CVE Tools

Web & CMS Plugins

66,504 CVEs tracked since 1999. In the last 12 months, 14,449, +22% on the 12 before.

Web & CMS Plugins by subsector, Sep 2026 so far

Sep 2026 so far: 1,078 CVEs across 7 subsectors. Area is each subsector's share; inside are the products it counted most. Point at one to read it.
  • WordPress plugins31829% · 198 vendors
  • Not yet sub-classified314The tagger has not placed these yet
  • CMS cores28627% · 74 vendors
  • E-commerce platforms706% · 32 vendors
  • 3 smaller subsectors90
    • Site builders43
    • WordPress themes24
    • Forums & wikis23

Month by month

Every monthly snapshot of Web & CMS Plugins. A column is the CVEs published that month.

Sep 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Web & CMS Plugins CVEs per month
MonthCVEs
2021-09268
2021-10242
2021-11227
2021-12226
2022-01270
2022-02338
2022-03395
2022-04313
2022-05342
2022-06388
2022-07234
2022-08406
2022-09353
2022-10250
2022-11391
2022-12350
2023-01450
2023-02452
2023-030
2023-04620
2023-05591
2023-06663
2023-07527
2023-08467
2023-09489
2023-10695
2023-11805
2023-12740
2024-01687
2024-02743
2024-031119
2024-041062
2024-051156
2024-06952
2024-07844
2024-08842
2024-09539
2024-10978
2024-11990
2024-121062
2025-011334
2025-02822
2025-031033
2025-041321
2025-051003
2025-061052
2025-07843
2025-08882
2025-091043
2025-10939
2025-11794
2025-121423
2026-011115
2026-021107
2026-031581
2026-041025
2026-051134
2026-061476
2026-071394
2026-081418
2026-091078

Vendors

Who shipped the most Web & CMS Plugins CVEs in Sep 2026 so far, with their rank across all vendors.

  1. Wwbn106#12
  2. Apache Software Foundation93#14
  3. Concrete CMS65#15
  4. Sourcecodester58#16
  5. Apache38#25
  6. code-projects28#39
  7. Drupal26#43
  8. Craftcms25#44

Weaknesses

The weakness classes behind Web & CMS Plugins CVEs in Sep 2026 so far.

  1. CWE-79 XSS357
  2. CWE-862 Missing Authorization217
  3. CWE-89 SQL Injection146
  4. CWE-639 Auth Bypass via User Key70
  5. CWE-200 Information Exposure50
  6. CWE-22 Path Traversal36

Latest CVEs

The 15 most recently published vulnerabilities in Web & CMS Plugins.

  1. CVE-2026-100739mathurvishal CloudClassroom-PHP-Project viewresult.php sql injection7.3
  2. CVE-2026-82901Ultra Addons for Contact Form 7 <= 3.5.50 - Unauthenticated Arbitrary File Upload via Signature Form Field9.8
  3. CVE-2026-77203Groups <= 4.6.0 - Authenticated (Subscriber+) Privilege Escalation via 'groups_join' Shortcode8.8
  4. CVE-2026-94131Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0—
  5. CVE-2026-94132Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0—
  6. CVE-2026-100694Hugo before 0.166.0 Cross-Site Scripting via text/org6.1
  7. CVE-2026-100693Hugo v0.162.0 before v0.166.0 IP-literal Deny Rule Bypass8.4
  8. CVE-2026-100692Hugo before v0.166.0 Path Traversal via Symlinked Mount Roots7.5
  9. CVE-2026-100691Hugo before 0.166.0 Stored XSS via lineAnchors code block option5.4
  10. CVE-2026-100690Hugo v0.161.0 to v0.165.0 Arbitrary File Read via Symlinks7.5
  11. CVE-2026-100673Grav Data Manager before 1.4.5 Stored XSS via item-detail view8.2
  12. CVE-2026-100672grav-plugin-comments before 1.2.11 Unauthenticated Information Disclosure7.5
  13. CVE-2026-100671Grav before 2.0.25 Session Cookie Theft via Twig Sandbox8.0
  14. CVE-2026-100670Grav CMS 2.0.14 through 2.0.24 Privilege Escalation via Blueprint Guard Bypass8.8
  15. CVE-2026-100669Grav before 2.0.25 Sensitive File Disclosure via Case-Variation Bypass7.5

The record

Busiest month
Mar 2026, 1,581 CVEs
Sep 2026 so far
1,078 CVEs from 382 vendors
Deployment
On-prem, 59%
Monthly snapshots
292 since 1999
All 15 sectors on one map

Is your business exposed to threats like these?

Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.

Request an assessment

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store