{
  "query": {
    "page": "71"
  },
  "count": 20,
  "total": 47896,
  "page": 71,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T14:49:13.947Z",
    "kev": "2026-10-08T14:50:13.692Z",
    "epss": "2026-10-08T13:01:09.708Z",
    "breaches": "2026-10-08T12:49:09.286Z",
    "posts": "2026-10-08T14:49:13.947Z"
  },
  "links": {
    "web": "https://spydr.io/threats?page=71",
    "next": "https://spydr.io/threats.json?page=72"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2026-39781",
      "url": "https://spydr.io/cve/CVE-2026-39781",
      "published": "2026-10-06T09:17:50.793Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00191,
      "epss_percentile": 0.08035,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Dan Rossiter"
      ],
      "products": [
        "Dan Rossiter Document Gallery"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Document Gallery <= 5.1.1 versions."
    },
    {
      "id": "CVE-2026-39780",
      "url": "https://spydr.io/cve/CVE-2026-39780",
      "published": "2026-10-06T09:17:50.647Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00191,
      "epss_percentile": 0.08036,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Youzify"
      ],
      "products": [
        "Youzify"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Youzify <= 1.3.7 versions."
    },
    {
      "id": "CVE-2026-39778",
      "url": "https://spydr.io/cve/CVE-2026-39778",
      "published": "2026-10-06T09:17:50.503Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00191,
      "epss_percentile": 0.08036,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "themeansar"
      ],
      "products": [
        "themeansar Ansar Import – One Click Starter Sites – for Elementor &amp; Themes"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Ansar Import – One Click Starter Sites – for Elementor &amp; Themes <= 2.1.2 versions."
    },
    {
      "id": "CVE-2026-39776",
      "url": "https://spydr.io/cve/CVE-2026-39776",
      "published": "2026-10-06T09:17:50.347Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00384,
      "epss_percentile": 0.30301,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "wpshopmart"
      ],
      "products": [
        "wpshopmart Tabs"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Editor Remote Code Execution (RCE) in Tabs <= 2.5 versions."
    },
    {
      "id": "CVE-2026-39775",
      "url": "https://spydr.io/cve/CVE-2026-39775",
      "published": "2026-10-06T09:17:50.200Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00338,
      "epss_percentile": 0.25182,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "DexignZone"
      ],
      "products": [
        "DexignZone JobZilla - Job Board WordPress Theme"
      ],
      "cwes": [
        "CWE-266"
      ],
      "description": "Subscriber Privilege Escalation in JobZilla - Job Board WordPress Theme <= 2.2 versions."
    },
    {
      "id": "CVE-2026-39774",
      "url": "https://spydr.io/cve/CVE-2026-39774",
      "published": "2026-10-06T09:17:50.053Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00249,
      "epss_percentile": 0.14838,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Tourfic AI Studio"
      ],
      "products": [
        "Tourfic AI Studio Tourfic Pro"
      ],
      "cwes": [
        "CWE-266"
      ],
      "description": "Unauthenticated Privilege Escalation in Tourfic Pro <= 1.17.3 versions."
    },
    {
      "id": "CVE-2026-39773",
      "url": "https://spydr.io/cve/CVE-2026-39773",
      "published": "2026-10-06T09:17:49.900Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00288,
      "epss_percentile": 0.19545,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "AmentoTech"
      ],
      "products": [
        "AmentoTech Doctreat Core"
      ],
      "cwes": [
        "CWE-266"
      ],
      "description": "Unauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions."
    },
    {
      "id": "CVE-2026-39772",
      "url": "https://spydr.io/cve/CVE-2026-39772",
      "published": "2026-10-06T09:17:49.740Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00357,
      "epss_percentile": 0.27419,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "bestwebsoft"
      ],
      "products": [
        "bestwebsoft Captcha by BestWebSoft"
      ],
      "cwes": [
        "CWE-290"
      ],
      "description": "Unauthenticated Bypass Vulnerability in Captcha by BestWebSoft <= 5.2.8 versions."
    },
    {
      "id": "CVE-2026-39771",
      "url": "https://spydr.io/cve/CVE-2026-39771",
      "published": "2026-10-06T09:17:49.590Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 8.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": 0.0029,
      "epss_percentile": 0.1973,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "MightyNetworks vs BuddyBoss"
      ],
      "products": [
        "MightyNetworks vs BuddyBoss Buddyboss Platform"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Subscriber SQL Injection in Buddyboss Platform <= 3.1.0 versions."
