Cms
This hub aggregates every CVE we track for Cms, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
297
CVEs tracked
17
Critical
65
High
6
In CISA KEV
Severity distribution
MEDIUM163HIGH65LOW52CRITICAL17
Monthly trend
2
0
6
4
2
1
2
4
4
17
4
6
3
6
0
1
6
25
37
13
4
12
7
8
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Cms.
- CVE-2026-71435Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template6.1
- CVE-2026-71434Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types5.3
- CVE-2026-64662Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries6.5
- CVE-2026-64663Statamic: Unsafe method invocation via Antlers template resolution allows data destruction6.5
- CVE-2026-64665Statamic: Account takeover via OAuth email matching without email-verification check8.1
- CVE-2026-64664Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence4.3
- CVE-2026-5134SQLi in Loca Software's CMS9.8
- CVE-2026-71293Statamic CMS Unguarded Exposure of 2FA Recovery Codes via Antlers current_user Variable6.2
- CVE-2026-16219Croogo CMS Admin File Manager FileManager.php isEditable path traversal6.3
- CVE-2026-16205Pluck CMS Albums albums.admin.php htmlspecialchars_decode cross site scripting2.4
- CVE-2026-54243Statamic: CSV formula injection in form submission exports6.1
- CVE-2026-54242Statamic: Server-Side Request Forgery via Glide (DNS rebinding)4.9
- CVE-2026-54244Statamic: Incorrect authorization lets view-only users submit Live Preview content reserved for editors3.5
- CVE-2026-14794Craft CMS Charts Endpoint ChartsController.php actionGetNewUsersData improper authorization4.3
- CVE-2026-14793Craft CMS reorder-sets Endpoint GlobalsController.php actionReorderSets authorization4.3
Product normalization is registry-driven with AI assist and human review. How it works