Core
This hub aggregates every CVE we track for Core, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
103
CVEs tracked
14
Critical
46
High
2
In CISA KEV
Severity distribution
HIGH46MEDIUM41CRITICAL14LOW2
Monthly trend
0
0
0
0
0
1
1
3
0
0
0
0
1
2
0
0
1
4
17
5
12
4
4
4
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Core.
- CVE-2026-66061Home Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enabling silent automation execution7.1
- CVE-2026-66060Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callers7.1
- CVE-2026-59717Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing4.3
- CVE-2026-71291Bolt CMS Server-Side Template Injection via Unsandboxed allow_twig Field Rendering8.8
- CVE-2026-53599Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers7.5
- CVE-2026-48795Incomplete fix for CVE-2026-25754 in @adonisjs/bodyparser8.6
- CVE-2026-49858API Platform Core: Cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate5.9
- CVE-2026-54164API Platform Core: Missing IRI type check enables resource type confusion6.5
- CVE-2026-55844Home Assistant: iOS Companion App ignores internal SSID allowlist for connections – possible leak of access token and sensor data7.5
- CVE-2026-54318Home Assistant: Exported BroadcastReceiver allows local apps to spoof device location7.1
- CVE-2026-54317Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN7.6
- CVE-2024-14036Dräger Core 1.0.5 Denial of Service via Malformed SDC Message7.5
- CVE-2026-44698Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injection8.3
- CVE-2026-44473Ella Core: UE Downlink Redirection via Forged PDUSessionResourceSetupResponse7.1
- CVE-2026-44475Ella Core: UE Security Capability bypass on NGAP PathSwitchRequest6.1
Product normalization is registry-driven with AI assist and human review. How it works