    },
    {
      "id": "CVE-2026-39770",
      "url": "https://spydr.io/cve/CVE-2026-39770",
      "published": "2026-10-06T09:17:49.427Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00423,
      "epss_percentile": 0.34596,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "AmentoTech"
      ],
      "products": [
        "AmentoTech Doctreat"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions."
    },
    {
      "id": "CVE-2026-39769",
      "url": "https://spydr.io/cve/CVE-2026-39769",
      "published": "2026-10-06T09:17:49.280Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00485,
      "epss_percentile": 0.39748,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Iqonic Design"
      ],
      "products": [
        "Iqonic Design Graphina"
      ],
      "cwes": [
        "CWE-288"
      ],
      "description": "Unauthenticated Broken Authentication in Graphina <= 3.1.12 versions."
    },
    {
      "id": "CVE-2026-39767",
      "url": "https://spydr.io/cve/CVE-2026-39767",
      "published": "2026-10-06T09:17:48.763Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00411,
      "epss_percentile": 0.33246,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "baseapp"
      ],
      "products": [
        "baseapp WPBase Cache"
      ],
      "cwes": [
        "CWE-770"
      ],
      "description": "Subscriber Denial of Service Attack in WPBase Cache <= 5.5.6 versions."
    },
    {
      "id": "CVE-2026-39766",
      "url": "https://spydr.io/cve/CVE-2026-39766",
      "published": "2026-10-06T09:17:48.610Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00251,
      "epss_percentile": 0.15167,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "reputeinfosystems"
      ],
      "products": [
        "reputeinfosystems ARForms"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions."
    },
    {
      "id": "CVE-2026-39765",
      "url": "https://spydr.io/cve/CVE-2026-39765",
      "published": "2026-10-06T09:17:48.457Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00462,
      "epss_percentile": 0.38019,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "WebAppick"
      ],
      "products": [
        "WebAppick Challan"
      ],
      "cwes": [
        "CWE-266"
      ],
      "description": "Shop Manager Privilege Escalation in Challan <= 3.7.88 versions."
    },
    {
      "id": "CVE-2026-39764",
      "url": "https://spydr.io/cve/CVE-2026-39764",
      "published": "2026-10-06T09:17:48.310Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00304,
      "epss_percentile": 0.21267,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "RadiusTheme"
      ],
      "products": [
        "RadiusTheme Radius Booking — Booking Calendar for Appointments &amp; Services"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Unauthenticated SQL Injection in Radius Booking — Booking Calendar for Appointments &amp; Services <= 1.0.19 versions."
    },
    {
      "id": "CVE-2026-39762",
      "url": "https://spydr.io/cve/CVE-2026-39762",
      "published": "2026-10-06T09:17:48.160Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00332,
      "epss_percentile": 0.24356,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Patterns In The Cloud"
      ],
      "products": [
        "Patterns In The Cloud Autoship Cloud for WooCommerce Subscription Products"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Missing Authorization vulnerability in Patterns In The Cloud Autoship Cloud for WooCommerce Subscription Products autoship-cloud allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.17.1."
    },
    {
      "id": "CVE-2026-39761",
      "url": "https://spydr.io/cve/CVE-2026-39761",
      "published": "2026-10-06T09:17:48.010Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00483,
      "epss_percentile": 0.39609,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "eLightUp"
      ],
      "products": [
        "eLightUp Meta Box AIO"
      ],
      "cwes": [
        "CWE-266"
      ],
      "description": "Unauthenticated Privilege Escalation in Meta Box AIO <= 3.7.1 versions."
    },
    {
      "id": "CVE-2026-39759",
      "url": "https://spydr.io/cve/CVE-2026-39759",
      "published": "2026-10-06T09:17:47.853Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00479,
      "epss_percentile": 0.39364,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "AmentoTech"
      ],
      "products": [
        "AmentoTech Workreap Core"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions."
    },
    {
      "id": "CVE-2026-39758",
      "url": "https://spydr.io/cve/CVE-2026-39758",
      "published": "2026-10-06T09:17:47.707Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00251,
      "epss_percentile": 0.15167,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Midtrans"
      ],
      "products": [
        "Midtrans-WooCommerce"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Midtrans-WooCommerce <= 2.32.3 versions."
    },
    {
      "id": "CVE-2026-39757",
      "url": "https://spydr.io/cve/CVE-2026-39757",
      "published": "2026-10-06T09:17:47.553Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00479,
      "epss_percentile": 0.39364,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "AmentoTech"
      ],
      "products": [
        "AmentoTech Taskbot"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
