Solution sectors / web-cms-plugins
Web & CMS Plugins
The web's content-management layer — WordPress plugins and themes, CMS cores and e-commerce platforms — is one of the most frequently exploited targets online. This hub tracks CVE volume and severity across it.
wordpress-plugin · 295cms-core · 286wordpress-theme · 58site-builder · 47ecommerce-platform · 42forum-wiki · 5
Cumulative CVEs
63,492
across 290 monthly snapshots
Latest month
1,008 · proj
-31.7% MoM · +19.6% YoY
Peak month
1,581
Mar 26
KEV this month
2
367 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem63%
- Mixed31%
- SaaS5%
- Library1%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Web & CMS Plugins.
- CVE-2026-15962Fluent Forms Pro Add On Pack <= 6.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary User Password Change via User Meta Field8.8
- CVE-2026-10818WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering8.1
- CVE-2026-15425Yoast SEO <= 28.0 - Authenticated (Author+) Stored Cross-Site Scripting via Post Slug (post_name)6.4
- CVE-2026-14955Checkout Field Editor for WooCommerce (Pro) <= 3.7.7 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Read via 'thwcfe_legacy_file' Parameter6.5
- CVE-2026-65707Likeshop 3.0.5 Authenticated SQL Injection via adjustAccount Endpoint6.5
- CVE-2026-65693Microweber CMS 2.0.20 Server-Side Template Injection via Mail Templates7.2
- CVE-2026-8789Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Contributor+) Arbitrary Connection Deletion8.1
- CVE-2026-17059Keycloak-services: keycloak-services: information disclosure via role-users endpoint bypasses per-user view filter6.5
- CVE-2026-17048Keycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest api5.5
- CVE-2026-7484Improper Access Control in Abis Technology's AVESİS5.3
- CVE-2026-15663Ninja Forms <= 3.14.9 - Authenticated (Administrator+) SQL Injection via Import File 'settings' Key4.9
- CVE-2026-10033EventON Action User <= 2.5.14 - Missing Authorization to Unauthenticated Privilege Escalation via evoau_save_capability AJAX Action7.3
- CVE-2026-15401VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Unauthenticated Stored Cross-Site Scripting via Custom Field 'vbfX' Parameter7.2
- CVE-2026-15346VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Reflected Cross-Site Scripting via 'category_id' Parameter6.1
- CVE-2026-15739Rich Showcase for Google Reviews <= 6.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pagination' Shortcode Attribute6.4
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| apache software foundation | 78 | 24 | · |
| apache | 67 | 20 | · |
| drupal | 46 | 5 | · |
| sourcecodester | 46 | · | · |
| code-projects | 33 | · | · |
| getgrav | 29 | 1 | · |
| mediawiki | 25 | 3 | · |
| wikimedia foundation | 18 | 1 | · |
| fossbilling | 17 | · | · |
| getkirby | 13 | · | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| wordpress-plugin | 295 | 14 | · | 186 | — | easyappointments (6) · ecommerce-codeigniter-bootstrap (6) · givewp – donation plugin and fundraising platform (4) |
| cms-core | 286 | 28 | 2 | 66 | — | grav (31) · class and exam timetabling system (20) · kirby (13) |
| — | 145 | 10 | · | 29 | — | mediawiki (22) · red hat build of keycloak (13) · cms (11) |
| wordpress-theme | 58 | 6 | · | 36 | — | flatsome (4) · werkstatt (3) · blocksy companion (2) |
| site-builder | 47 | 3 | · | 24 | — | hugo (6) · filebrowser (5) · nocobase (4) |
| ecommerce-platform | 42 | 2 | · | 22 | — | fossbilling (17) · acymailing smtp newsletter (3) · pretix-oppwa (2) |
| forum-wiki | 5 | · | · | 4 | — | smf (2) · cms (1) · nodebb (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification