{
  "append_only": true,
  "archive_index_url": "https://vuln.signal-radar.com/data/vuln/archive/index.json",
  "archive_version": "v0.1",
  "generated_at": "2026-08-10T05:04:14.185247+00:00",
  "immutable_run": true,
  "item_count": 20,
  "items": [
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18583/",
      "current_public_safe_latest": true,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.3994,
      "epss_score": 0.00496,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-18583",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18583.json",
      "product": null,
      "public_safe_summary": "NVD: A weakness has been identified in mz-automation libiec61850 up to 1.6.1. NVD: This issue affects the function checkDataSetAccess of the file src/iec61850/server/mms_mapping/mms_mapping.c of the component MMS Request Handler. NVD: This manipulation causes out-of-bounds read.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-18583.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A weakness has been identified in mz-automation libiec61850 up to 1.6.1. NVD: This issue affects the function checkDataSetAccess of the file src/iec61850/server/mms_mapping/mms_mapping.c of the component MMS Request Handler. NVD: This manipulation causes out-of-bounds read.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18583/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18584/",
      "current_public_safe_latest": true,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.13827,
      "epss_score": 0.0023,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-18584",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18584.json",
      "product": null,
      "public_safe_summary": "NVD: A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. NVD: Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. NVD: Such manipulation leads to improper authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-18584.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. NVD: Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. NVD: Such manipulation leads to improper authorization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18584/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18585/",
      "current_public_safe_latest": true,
      "cvss_score": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.22167,
      "epss_score": 0.00299,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-18585",
      "impact_tags": [
        "memory safety review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18585.json",
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. NVD: The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. NVD: Performing a manipulation results in heap-based buffer overflow.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-18585.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes memory safety review. Possible impact: The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. NVD: The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. NVD: Performing a manipulation results in heap-based buffer overflow.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18585/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6694/",
      "current_public_safe_latest": true,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04618,
      "epss_score": 0.00149,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-6694",
      "impact_tags": [
        "service availability review",
        "memory safety review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-6694.json",
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in GIMP's file-png plugin. NVD: A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. NVD: This can lead to a stack-based buffer overflow (CWE-121), causing the file-png plugin to crash and resulting in a Denial of Service (DoS) for the user.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-6694.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes service availability risk · memory safety review · remote exposure. Possible impact: The affected service may become unavailable or unreliable.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in GIMP's file-png plugin. NVD: A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. NVD: This can lead to a stack-based buffer overflow (CWE-121), causing the file-png plugin to crash and resulting in a Denial of Service (DoS) for the user.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6694/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-6695/",
      "current_public_safe_latest": true,
      "cvss_score": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04815,
      "epss_score": 0.00152,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-6695",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-6695.json",
      "product": null,
      "public_safe_summary": "NVD: A flaw was found in GIMP. NVD: A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. NVD: This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended memory buffer.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-6695.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw was found in GIMP. NVD: A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. NVD: This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended memory buffer.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-6695/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-15672/",
      "current_public_safe_latest": true,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.38234,
      "epss_score": 0.0047,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2025-15672",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2025-15672.json",
      "product": null,
      "public_safe_summary": "NVD: The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2025-15672.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-15672/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2025-15673/",
      "current_public_safe_latest": true,
      "cvss_score": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.27882,
      "epss_score": 0.00352,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2025-15673",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2025-15673.json",
      "product": null,
      "public_safe_summary": "NVD: The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2025-15673.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2025-15673/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12872/",
      "current_public_safe_latest": true,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.49362,
      "epss_score": 0.0069,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-12872",
      "impact_tags": [
        "code execution review",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-12872.json",
      "product": null,
      "public_safe_summary": "NVD: The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or nonce check, allowing unauthenticated attackers to upload arbitrary files (including PHP) to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-12872.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or nonce check, allowing unauthenticated attackers to upload arbitrary files (including PHP) to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12872/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-12965/",
      "current_public_safe_latest": true,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.24889,
      "epss_score": 0.00324,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-12965",
      "impact_tags": [
        "SQL injection risk",
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-12965.json",
      "product": null,
      "public_safe_summary": "NVD: The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-12965.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · remote exposure · authenticated boundary. Possible impact: A remote attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-12965/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-13340/",
      "current_public_safe_latest": true,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.07818,
