{
  "query": {
    "page": "75"
  },
  "count": 20,
  "total": 47961,
  "page": 75,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T16:49:18.208Z",
    "kev": "2026-10-08T17:50:20.616Z",
    "epss": "2026-10-08T13:01:09.708Z",
    "breaches": "2026-10-08T12:49:09.286Z",
    "posts": "2026-10-08T17:49:20.867Z"
  },
  "links": {
    "web": "https://spydr.io/threats?page=75",
    "next": "https://spydr.io/threats.json?page=76"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2026-39762",
      "url": "https://spydr.io/cve/CVE-2026-39762",
      "published": "2026-10-06T09:17:48.160Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00332,
      "epss_percentile": 0.24356,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Patterns In The Cloud"
      ],
      "products": [
        "Patterns In The Cloud Autoship Cloud for WooCommerce Subscription Products"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Missing Authorization vulnerability in Patterns In The Cloud Autoship Cloud for WooCommerce Subscription Products autoship-cloud allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.17.1."
    },
    {
      "id": "CVE-2026-39761",
      "url": "https://spydr.io/cve/CVE-2026-39761",
      "published": "2026-10-06T09:17:48.010Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00483,
      "epss_percentile": 0.39609,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "eLightUp"
      ],
      "products": [
        "eLightUp Meta Box AIO"
      ],
      "cwes": [
        "CWE-266"
      ],
      "description": "Unauthenticated Privilege Escalation in Meta Box AIO <= 3.7.1 versions."
    },
    {
      "id": "CVE-2026-39759",
      "url": "https://spydr.io/cve/CVE-2026-39759",
      "published": "2026-10-06T09:17:47.853Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00479,
      "epss_percentile": 0.39364,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "AmentoTech"
      ],
      "products": [
        "AmentoTech Workreap Core"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions."
    },
    {
      "id": "CVE-2026-39758",
      "url": "https://spydr.io/cve/CVE-2026-39758",
      "published": "2026-10-06T09:17:47.707Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00251,
      "epss_percentile": 0.15167,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Midtrans"
      ],
      "products": [
        "Midtrans-WooCommerce"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Midtrans-WooCommerce <= 2.32.3 versions."
    },
    {
      "id": "CVE-2026-39757",
      "url": "https://spydr.io/cve/CVE-2026-39757",
      "published": "2026-10-06T09:17:47.553Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00479,
      "epss_percentile": 0.39364,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "AmentoTech"
      ],
      "products": [
        "AmentoTech Taskbot"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions."
    },
    {
      "id": "CVE-2026-39756",
      "url": "https://spydr.io/cve/CVE-2026-39756",
      "published": "2026-10-06T09:17:47.387Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00255,
      "epss_percentile": 0.15663,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Wappointment team"
      ],
      "products": [
        "Wappointment team Wappointment"
      ],
      "cwes": [
        "CWE-639"
      ],
      "description": "Unauthenticated Insecure Direct Object References (IDOR) in Wappointment <= 2.7.7 versions."
    },
    {
      "id": "CVE-2026-39755",
      "url": "https://spydr.io/cve/CVE-2026-39755",
      "published": "2026-10-06T09:17:47.237Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00447,
      "epss_percentile": 0.36804,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "revmakx"
      ],
      "products": [
        "revmakx WP Duplicate"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions."
    },
    {
      "id": "CVE-2026-39754",
      "url": "https://spydr.io/cve/CVE-2026-39754",
      "published": "2026-10-06T09:17:47.087Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00328,
      "epss_percentile": 0.2388,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "About Piotnet"
      ],
      "products": [
        "About Piotnet Piotnet Addons For Elementor"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Contributor Arbitrary File Download in Piotnet Addons For Elementor <= 7.1.71 versions."
    },
    {
      "id": "CVE-2026-39753",
      "url": "https://spydr.io/cve/CVE-2026-39753",
      "published": "2026-10-06T09:17:46.940Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": 0.0045,
      "epss_percentile": 0.37071,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "AmentoTech"
      ],
      "products": [
        "AmentoTech Taskbot"
      ],
      "cwes": [
        "CWE-266"
      ],
      "description": "Unauthenticated Privilege Escalation in Taskbot <= 6.6 versions."
