Core
119 CVEs tracked. 2 of them are in CISA KEV.
This hub aggregates every CVE we track for Core, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Core CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 1 |
| 2025-03 | 1 |
| 2025-04 | 3 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 1 |
| 2025-10 | 3 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 4 |
| 2026-03 | 17 |
| 2026-04 | 5 |
| 2026-05 | 14 |
| 2026-06 | 4 |
| 2026-07 | 4 |
| 2026-08 | 9 |
| 2026-09 | 8 |
Severity
How the 119 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical16
- High47
- Medium49
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting Core.
- CVE-2026-63000REDAXO: Missing CSRF Protection on Package Update Action Allows Forced Addon Updates6.4
- CVE-2026-62998REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration4.3
- CVE-2026-63002REDAXO: Stored XSS in Mediapool Sync Page via Unescaped Filesystem Filenames4.8
- CVE-2026-63001REDAXO: Stored XSS via Unescaped Media Manager Type Name in `mediaIsInUse()`4.8
- CVE-2026-91129Home Assistant: mDNS Server-Side Request Forgery5.4
- CVE-2026-91130Home Assistant: XSS in Statistics Graph Card—
- CVE-2026-53581ntp: write path traversal9.0
- CVE-2026-85093Cheshire Cat AI Memory Collection Endpoint Information Disclosure6.5
- CVE-2026-57499Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE)9.1
- CVE-2026-73420NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass—
- CVE-2026-73419NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them6.8
- CVE-2026-73418NextAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers7.5
- CVE-2026-66061Home Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enabling silent automation execution7.1
- CVE-2026-66060Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callers7.1
- CVE-2026-59717Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing4.3
Product grouping is registry-driven, with AI assist and human review. How it works