Products › Server applications and development
Server applications and development
CMS, e-commerce and websites
Content management systems, online stores, plug-ins and forums.
For example: WordPress, Drupal, Joomla, Magento.
-
18 vulnerabilities added in the last 12 months
-
46 exploited vulnerabilities in the catalog, in total
-
3 added in the last 30 days
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 9, 2025 to Oct 8, 2025 | 0 |
| Oct 9, 2025 to Nov 7, 2025 | 4 |
| Nov 8, 2025 to Dec 7, 2025 | 0 |
| Dec 8, 2025 to Jan 6, 2026 | 0 |
| Jan 7, 2026 to Feb 5, 2026 | 0 |
| Feb 6, 2026 to Mar 7, 2026 | 0 |
| Mar 8, 2026 to Apr 6, 2026 | 1 |
| Apr 7, 2026 to May 6, 2026 | 1 |
| May 7, 2026 to Jun 5, 2026 | 2 |
| Jun 6, 2026 to Jul 5, 2026 | 1 |
| Jul 6, 2026 to Aug 4, 2026 | 6 |
| Aug 5, 2026 to Sep 3, 2026 | 0 |
| Sep 4, 2026 to Oct 3, 2026 (in progress) | 3 |
Affected brands
In alphabetical order, with their number of vulnerabilities in this category.
- Adobe 6 vulnerabilities · 4 in the last 12 months
- Balbooa 1 vulnerability · 1 in the last 12 months
- Craft CMS 4 vulnerabilities · 1 in the last 12 months
- dotCMS 1 vulnerability
- DotNetNuke (DNN) 3 vulnerabilities
- Drupal 5 vulnerabilities · 1 in the last 12 months
- Fuel CMS 1 vulnerability
- iCagenda 1 vulnerability · 1 in the last 12 months
- Joomla! 1 vulnerability
- Joomlack 1 vulnerability · 1 in the last 12 months
- JoomShaper 1 vulnerability · 1 in the last 12 months
- Kentico 4 vulnerabilities · 3 in the last 12 months
- Liferay 1 vulnerability
- Mirasvit 1 vulnerability · 1 in the last 12 months
- October CMS 1 vulnerability
- SAP 1 vulnerability
- Sitecore 4 vulnerabilities
- vBulletin 2 vulnerabilities
- Widget Factory (JCE) 1 vulnerability · 1 in the last 12 months
- WordPress 6 vulnerabilities · 3 in the last 12 months
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
See also
- Web and application servers 67 vulnerabilities
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.
- Rank 1
WordPress CoreCVE-2026-87902
WordPress Core Remote File Inclusion Vulnerability
Recently addedHunt for compromise (CISA)
CVSS severity 8.1high
Added Sep 25, 2026
- Rank 2
Adobe Commerce (Magento)CVE-2026-71362
Adobe Commerce and Magento Incorrect Authorization Vulnerability
Recently addedHunt for compromise (CISA)
CVSS severity 9.1critical
Added Sep 24, 2026
- Rank 3
Adobe Commerce (Magento)CVE-2026-75650
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Recently addedHunt for compromise (CISA)
CVSS severity 10.0critical
Added Sep 8, 2026
- Rank 4
Craft CMSCVE-2025-32432
Craft CMS Code Injection Vulnerability
CVSS severity 10.0critical
Added Mar 20, 2026
- Rank 5
Adobe Experience Manager (AEM)CVE-2025-54253
Adobe Experience Manager Forms Code Execution Vulnerability
CVSS severity 10.0critical
Added Oct 15, 2025
- Rank 6
WordPress CoreCVE-2026-63030
WordPress Core Interpretation Conflict Vulnerability
Hunt for compromise (CISA)
CVSS severity 9.8critical
Added Jul 21, 2026
- Rank 7
iCagendaCVE-2026-48939
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
Hunt for compromise (CISA)
CVSS severity 9.8critical
Added Jul 10, 2026
- Rank 8
Balbooa FormsCVE-2026-56291
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
Hunt for compromise (CISA)
CVSS severity 9.8critical
Added Jul 10, 2026
- Rank 9
JoomShaper SP Page BuilderCVE-2026-48908
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
Hunt for compromise (CISA)
CVSS severity 9.8critical
Added Jul 7, 2026
- Rank 10
Joomlack Page BuilderCVE-2026-56290
Joomlack Page Builder Improper Access Control Vulnerability
