Solution sectors / web-cms-plugins
Web & CMS Plugins
The web's content-management layer — WordPress plugins and themes, CMS cores and e-commerce platforms — is one of the most frequently exploited targets online. This hub tracks CVE volume and severity across it.
wordpress-plugin · 180cms-core · 171site-builder · 29ecommerce-platform · 27forum-wiki · 19wordpress-theme · 18
Cumulative CVEs
66,049
across 292 monthly snapshots
Latest month
1,246 · proj
-12.1% MoM · +19.5% YoY
Peak month
1,581
Mar 26
KEV this month
0
242 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem63%
- Mixed36%
- SaaS1%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Web & CMS Plugins.
- CVE-2026-91198GrowthBook through 5.0.1 Information Disclosure via Public Endpoints5.3
- CVE-2026-54247Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS4.3
- CVE-2026-54246Skipper routesrv-no-auth: All routesrv API Endpoints Lack Authentication5.7
- CVE-2026-65838Skipper: an oversized declared-`Content-Length` body still hands OPA an empty `parsed_body`, so deny-on-presence Rego policies fail OPEN while the full payload reaches upstream8.2
- CVE-2026-54628Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode8.6
- CVE-2026-50006Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode9.1
- CVE-2026-54629Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode7.5
- CVE-2026-47253Anyquery: Path Traversal in `clear_plugin_cache` Allows Arbitrary Directory Deletion7.3
- CVE-2026-89023ThemeAtelier Domain For Sale < 3.5.2 Missing Authorization via REST API8.6
- CVE-2026-90944Krayin CRM through 2.2.6 Unauthenticated Email Injection via inbound-parse8.2
- CVE-2026-49400October CMS: PHP Object Injection via Backend Widget Session Storage3.3
- CVE-2026-70658pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier7.4
- CVE-2026-46696October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls3.3
- CVE-2026-57579Alchemy: Unauthenticated nested page API leaks restricted & unpublished content7.5
- CVE-2026-55416Pimcore: SQL Injection in Mautic Custom Reports Bundle Due to Direct Concatenation of User-Controlled Configuration Fields Without Parameterization8.8
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Top vendors
Most CVEs in this sector, latest monthly snapshot (month in progress).
| Vendor | CVEs | Crit | KEV |
|---|---|---|---|
| wwbn | 89 | 6 | · |
| apache software foundation | 32 | 11 | · |
| sourcecodester | 31 | · | · |
| drupal | 26 | 1 | · |
| concrete cms | 21 | · | · |
| code-projects | 19 | · | · |
| craftcms | 18 | 1 | · |
| xenforo | 14 | · | · |
| getgrav | 13 | · | · |
| yeswiki | 12 | 1 | · |
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| wordpress-plugin | 180 | 13 | · | 129 | — | eventin – event calendar, tickets, registration, booking & woocommerce (5) · laradashboard (5) · media library assistant (3) |
| — | 179 | 10 | · | 21 | — | avideo (89) · concrete cms (21) · cms (18) |
| cms-core | 171 | 12 | · | 43 | — | class and exam timetabling system (12) · yeswiki (12) · syllabus-aligned learning management & examination system (7) |
| site-builder | 29 | 3 | · | 17 | — | live composer – free wordpress website builder (5) · wger (4) · builderall for wordpress (3) |
| ecommerce-platform | 27 | 3 | · | 17 | — | sylius (3) · litemall (2) · shopping cart & ecommerce store (2) |
| forum-wiki | 19 | · | · | 4 | — | xenforo (14) · bookwyrm (3) · bookstack (1) |
| wordpress-theme | 18 | 1 | · | 11 | — | divi (5) · rtmkit (3) · nokri – job board wordpress theme (2) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification