CVE Tools

CMS

361 CVEs tracked. 6 of them are in CISA KEV.

This hub aggregates every CVE we track for CMS, a product in the web CMS plugins space. Use it to gauge the current risk picture and drill into individual advisories.

CMS CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
CMS CVEs per month
MonthCVEs
2024-100
2024-116
2024-124
2025-012
2025-021
2025-032
2025-044
2025-054
2025-0617
2025-074
2025-086
2025-093
2025-106
2025-110
2025-121
2026-016
2026-0225
2026-0337
2026-0416
2026-055
2026-0612
2026-0719
2026-0821
2026-0935

Severity

How the 361 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical185%
  • High8425%
  • Medium18554%
  • Low5316%

Latest CVEs

The 15 most recently published vulnerabilities affecting CMS.

  1. CVE-2026-92594Craft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQL7.5
  2. CVE-2026-92593Craft CMS 5.10.0 before 5.10.13 Authenticated Remote Code Execution8.8
  3. CVE-2026-92592Craft CMS before 4.18.6 Remote Code Execution via signed cookie8.8
  4. CVE-2026-92591Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer5.9
  5. CVE-2026-92590Craft CMS 5.7.0 before 5.10.13 Stored XSS via Generated Fields5.4
  6. CVE-2026-92589Craft CMS 5.0.0 before 5.10.13 Broken Access Control via nested-elements/reorder4.3
  7. CVE-2026-90709Yot CMS Admin Console admin.php eval code injection4.7
  8. CVE-2026-90708Yot CMS Cookie global.php login sql injection7.3
  9. CVE-2026-79987Low-privilege RCE through element-search eager loading8.8
  10. CVE-2026-86732Craft CMS before 5.10.12 Remote Code Execution via element-index8.8
  11. CVE-2026-86731Craft CMS 5.0.0-RC1 before 5.10.12 Permission Escalation via UsersController6.5
  12. CVE-2026-86730Craft CMS 5.0.0-RC1 before 5.10.12 Behavior Injection RCE8.8
  13. CVE-2026-86308light0011 cms Debug Mode config.php information disclosure5.3
  14. CVE-2026-86307light0011 cms cross-site request forgery4.3
  15. CVE-2026-86306light0011 cms Cookie Helper UserModel.class.php improper authentication7.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store