CMS
361 CVEs tracked. 6 of them are in CISA KEV.
This hub aggregates every CVE we track for CMS, a product in the web CMS plugins space. Use it to gauge the current risk picture and drill into individual advisories.
CMS CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 6 |
| 2024-12 | 4 |
| 2025-01 | 2 |
| 2025-02 | 1 |
| 2025-03 | 2 |
| 2025-04 | 4 |
| 2025-05 | 4 |
| 2025-06 | 17 |
| 2025-07 | 4 |
| 2025-08 | 6 |
| 2025-09 | 3 |
| 2025-10 | 6 |
| 2025-11 | 0 |
| 2025-12 | 1 |
| 2026-01 | 6 |
| 2026-02 | 25 |
| 2026-03 | 37 |
| 2026-04 | 16 |
| 2026-05 | 5 |
| 2026-06 | 12 |
| 2026-07 | 19 |
| 2026-08 | 21 |
| 2026-09 | 35 |
Severity
How the 361 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical18
- High84
- Medium185
- Low53
Latest CVEs
The 15 most recently published vulnerabilities affecting CMS.
- CVE-2026-92594Craft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQL7.5
- CVE-2026-92593Craft CMS 5.10.0 before 5.10.13 Authenticated Remote Code Execution8.8
- CVE-2026-92592Craft CMS before 4.18.6 Remote Code Execution via signed cookie8.8
- CVE-2026-92591Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer5.9
- CVE-2026-92590Craft CMS 5.7.0 before 5.10.13 Stored XSS via Generated Fields5.4
- CVE-2026-92589Craft CMS 5.0.0 before 5.10.13 Broken Access Control via nested-elements/reorder4.3
- CVE-2026-90709Yot CMS Admin Console admin.php eval code injection4.7
- CVE-2026-90708Yot CMS Cookie global.php login sql injection7.3
- CVE-2026-79987Low-privilege RCE through element-search eager loading8.8
- CVE-2026-86732Craft CMS before 5.10.12 Remote Code Execution via element-index8.8
- CVE-2026-86731Craft CMS 5.0.0-RC1 before 5.10.12 Permission Escalation via UsersController6.5
- CVE-2026-86730Craft CMS 5.0.0-RC1 before 5.10.12 Behavior Injection RCE8.8
- CVE-2026-86308light0011 cms Debug Mode config.php information disclosure5.3
- CVE-2026-86307light0011 cms cross-site request forgery4.3
- CVE-2026-86306light0011 cms Cookie Helper UserModel.class.php improper authentication7.3
Product grouping is registry-driven, with AI assist and human review. How it works