Every hour we pull new vulnerabilities from public feeds and match them to what each site in the index shows publicly. You see counts. Each owner sees only their own site.
CISA confirmed attacks in the wild and added it to its catalogue of exploited vulnerabilities. Mass exploitation of holes like this is what fills the index.
CMS version from the generator tag and asset links. Plugins and modules from their public paths. Their versions from readme files and asset links. Plain GET requests, nothing more.
A version inside an affected range makes a site likely affected, never proven: hosts sometimes patch without changing the number. Exploited-now holes jump the queue.
Monitored sites get an alert the same day. Every reachable site that is likely affected gets one free notice when a hole is exploited now. The public page only moves a number.