25 CVEs affecting Webmproject products, 2 known to be exploited (CISA KEV), with EPSS scores. Most affected: Libwebp, Libvpx, Libwebm.