00316,
      "epss_percentile": 0.22485,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Pluginjoy"
      ],
      "products": [
        "Pluginjoy SafeSnap – Verified WordPress Backup &amp; Restore"
      ],
      "cwes": [
        "CWE-201"
      ],
      "description": "Unauthenticated Sensitive Data Exposure in SafeSnap – Verified WordPress Backup &amp; Restore <= 2.1.2 versions."
    },
    {
      "id": "CVE-2026-41555",
      "url": "https://spydr.io/cve/CVE-2026-41555",
      "published": "2026-10-06T09:17:53.433Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00247,
      "epss_percentile": 0.1463,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Weblizar – WordPress Themes & Plugin"
      ],
      "products": [
        "Weblizar – WordPress Themes & Plugin Newsletter Subscription Form – User Subscriptions Form, Capture Email"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions."
    },
    {
      "id": "CVE-2026-40807",
      "url": "https://spydr.io/cve/CVE-2026-40807",
      "published": "2026-10-06T09:17:53.287Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00191,
      "epss_percentile": 0.08035,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Aman"
      ],
      "products": [
        "Aman CF7 Views &#8211; Complete Entry Management for Contact Form 7"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in CF7 Views &#8211; Complete Entry Management for Contact Form 7 <= 3.2.6 versions."
    },
    {
      "id": "CVE-2026-40806",
      "url": "https://spydr.io/cve/CVE-2026-40806",
      "published": "2026-10-06T09:17:53.140Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00191,
      "epss_percentile": 0.08034,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Plugin Devs"
      ],
      "products": [
        "Plugin Devs Blog, Posts and Category Filter for Elementor"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions."
    },
    {
      "id": "CVE-2026-39798",
      "url": "https://spydr.io/cve/CVE-2026-39798",
      "published": "2026-10-06T09:17:52.990Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00253,
      "epss_percentile": 0.15359,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "ThemetechMount"
      ],
      "products": [
        "ThemetechMount TrueBooker"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions."
    },
    {
      "id": "CVE-2026-39797",
      "url": "https://spydr.io/cve/CVE-2026-39797",
      "published": "2026-10-06T09:17:52.843Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00336,
      "epss_percentile": 0.24936,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Data443 Risk Mitigation, Inc."
      ],
      "products": [
        "Data443 Risk Mitigation, Inc. GDPR Framework By Data443"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions."
    },
    {
      "id": "CVE-2026-39796",
      "url": "https://spydr.io/cve/CVE-2026-39796",
      "published": "2026-10-06T09:17:52.697Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00299,
      "epss_percentile": 0.2073,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Flipper Code – WordPress Development Company"
      ],
      "products": [
        "Flipper Code – WordPress Development Company Advanced Posts Listing – Show Post List Easily"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions."
    },
    {
      "id": "CVE-2026-39795",
      "url": "https://spydr.io/cve/CVE-2026-39795",
      "published": "2026-10-06T09:17:52.540Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00325,
      "epss_percentile": 0.2348,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "brewlabs"
      ],
      "products": [
        "brewlabs SendPress Newsletters"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions."
    },
    {
      "id": "CVE-2026-39794",
      "url": "https://spydr.io/cve/CVE-2026-39794",
      "published": "2026-10-06T09:17:52.387Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00394,
      "epss_percentile": 0.31424,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "WC Lovers"
      ],
      "products": [
        "WC Lovers WooCommerce Multivendor Marketplace – REST API"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions."
    },
    {
      "id": "CVE-2026-39793",
      "url": "https://spydr.io/cve/CVE-2026-39793",
      "published": "2026-10-06T09:17:52.237Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00423,
      "epss_percentile": 0.34553,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Nicu Micle"
      ],
      "products": [
        "Nicu Micle Simple JWT Login"
      ],
      "cwes": [
        "CWE-288"
      ],
      "description": "Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions."
    },
    {
      "id": "CVE-2026-39792",
      "url": "https://spydr.io/cve/CVE-2026-39792",
      "published": "2026-10-06T09:17:52.080Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
      "score_source": "patchstack.com",
      "epss": 0.0036,
      "epss_percentile": 0.27679,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Mitchell Bennis"
      ],
      "products": [
        "Mitchell Bennis Simple File List"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Unauthenticated Arbitrary File Deletion in Simple File List <= 6.3.11 versions."
    },
    {
      "id": "CVE-2026-39791",
      "url": "https://spydr.io/cve/CVE-2026-39791",
      "published": "2026-10-06T09:17:51.930Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00251,
      "epss_percentile": 0.15075,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Mailjet"
      ],
      "products": [
        "Mailjet Email Marketing"
      ],
      "cwes": [
        "CWE-201"
      ],
      "description": "Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions."
    },
    {
      "id": "CVE-2026-39790",
      "url": "https://spydr.io/cve/CVE-2026-39790",
      "published": "2026-10-06T09:17:51.777Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00251,
      "epss_percentile": 0.15166,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "e4jvikwp"
      ],
      "products": [
        "e4jvikwp VikRentCar"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in VikRentCar <= 1.4.6 versions."
    },
    {
      "id": "CVE-2026-39788",
      "url": "https://spydr.io/cve/CVE-2026-39788",
      "published": "2026-10-06T09:17:51.627Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00224,
      "epss_percentile": 0.12018,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Shamim Hasan"
      ],
      "products": [
        "Shamim Hasan Front End PM"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Subscriber Cross Site Scripting (XSS) in Front End PM <= 11.4.6 versions."
    },
    {
      "id": "CVE-2026-39787",
      "url": "https://spydr.io/cve/CVE-2026-39787",
      "published": "2026-10-06T09:17:51.267Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "score_source": "patchstack.com",
      "epss": 0.0029,
      "epss_percentile": 0.19716,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "10Web"
      ],
      "products": [
        "10Web Social Photo Feed"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Unauthenticated Broken Access Control in 10Web Social Photo Feed <= 1.4.35 versions."
    },
    {
      "id": "CVE-2026-39785",
      "url": "https://spydr.io/cve/CVE-2026-39785",
      "published": "2026-10-06T09:17:51.100Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00247,
      "epss_percentile": 0.1463,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Serhii Pasyuk"
      ],
      "products": [
        "Serhii Pasyuk Gmedia Photo Gallery"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Unauthenticated SQL Injection in Gmedia Photo Gallery <= 1.25.1 versions."
    },
    {
      "id": "CVE-2026-39784",
      "url": "https://spydr.io/cve/CVE-2026-39784",
      "published": "2026-10-06T09:17:50.940Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00191,
      "epss_percentile": 0.08035,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "nicdark"
      ],
      "products": [
        "nicdark Hotel Booking"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Hotel Booking <= 3.8 versions."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
