Cms
This hub aggregates every CVE we track for Cms, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
361
CVEs tracked
18
Critical
84
High
6
In CISA KEV
Severity distribution
MEDIUM185HIGH84LOW53CRITICAL18
Monthly trend
0
6
4
2
1
2
4
4
17
4
6
3
6
0
1
6
25
37
16
5
12
19
21
35
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Cms.
- CVE-2026-92594Craft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQL7.5
- CVE-2026-92593Craft CMS 5.10.0 before 5.10.13 Authenticated Remote Code Execution8.8
- CVE-2026-92592Craft CMS before 4.18.6 Remote Code Execution via signed cookie8.8
- CVE-2026-92591Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer5.9
- CVE-2026-92590Craft CMS 5.7.0 before 5.10.13 Stored XSS via Generated Fields5.4
- CVE-2026-92589Craft CMS 5.0.0 before 5.10.13 Broken Access Control via nested-elements/reorder4.3
- CVE-2026-90709Yot CMS Admin Console admin.php eval code injection4.7
- CVE-2026-90708Yot CMS Cookie global.php login sql injection7.3
- CVE-2026-79987Low-privilege RCE through element-search eager loading8.8
- CVE-2026-86732Craft CMS before 5.10.12 Remote Code Execution via element-index8.8
- CVE-2026-86731Craft CMS 5.0.0-RC1 before 5.10.12 Permission Escalation via UsersController6.5
- CVE-2026-86730Craft CMS 5.0.0-RC1 before 5.10.12 Behavior Injection RCE8.8
- CVE-2026-86308light0011 cms Debug Mode config.php information disclosure5.3
- CVE-2026-86307light0011 cms cross-site request forgery4.3
- CVE-2026-86306light0011 cms Cookie Helper UserModel.class.php improper authentication7.3
Product normalization is registry-driven with AI assist and human review. How it works