{"api_version":"v1","generated_at":"2026-10-08T18:05:00+00:00","product":{"cve_count":3,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-chouby-polylang-8b5c0e228204","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/polylang","name":"Polylang","next_cursor":null,"observations":[{"affected":"Polylang: n/a \u2264 3.8.9","affected_versions_present":true,"cve_id":"CVE-2026-97279","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-97279","fixed":"Update the WordPress Polylang plugin to the latest available version (at least 3.8.10).","last_modified":"2026-09-30T13:37:18.630Z","patch_url":"https://patchstack.com/database/wordpress/plugin/polylang/vulnerability/wordpress-polylang-plugin-3-8-9-cross-site-scripting-xss-vulnerability?_s_id=cve","primary_source":"","published":"2026-09-30T12:28:16.360Z"},{"affected":"\u2264 3.8.5","affected_versions_present":true,"cve_id":"CVE-2026-65458","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-65458","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-06T09:51:46.458Z","patch_url":"","primary_source":"","published":"2026-07-23T11:18:38.882Z"},{"affected":"\u2264 3.7.3","affected_versions_present":true,"cve_id":"CVE-2025-64353","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-64353","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T18:30:21.297Z","patch_url":"","primary_source":"","published":"2025-10-31T11:42:25.417Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"Chouby"}}
