Core
This hub aggregates every CVE we track for Core, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
119
CVEs tracked
16
Critical
47
High
2
In CISA KEV
Severity distribution
MEDIUM49HIGH47CRITICAL16LOW2
Monthly trend
0
0
0
0
1
1
3
0
0
0
0
1
3
0
0
1
4
17
5
14
4
4
9
8
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Core.
- CVE-2026-63000REDAXO: Missing CSRF Protection on Package Update Action Allows Forced Addon Updates6.4
- CVE-2026-62998REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration4.3
- CVE-2026-63002REDAXO: Stored XSS in Mediapool Sync Page via Unescaped Filesystem Filenames4.8
- CVE-2026-63001REDAXO: Stored XSS via Unescaped Media Manager Type Name in `mediaIsInUse()`4.8
- CVE-2026-91129Home Assistant: mDNS Server-Side Request Forgery5.4
- CVE-2026-91130Home Assistant: XSS in Statistics Graph Card
- CVE-2026-53581ntp: write path traversal9.0
- CVE-2026-85093Cheshire Cat AI Memory Collection Endpoint Information Disclosure6.5
- CVE-2026-57499Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE)9.1
- CVE-2026-73420NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
- CVE-2026-73419NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them6.8
- CVE-2026-73418NextAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers7.5
- CVE-2026-66061Home Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enabling silent automation execution7.1
- CVE-2026-66060Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callers7.1
- CVE-2026-59717Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing4.3
Product normalization is registry-driven with AI assist and human review. How it works