      "epss_score": 0.00181,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-13340",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-13340.json",
      "product": null,
      "public_safe_summary": "NVD: The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and serves them as SVG, allowing a user permitted to upload SVGs (such as an Author once granted upload...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-13340.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and serves them as SVG, allowing a user permitted to upload SVGs (such as an Author once granted upload...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-13340/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-14557/",
      "current_public_safe_latest": true,
      "cvss_score": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.28186,
      "epss_score": 0.00354,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-14557",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-14557.json",
      "product": null,
      "public_safe_summary": "NVD: The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-14557.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-14557/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15231/",
      "current_public_safe_latest": true,
      "cvss_score": 2.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.12252,
      "epss_score": 0.00218,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-15231",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-15231.json",
      "product": null,
      "public_safe_summary": "NVD: The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-15231.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15231/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15254/",
      "current_public_safe_latest": true,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.10086,
      "epss_score": 0.00201,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-15254",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-15254.json",
      "product": null,
      "public_safe_summary": "NVD: The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-15254.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15254/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15260/",
      "current_public_safe_latest": true,
      "cvss_score": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.04878,
      "epss_score": 0.00152,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-15260",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-15260.json",
      "product": null,
      "public_safe_summary": "NVD: The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-15260.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users with subscriber-level access or above to modify or permanently delete other users' and posts' geolocation...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15260/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15383/",
      "current_public_safe_latest": true,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05834,
      "epss_score": 0.00162,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-15383",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-15383.json",
      "product": null,
      "public_safe_summary": "NVD: The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, which it stores through an unauthenticated tracking REST endpoint and later renders unescaped in an administrator report page. NVD: This allows an unauthenticated attacker to store a malicious script that executes in the session of any administrator who views the access report, leading to site takeover.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-15383.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, which it stores through an unauthenticated tracking REST endpoint and later renders unescaped in an administrator report page. NVD: This allows an unauthenticated attacker to store a malicious script that executes in the session of any administrator who views the access report, leading to site takeover.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15383/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15930/",
      "current_public_safe_latest": true,
      "cvss_score": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.14113,
      "epss_score": 0.00233,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-15930",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-15930.json",
      "product": null,
      "public_safe_summary": "NVD: The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-15930.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15930/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-15931/",
      "current_public_safe_latest": true,
      "cvss_score": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.05833,
      "epss_score": 0.00162,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-15931",
      "impact_tags": [
        "remote exposure relevant",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-15931.json",
      "product": null,
      "public_safe_summary": "NVD: The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when displaying it in the administration dashboard, allowing unauthenticated attackers to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-15931.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes remote exposure · authenticated boundary. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when displaying it in the administration dashboard, allowing unauthenticated attackers to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-15931/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16057/",
      "current_public_safe_latest": true,
      "cvss_score": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.14109,
      "epss_score": 0.00232,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-16057",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-16057.json",
      "product": null,
      "public_safe_summary": "NVD: The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-16057.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16057/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16060/",
      "current_public_safe_latest": true,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.38192,
      "epss_score": 0.00469,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-16060",
      "impact_tags": [
        "code execution review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-16060.json",
      "product": null,
      "public_safe_summary": "NVD: The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-16060.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16060/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-16250/",
      "current_public_safe_latest": true,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.4045,
      "epss_score": 0.00505,
      "first_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "id": "CVE-2026-16250",
      "impact_tags": [
        "code execution review",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T04:58:31.923491+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-16250.json",
      "product": null,
      "public_safe_summary": "NVD: The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/items/CVE-2026-16250.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to...",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-16250/timeline.json",
      "vendor": null
    }
  ],
  "public_safe_only": true,
  "radar": "vuln",
  "run_id": "20260810T050414Z",
  "run_index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T050414Z/index.json",
  "safety": {
    "auto_remediation_allowed": false,
    "exploit_detail_allowed": false,
    "external_execution_allowed": false,
    "github_issue_creation_allowed": false,
    "indexing_allowed": true,
    "noindex_removal_allowed": true,
    "noindex_required": false,
    "patch_allowed": false,
    "public_launch_allowed": true,
    "public_safe_only": true,
    "raw_source_included": false,
    "read_only": true,
    "scan_allowed": false,
    "search_console_registered": true,
    "signal_radar_integration_allowed": false
  },
  "schema_version": "v0.1"
}