Solution sectors / web-cms-plugins
Web & CMS Plugins
The web's content-management layer — WordPress plugins and themes, CMS cores and e-commerce platforms — is one of the most frequently exploited targets online. This hub tracks CVE volume and severity across it.
wordpress-plugin · 122cms-core · 107wordpress-theme · 13ecommerce-platform · 12site-builder · 12forum-wiki · 2
Cumulative CVEs
64,305
across 291 monthly snapshots
Latest month
767 · proj
-45.0% MoM · -13.0% YoY
Peak month
1,581
Mar 26
KEV this month
0
176 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- Mixed65%
- On-prem31%
- SaaS4%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Web & CMS Plugins.
- CVE-2026-49262Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxy3.0
- CVE-2026-66659WordPress Tablesome Table plugin <= 1.2.9 - SQL Injection vulnerability9.3
- CVE-2026-15606Frontend Admin by DynamiApps <= 3.29.9 - Authenticated (Subscriber+) Arbitrary Password Reset via Encrypted Object Token8.8
- CVE-2026-19091GeoDirectory <= 2.8.169 - Authenticated (Subscriber+) Arbitrary File Deletion via 'post_type' Parameter via Query-String Bypass in geodir_save_post + geodir_delete_revision8.1
- CVE-2026-13457InstaWP Connect <= 0.1.3.6 - Unauthenticated Cryptographic Key Disclosure7.5
- CVE-2026-16230Formidable Digital Signatures <= 3.0.6 - Unauthenticated Arbitrary File Deletion via Signature Field9.8
- CVE-2026-15426AcyMailing <= 10.11.1 - Authenticated (Subscriber+) Missing Authorization to Account Takeover via Notification Template Update8.8
- CVE-2022-50997Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp7.5
- CVE-2016-20097Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad7.5
- CVE-2026-56721CamaleonCMS 2.9.2 Privilege Escalation via Parameter Confusion in UsersController8.8
- CVE-2026-56720CamaleonCMS 2.9.2 and earlier Missing Authorization via profile Action4.3
- CVE-2026-73069Twenty: SQL Injection in the `searchVector` Field Settings Allows Arbitrary PostgreSQL Execution9.1
- CVE-2026-46670YesWiki: Unauthenticated SQL Injection9.8
- CVE-2026-72785Craft CMS before 5.10.6 Authorization Bypass via structures/move-element4.3
- CVE-2026-72784Craft CMS 5.0.0-RC1 before 5.10.6 SSRF via GraphQL asset mutation5.4
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| apache software foundation | 60 | 14 | · |
| apache | 59 | 14 | · |
| sourcecodester | 12 | · | · |
| tryghost | 9 | · | · |
| statamic | 7 | · | · |
| ancorathemes | 5 | 5 | · |
| code-projects | 5 | · | · |
| axiomthemes | 4 | 4 | · |
| codesupplyco | 4 | · | · |
| bdthemes | 3 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| wordpress-plugin | 122 | 13 | · | 96 | — | powerkit – supercharge your wordpress site (3) · wgdashboard (3) · formgent – next-gen ai form builder for wordpress with multi-step, quizzes, payments & more (2) |
| cms-core | 107 | 18 | · | 37 | — | ghost (9) · cms (7) · answer (6) |
| — | 29 | 4 | · | 15 | — | red hat build of keycloak (6) · red hat build of keycloak 26.4 (6) · nifi (3) |
| wordpress-theme | 13 | 12 | · | 6 | — | 69 clothing (1) · a.williams (1) · abogado (1) |
| ecommerce-platform | 12 | 1 | · | 12 | — | advanced ajax product filters (1) · ctx feed (1) · dokan (1) |
| site-builder | 12 | 1 | · | 9 | — | cubewp framework (2) · dwsurvey (2) · backmeup (1) |
| forum-wiki | 2 | · | · | 1 | — | flarum framework (2) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification