Skip to content

Products › Server applications and development

Server applications and development

CMS, e-commerce and websites

Content management systems, online stores, plug-ins and forums.

For example: WordPress, Drupal, Joomla, Magento.

Category RSS feed

Pace of additions

Number of “CMS and websites” vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on October 3, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 9, 2025 to Oct 8, 20250
Oct 9, 2025 to Nov 7, 20254
Nov 8, 2025 to Dec 7, 20250
Dec 8, 2025 to Jan 6, 20260
Jan 7, 2026 to Feb 5, 20260
Feb 6, 2026 to Mar 7, 20260
Mar 8, 2026 to Apr 6, 20261
Apr 7, 2026 to May 6, 20261
May 7, 2026 to Jun 5, 20262
Jun 6, 2026 to Jul 5, 20261
Jul 6, 2026 to Aug 4, 20266
Aug 5, 2026 to Sep 3, 20260
Sep 4, 2026 to Oct 3, 2026 (in progress)3

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1

    WordPress CoreCVE-2026-87902

    WordPress Core Remote File Inclusion Vulnerability

    Recently addedHunt for compromise (CISA)

    CVSS severity 8.1high

    Added Sep 25, 2026

  2. Rank 2

    Adobe Commerce (Magento)CVE-2026-71362

    Adobe Commerce and Magento Incorrect Authorization Vulnerability

    Recently addedHunt for compromise (CISA)

    CVSS severity 9.1critical

    Added Sep 24, 2026

  3. Rank 3

    Adobe Commerce (Magento)CVE-2026-75650

    Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

    Recently addedHunt for compromise (CISA)

    CVSS severity 10.0critical

    Added Sep 8, 2026

  4. Rank 4

    Craft CMSCVE-2025-32432

    Craft CMS Code Injection Vulnerability

    CVSS severity 10.0critical

    Added Mar 20, 2026

  5. Rank 5

    Adobe Experience Manager (AEM)CVE-2025-54253

    Adobe Experience Manager Forms Code Execution Vulnerability

    CVSS severity 10.0critical

    Added Oct 15, 2025

  6. Rank 6

    WordPress CoreCVE-2026-63030

    WordPress Core Interpretation Conflict Vulnerability

    Hunt for compromise (CISA)

    CVSS severity 9.8critical

    Added Jul 21, 2026

  7. Rank 7

    iCagendaCVE-2026-48939

    iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

    Hunt for compromise (CISA)

    CVSS severity 9.8critical

    Added Jul 10, 2026

  8. Rank 8

    Balbooa FormsCVE-2026-56291

    Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability

    Hunt for compromise (CISA)

    CVSS severity 9.8critical

    Added Jul 10, 2026

  9. Rank 9

    JoomShaper SP Page BuilderCVE-2026-48908

    JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

    Hunt for compromise (CISA)

    CVSS severity 9.8critical

    Added Jul 7, 2026

  10. Rank 10

    Joomlack Page BuilderCVE-2026-56290

    Joomlack Page Builder Improper Access Control Vulnerability

    Hunt for compromise (CISA)

    CVSS severity 9.8critical

    Added Jul 7, 2026

Show 36 more vulnerabilities
  1. Rank 11

    Widget Factory (JCE) JCE (Joomla Content Editor)CVE-2026-48907

    Widget Factory Joomla Content Editor Improper Access Control Vulnerability

    CVSS severity 9.8critical

    Added Jun 16, 2026

  2. Rank 12

    Mirasvit Full Page Cache WarmerCVE-2026-45247

    Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability

    CVSS severity 9.8critical

    Added Jun 3, 2026

  3. Rank 13

    Drupal CoreCVE-2026-9082

    Drupal Core SQL Injection Vulnerability

    CVSS severity 9.8critical

    Added May 22, 2026

  4. Rank 14

    Kentico XperienceCVE-2025-2746

    Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability

    CVSS severity 9.8critical

    Added Oct 20, 2025

  5. Rank 15

    Kentico XperienceCVE-2025-2747

    Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability

    CVSS severity 9.8critical

    Added Oct 20, 2025

  6. Rank 16

    Adobe Commerce (Magento)CVE-2025-54236

    Adobe Commerce and Magento Improper Input Validation Vulnerability

    CVSS severity 9.1critical

    Added Oct 24, 2025

  7. Rank 17

    Kentico XperienceCVE-2025-2749

    Kentico Xperience Path Traversal Vulnerability

    CVSS severity 7.2high

    Added Apr 20, 2026

  8. Rank 18

    WordPress CoreCVE-2026-60137

    WordPress Core SQL Injection Vulnerability

    CVSS severity 5.9medium

    Added Jul 21, 2026

  9. Rank 19

    Craft CMSCVE-2024-56145

    Craft CMS Code Injection Vulnerability

    CVSS severity 9.8critical

    Added Jun 2, 2025

  10. Rank 20

    Sitecore Experience Platform / Manager (XP / XM)CVE-2019-9874

    Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

    CVE from 2019, added in 2025

    CVSS severity 9.8critical

    Added Mar 26, 2025

  11. Rank 21

    SAP Commerce Cloud (Hybris)CVE-2019-0344

    SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability

    CVE from 2019, added in 2024

    CVSS severity 9.8critical

    Added Sep 30, 2024

  12. Rank 22

    Adobe Commerce (Magento)CVE-2024-34102

    Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability

    CVSS severity 9.8critical

    Added Jul 17, 2024

  13. Rank 23

    dotCMSCVE-2022-26352

    dotCMS Unrestricted Upload of File Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Aug 25, 2022

