Cms
This hub aggregates every CVE we track for Cms, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
308
CVEs tracked
17
Critical
67
High
6
In CISA KEV
Severity distribution
MEDIUM171HIGH67LOW53CRITICAL17
Monthly trend
2
0
6
4
2
1
2
4
4
17
4
6
3
6
0
1
6
25
37
13
4
12
7
19
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Cms.
- CVE-2026-19975Azuriom CMS Money Transfer ProfileController.php transferMoney toctou3.1
- CVE-2026-72787Craft CMS 5.0.0-RC1 before 5.10.8 Stored XSS via Draft Name6.4
- CVE-2026-72786Craft CMS 5.0.0-RC1 before 5.10.8 Authentication Bypass via Password Reset6.5
- CVE-2026-72785Craft CMS before 5.10.6 Authorization Bypass via structures/move-element4.3
- CVE-2026-72784Craft CMS 5.0.0-RC1 before 5.10.6 SSRF via GraphQL asset mutation5.4
- CVE-2026-72783Craft CMS 5.0.0-RC1 before 5.10.6 Path Traversal via ensurePathIsContained6.2
- CVE-2026-72782Craft CMS 5.0.0-RC1 before 5.10.6 Environment Variable Leak6.5
- CVE-2026-72781Craft CMS 5.0.0-RC1 before 5.10.7 Remote Code Execution via Twig Sandbox Escape8.8
- CVE-2026-72780Craft CMS before 5.10.5 WebAuthn Assertion Replay via login-with-passkey6.5
- CVE-2026-72779Craft CMS 5.0.0-RC1 before 5.10.6 Arbitrary File Read via SplFileObject4.5
- CVE-2026-72778Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.config8.8
- CVE-2026-71435Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template6.1
- CVE-2026-71434Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types5.3
- CVE-2026-64662Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries6.5
- CVE-2026-64663Statamic: Unsafe method invocation via Antlers template resolution allows data destruction6.5
Product normalization is registry-driven with AI assist and human review. How it works