Web & CMS Plugins
66,504 CVEs tracked since 1999. In the last 12 months, 14,449, +22% on the 12 before.
Web & CMS Plugins by subsector, Sep 2026 so far
- WordPress plugins31829% · 198 vendors
- Not yet sub-classified314The tagger has not placed these yet
- CMS cores28627% · 74 vendors
- E-commerce platforms706% · 32 vendors
- 3 smaller subsectors90
- Site builders43
- WordPress themes24
- Forums & wikis23
Month by month
Every monthly snapshot of Web & CMS Plugins. A column is the CVEs published that month.
| Month | CVEs |
|---|---|
| 2021-09 | 268 |
| 2021-10 | 242 |
| 2021-11 | 227 |
| 2021-12 | 226 |
| 2022-01 | 270 |
| 2022-02 | 338 |
| 2022-03 | 395 |
| 2022-04 | 313 |
| 2022-05 | 342 |
| 2022-06 | 388 |
| 2022-07 | 234 |
| 2022-08 | 406 |
| 2022-09 | 353 |
| 2022-10 | 250 |
| 2022-11 | 391 |
| 2022-12 | 350 |
| 2023-01 | 450 |
| 2023-02 | 452 |
| 2023-03 | 0 |
| 2023-04 | 620 |
| 2023-05 | 591 |
| 2023-06 | 663 |
| 2023-07 | 527 |
| 2023-08 | 467 |
| 2023-09 | 489 |
| 2023-10 | 695 |
| 2023-11 | 805 |
| 2023-12 | 740 |
| 2024-01 | 687 |
| 2024-02 | 743 |
| 2024-03 | 1119 |
| 2024-04 | 1062 |
| 2024-05 | 1156 |
| 2024-06 | 952 |
| 2024-07 | 844 |
| 2024-08 | 842 |
| 2024-09 | 539 |
| 2024-10 | 978 |
| 2024-11 | 990 |
| 2024-12 | 1062 |
| 2025-01 | 1334 |
| 2025-02 | 822 |
| 2025-03 | 1033 |
| 2025-04 | 1321 |
| 2025-05 | 1003 |
| 2025-06 | 1052 |
| 2025-07 | 843 |
| 2025-08 | 882 |
| 2025-09 | 1043 |
| 2025-10 | 939 |
| 2025-11 | 794 |
| 2025-12 | 1423 |
| 2026-01 | 1115 |
| 2026-02 | 1107 |
| 2026-03 | 1581 |
| 2026-04 | 1025 |
| 2026-05 | 1134 |
| 2026-06 | 1476 |
| 2026-07 | 1394 |
| 2026-08 | 1418 |
| 2026-09 | 1078 |
Vendors
Who shipped the most Web & CMS Plugins CVEs in Sep 2026 so far, with their rank across all vendors.
Weaknesses
The weakness classes behind Web & CMS Plugins CVEs in Sep 2026 so far.
Latest CVEs
The 15 most recently published vulnerabilities in Web & CMS Plugins.
- CVE-2026-100739mathurvishal CloudClassroom-PHP-Project viewresult.php sql injection7.3
- CVE-2026-82901Ultra Addons for Contact Form 7 <= 3.5.50 - Unauthenticated Arbitrary File Upload via Signature Form Field9.8
- CVE-2026-77203Groups <= 4.6.0 - Authenticated (Subscriber+) Privilege Escalation via 'groups_join' Shortcode8.8
- CVE-2026-94131Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0—
- CVE-2026-94132Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0—
- CVE-2026-100694Hugo before 0.166.0 Cross-Site Scripting via text/org6.1
- CVE-2026-100693Hugo v0.162.0 before v0.166.0 IP-literal Deny Rule Bypass8.4
- CVE-2026-100692Hugo before v0.166.0 Path Traversal via Symlinked Mount Roots7.5
- CVE-2026-100691Hugo before 0.166.0 Stored XSS via lineAnchors code block option5.4
- CVE-2026-100690Hugo v0.161.0 to v0.165.0 Arbitrary File Read via Symlinks7.5
- CVE-2026-100673Grav Data Manager before 1.4.5 Stored XSS via item-detail view8.2
- CVE-2026-100672grav-plugin-comments before 1.2.11 Unauthenticated Information Disclosure7.5
- CVE-2026-100671Grav before 2.0.25 Session Cookie Theft via Twig Sandbox8.0
- CVE-2026-100670Grav CMS 2.0.14 through 2.0.24 Privilege Escalation via Blueprint Guard Bypass8.8
- CVE-2026-100669Grav before 2.0.25 Sensitive File Disclosure via Case-Variation Bypass7.5
The record
- Busiest month
- Mar 2026, 1,581 CVEs
- Sep 2026 so far
- 1,078 CVEs from 382 vendors
- Deployment
- On-prem, 59%
- Monthly snapshots
- 292 since 1999
Is your business exposed to threats like these?
Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.
Request an assessment