  14. Rank 24

    Drupal CoreCVE-2018-7602

    Drupal Core Remote Code Execution Vulnerability

    RansomwareCVE from 2018, added in 2022

    CVSS severity 9.8critical

    Added Apr 13, 2022

  15. Rank 25

    Kentico XperienceCVE-2019-10068

    Kentico Xperience Deserialization of Untrusted Data Vulnerability

    CVE from 2019, added in 2022

    CVSS severity 9.8critical

    Added Mar 25, 2022

  16. Rank 26

    Sitecore Experience Platform / Manager (XP / XM)CVE-2021-42237

    Sitecore XP Remote Command Execution Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Mar 25, 2022

  17. Rank 27

    Adobe Commerce (Magento)CVE-2022-24086

    Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability

    CVSS severity 9.8critical

    Added Feb 15, 2022

  18. Rank 28

    Fuel CMSCVE-2020-17463

    Fuel CMS SQL Injection Vulnerability

    CVSS severity 9.8critical

    Added Dec 10, 2021

  19. Rank 29

    Drupal CoreCVE-2018-7600

    Drupal Core Remote Code Execution Vulnerability

    RansomwareCVE from 2018, added in 2021

    CVSS severity 9.8critical

    Added Nov 3, 2021

  20. Rank 30

    vBulletinCVE-2019-16759

    vBulletin PHP Module Remote Code Execution Vulnerability

    CVE from 2019, added in 2021

    CVSS severity 9.8critical

    Added Nov 3, 2021

  21. Rank 31

    vBulletinCVE-2020-17496

    vBulletin PHP Module Remote Code Execution Vulnerability

    CVSS severity 9.8critical

    Added Nov 3, 2021

  22. Rank 32

    WordPress PluginsCVE-2020-25213

    WordPress File Manager Plugin Remote Code Execution Vulnerability

    CVSS severity 9.8critical

    Added Nov 3, 2021

  23. Rank 33

    Liferay Portal / DXPCVE-2020-7961

    Liferay Portal Deserialization of Untrusted Data Vulnerability

    CVSS severity 9.8critical

    Added Nov 3, 2021

  24. Rank 34

    October CMSCVE-2021-32648

    October CMS Improper Authentication

    CVSS severity 9.1critical

    Added Jan 18, 2022

  25. Rank 35

    Sitecore Experience Platform / Manager (XP / XM)CVE-2025-53690

    Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability

    CVSS severity 9.0critical

    Added Sep 4, 2025

  26. Rank 36

    Sitecore Experience Platform / Manager (XP / XM)CVE-2019-9875

    Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

    CVE from 2019, added in 2025

    CVSS severity 8.8high

    Added Mar 26, 2025

  27. Rank 37

    Drupal CoreCVE-2020-13671

    Drupal core Un-restricted Upload of File

    CVE from 2020, added in 2022

    CVSS severity 8.8high

    Added Jan 18, 2022

  28. Rank 38

    DotNetNuke (DNN)CVE-2017-9822

    DotNetNuke (DNN) Remote Code Execution Vulnerability

    RansomwareCVE from 2017, added in 2021

    CVSS severity 8.8high

    Added Nov 3, 2021

  29. Rank 39

    Craft CMSCVE-2025-23209

    Craft CMS Code Injection Vulnerability

    CVSS severity 8.1high

    Added Feb 20, 2025

  30. Rank 40

    Drupal CoreCVE-2019-6340

    Drupal Core Remote Code Execution Vulnerability

    CVE from 2019, added in 2022

    CVSS severity 8.1high

    Added Mar 25, 2022

  31. Rank 41

    DotNetNuke (DNN)CVE-2018-15811

    DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

    CVE from 2018, added in 2021

    CVSS severity 7.5high

    Added Nov 3, 2021

  32. Rank 42

    DotNetNuke (DNN)CVE-2018-18325

    DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

    CVE from 2018, added in 2021

    CVSS severity 7.5high

    Added Nov 3, 2021

  33. Rank 43

    WordPress PluginsCVE-2020-11738

    WordPress Snap Creek Duplicator Plugin File Download Vulnerability

    CVSS severity 7.5high

    Added Nov 3, 2021

  34. Rank 44

    WordPress PluginsCVE-2019-9978

    WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability

    CVE from 2019, added in 2021

    CVSS severity 6.1medium

    Added Nov 3, 2021

  35. Rank 45

    Craft CMSCVE-2025-35939

    Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability

    CVSS severity 5.3medium

    Added Jun 2, 2025

  36. Rank 46

    Joomla!CVE-2023-23752

    Joomla! Improper Access Control Vulnerability

    CVSS severity 5.3medium

    Added Jan 8, 2024

Filed under another category

This vulnerability also concerns this type of product, but is counted in its main category. My radar finds it when you follow this category.

  1. Progress Telerik UI for ASP.NET AJAXCVE-2017-9248

    Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability

    CVE from 2017, added in 2021

    CVSS severity 9.8critical

    Added Nov 3, 2021

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.