| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-59669 | Multiple vulnerabilities in the Repasat application | Repasat | Repasat application | Medium | 4.8 | 2026-10-02 08:40:53 | Deep Dive |
| CVE-2026-91784 | Argument Injection leading to arbitrary process termination in gotop | cjbassi | gotop | Medium | 4.8 | 2026-10-02 08:38:43 | Deep Dive |
| CVE-2026-18036 | NTRU leaks private key information by reducing secret values with a non-constant-time integer division | Legion of the Bouncy Castle Inc. | BC-JAVA | High | 8.2 | 2026-10-02 07:54:16 | Deep Dive |
| CVE-2026-94432 | Appointment Booking Plugin <= 5.7.1 - Insecure Direct Object Reference to Unauthenticated Unauthorized Transaction Intent Creation/Modification and Invoice Enumeration via 'invoice_id' Parameter | latepoint | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress | Medium | 5.3 | 2026-10-02 07:39:29 | Deep Dive |
| CVE-2026-97637 | JSON API Auth <= 3.1.2 - Unauthenticated Authentication Bypass via Cached 'generate_auth_cookie' Response | parorrey | JSON API Auth | Critical | 9.8 | 2026-10-02 07:39:29 | Deep Dive |
| CVE-2026-97338 | Download Manager <= 3.3.70 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Display Name | codename065 | Download Manager | Medium | 6.4 | 2026-10-02 07:39:29 | Deep Dive |
| CVE-2026-95670 | No External Links <= 5.2.0 - Unauthenticated Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect | mihdan | No External Links | High | 7.2 | 2026-10-02 07:39:28 | Deep Dive |
| CVE-2026-96647 | Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 6.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lsd[remark]' Parameter | webilia | Listdom: AI-powered Business Directory with Classifieds Ads Listings | Medium | 6.4 | 2026-10-02 07:39:28 | Deep Dive |
| CVE-2026-97634 | Event Tickets and Registration <= 5.29.5 - Authenticated (Contributor+) SQL Injection via 'orderby' Parameter | stellarwp | Event Tickets and Registration | Medium | 6.5 | 2026-10-02 07:39:28 | Deep Dive |
| CVE-2026-100107 | Kubio AI Page Builder <= 2.9.2 - Unauthenticated Stored Cross-Site Scripting via SVG Comment Content (KSES Allowlist Bypass) | extendthemes | Kubio AI Page Builder | High | 7.2 | 2026-10-02 07:39:27 | Deep Dive |
| CVE-2026-93756 | Smash Balloon Social Post Feed <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via Facebook Comment Message in Admin Builder Preview | smub | Smash Balloon Social Post Feed – Simple Social Feeds for WordPress | High | 7.2 | 2026-10-02 07:39:27 | Deep Dive |
| CVE-2026-96871 | Mang Board <= 2.4.2 - Unauthenticated Stored Cross-Site Scripting via 'data_type' Parameter | kitae-park | Mang Board | High | 7.2 | 2026-10-02 07:39:27 | Deep Dive |
| CVE-2026-97342 | JetFormBuilder <= 3.6.5.4 - Unauthenticated Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action | jetmonsters | JetFormBuilder — Dynamic Blocks Form Builder | High | 7.2 | 2026-10-02 07:39:26 | Deep Dive |
| CVE-2026-103426 | Relevanssi Premium <= 2.31.4 - Unauthenticated Stored Cross-Site Scripting via '_rt' Parameter | Relevanssi | Relevanssi Premium | High | 7.2 | 2026-10-02 07:39:25 | Deep Dive |
| CVE-2026-96566 | Newsletter <= 9.4.0 - Unauthenticated Stored Cross-Site Scripting via 'np1' Custom Field Parameter | satollo | Newsletter – Send awesome emails from WordPress | High | 7.2 | 2026-10-02 07:39:25 | Deep Dive |
| CVE-2026-102002 | Otter Blocks <= 3.2.6 - Authenticated (Subscriber+) Sensitive Information Exposure in Form Submissions Dashboard Widget | themeisle | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | Low | 3.1 | 2026-10-02 07:39:24 | Deep Dive |
| CVE-2026-12951 | MultiVendorX <= 5.0.18 - Authenticated (Store Manager+) SQL Injection via 'order_by' Parameter | wcmp | MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions | Medium | 6.5 | 2026-10-02 07:39:24 | Deep Dive |
| CVE-2026-100182 | Download Monitor <= 5.2.10 - Unauthenticated Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor | wpchill | Download Monitor | High | 7.2 | 2026-10-02 07:39:24 | Deep Dive |
| CVE-2026-102772 | CMB2 <= 2.13.1 - Unauthenticated Stored Cross-Site Scripting via 'textarea_code' Field | jtsternberg | CMB2 | High | 7.2 | 2026-10-02 07:39:23 | Deep Dive |
| CVE-2026-97641 | Relevanssi <= 4.28.3 - Unauthenticated Stored Cross-Site Scripting via Comment Content | comesio | Relevanssi – A Better Search | High | 7.2 | 2026-10-02 07:39:23 | Deep Dive |