Cms
This hub aggregates every CVE we track for Cms, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
328
CVEs tracked
18
Critical
77
High
6
In CISA KEV
Severity distribution
MEDIUM180HIGH77LOW53CRITICAL18
Monthly trend
0
6
4
2
1
2
4
4
17
4
6
3
6
0
1
6
25
37
13
4
12
7
19
20
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Cms.
- CVE-2026-86308light0011 cms Debug Mode config.php information disclosure5.3
- CVE-2026-86307light0011 cms cross-site request forgery4.3
- CVE-2026-86306light0011 cms Cookie Helper UserModel.class.php improper authentication7.3
- CVE-2026-86305light0011 cms Upload.class.php upload unrestricted upload7.3
- CVE-2026-85382light0011 cms Chapter Content Output oneChapter.tpl htmlspecialchars_decode cross site scripting4.3
- CVE-2026-85381light0011 cms Chapter Controller ChapterController.class.php authorization5.3
- CVE-2026-85380light0011 cms UEditor controller.php catchimage server-side request forgery7.3
- CVE-2026-85379light0011 cms Query Builder ChapterController.class.php searchChapter sql injection7.3
- CVE-2026-85378light0011 cms Chapter Controller ChapterController.class.php _initialize authorization7.3
- CVE-2026-84802Craft CMS 5.7.0 before 5.10.12 Information Disclosure via AssetsController4.3
- CVE-2026-84801Craft CMS 5.0.0-RC1 before 5.10.11 Authentication Bypass via administrateUsers8.8
- CVE-2026-84800Craft CMS 5.0.0-RC1 before 5.10.11 File Overwrite via assets/replace-file7.1
- CVE-2026-84799Craft CMS before 5.11.0 PII Disclosure via GraphQL User Relations4.3
- CVE-2026-84798Craft CMS before 5.10.11 Authorization Bypass via actionDeleteForSite7.1
- CVE-2026-84797Craft CMS 5.0.0-RC1 before 5.10.11 Authorization Bypass via actionDuplicate6.3
Product normalization is registry-driven with AI assist and human review. How it works