    },
    {
      "id": "CVE-2026-39752",
      "url": "https://spydr.io/cve/CVE-2026-39752",
      "published": "2026-10-06T09:17:46.790Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H",
      "score_source": "patchstack.com",
      "epss": 0.0045,
      "epss_percentile": 0.37045,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "BlueGlass Interactive AG"
      ],
      "products": [
        "BlueGlass Interactive AG Jobs for WordPress"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Contributor Arbitrary File Deletion in Jobs for WordPress <= 2.8.2 versions."
    },
    {
      "id": "CVE-2026-39751",
      "url": "https://spydr.io/cve/CVE-2026-39751",
      "published": "2026-10-06T09:17:46.640Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00323,
      "epss_percentile": 0.23304,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Payplug"
      ],
      "products": [
        "PayPlug for WooCommerce (Official)"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Unauthenticated Broken Access Control in PayPlug for WooCommerce (Official) <= 3.1.0 versions."
    },
    {
      "id": "CVE-2026-39750",
      "url": "https://spydr.io/cve/CVE-2026-39750",
      "published": "2026-10-06T09:17:46.487Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00237,
      "epss_percentile": 0.13464,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "weDevs"
      ],
      "products": [
        "weDevs StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.0.6 versions."
    },
    {
      "id": "CVE-2026-39749",
      "url": "https://spydr.io/cve/CVE-2026-39749",
      "published": "2026-10-06T09:17:46.333Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00279,
      "epss_percentile": 0.18651,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "digitalpoint"
      ],
      "products": [
        "digitalpoint App for Cloudflare®"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Subscriber Broken Access Control in App for Cloudflare® <= 1.10.1 versions."
    },
    {
      "id": "CVE-2026-39748",
      "url": "https://spydr.io/cve/CVE-2026-39748",
      "published": "2026-10-06T09:17:46.180Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00237,
      "epss_percentile": 0.13465,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "ThemeMove"
      ],
      "products": [
        "ThemeMove EduMall"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in EduMall <= 4.5.3 versions."
    },
    {
      "id": "CVE-2026-39747",
      "url": "https://spydr.io/cve/CVE-2026-39747",
      "published": "2026-10-06T09:17:46.033Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 8.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00342,
      "epss_percentile": 0.25635,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "WofficeIO"
      ],
      "products": [
        "WofficeIO Woffice"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Subscriber SQL Injection in Woffice <= 5.4.35 versions."
    },
    {
      "id": "CVE-2026-39746",
      "url": "https://spydr.io/cve/CVE-2026-39746",
      "published": "2026-10-06T09:17:45.883Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00383,
      "epss_percentile": 0.30217,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "fs-code"
      ],
      "products": [
        "fs-code Booknetic"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Unauthenticated SQL Injection in Booknetic <= 4.8.5 versions."
    },
    {
      "id": "CVE-2026-39745",
      "url": "https://spydr.io/cve/CVE-2026-39745",
      "published": "2026-10-06T09:17:45.730Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00237,
      "epss_percentile": 0.13467,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "bestweblayout"
      ],
      "products": [
        "bestweblayout Contact Form to DB by BestWebSoft"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Contact Form to DB by BestWebSoft <= 1.7.6 versions."
    },
    {
      "id": "CVE-2026-39731",
      "url": "https://spydr.io/cve/CVE-2026-39731",
      "published": "2026-10-06T09:17:45.583Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00237,
      "epss_percentile": 0.13468,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "code4life"
      ],
      "products": [
        "code4life Database for CF7"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Database for CF7 <= 1.2.6 versions."
    },
    {
      "id": "CVE-2026-39730",
      "url": "https://spydr.io/cve/CVE-2026-39730",
      "published": "2026-10-06T09:17:45.433Z",
      "modified": "2026-10-07T16:17:47.827Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00307,
      "epss_percentile": 0.21541,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Marcin"
      ],
      "products": [
        "Marcin Wise Chat"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Missing Authorization vulnerability in Marcin Wise Chat wise-chat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wise Chat: from n/a through 3.4.3."
    },
    {
      "id": "CVE-2026-39729",
      "url": "https://spydr.io/cve/CVE-2026-39729",
      "published": "2026-10-06T09:17:45.287Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00336,
      "epss_percentile": 0.24883,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "WisdmLabs"
      ],
      "products": [
        "WisdmLabs Edwiser Bridge"
      ],
      "cwes": [
        "CWE-201"
      ],
      "description": "Unauthenticated Sensitive Data Exposure in Edwiser Bridge <= 4.3.4 versions."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