Hunt for compromise (CISA)
CVSS severity 9.8critical
Added Jul 7, 2026
Show 36 more vulnerabilities
- Rank 11
Widget Factory (JCE) JCE (Joomla Content Editor)CVE-2026-48907
Widget Factory Joomla Content Editor Improper Access Control Vulnerability
CVSS severity 9.8critical
Added Jun 16, 2026
- Rank 12
Mirasvit Full Page Cache WarmerCVE-2026-45247
Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
CVSS severity 9.8critical
Added Jun 3, 2026
- Rank 13
Drupal CoreCVE-2026-9082
Drupal Core SQL Injection Vulnerability
CVSS severity 9.8critical
Added May 22, 2026
- Rank 14
Kentico XperienceCVE-2025-2746
Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVSS severity 9.8critical
Added Oct 20, 2025
- Rank 15
Kentico XperienceCVE-2025-2747
Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVSS severity 9.8critical
Added Oct 20, 2025
- Rank 16
Adobe Commerce (Magento)CVE-2025-54236
Adobe Commerce and Magento Improper Input Validation Vulnerability
CVSS severity 9.1critical
Added Oct 24, 2025
- Rank 17
Kentico XperienceCVE-2025-2749
Kentico Xperience Path Traversal Vulnerability
CVSS severity 7.2high
Added Apr 20, 2026
- Rank 18
WordPress CoreCVE-2026-60137
WordPress Core SQL Injection Vulnerability
CVSS severity 5.9medium
Added Jul 21, 2026
- Rank 19
Craft CMSCVE-2024-56145
Craft CMS Code Injection Vulnerability
CVSS severity 9.8critical
Added Jun 2, 2025
- Rank 20
Sitecore Experience Platform / Manager (XP / XM)CVE-2019-9874
Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
CVE from 2019, added in 2025
CVSS severity 9.8critical
Added Mar 26, 2025
- Rank 21
SAP Commerce Cloud (Hybris)CVE-2019-0344
SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability
CVE from 2019, added in 2024
CVSS severity 9.8critical
Added Sep 30, 2024
- Rank 22
Adobe Commerce (Magento)CVE-2024-34102
Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
CVSS severity 9.8critical
Added Jul 17, 2024
- Rank 23
dotCMSCVE-2022-26352
dotCMS Unrestricted Upload of File Vulnerability
Ransomware
CVSS severity 9.8critical
Added Aug 25, 2022
- Rank 24
Drupal CoreCVE-2018-7602
Drupal Core Remote Code Execution Vulnerability
RansomwareCVE from 2018, added in 2022
CVSS severity 9.8critical
Added Apr 13, 2022
- Rank 25
Kentico XperienceCVE-2019-10068
Kentico Xperience Deserialization of Untrusted Data Vulnerability
CVE from 2019, added in 2022
CVSS severity 9.8critical
Added Mar 25, 2022
- Rank 26
Sitecore Experience Platform / Manager (XP / XM)CVE-2021-42237
Sitecore XP Remote Command Execution Vulnerability
Ransomware
CVSS severity 9.8critical
Added Mar 25, 2022
- Rank 27
Adobe Commerce (Magento)CVE-2022-24086
Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability
CVSS severity 9.8critical
Added Feb 15, 2022
- Rank 28
Fuel CMSCVE-2020-17463
Fuel CMS SQL Injection Vulnerability
CVSS severity 9.8critical
Added Dec 10, 2021
- Rank 29
Drupal CoreCVE-2018-7600
Drupal Core Remote Code Execution Vulnerability
RansomwareCVE from 2018, added in 2021
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 30
vBulletinCVE-2019-16759
vBulletin PHP Module Remote Code Execution Vulnerability
CVE from 2019, added in 2021
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 31
vBulletinCVE-2020-17496
vBulletin PHP Module Remote Code Execution Vulnerability
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 32
WordPress PluginsCVE-2020-25213
WordPress File Manager Plugin Remote Code Execution Vulnerability
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 33
Liferay Portal / DXPCVE-2020-7961
Liferay Portal Deserialization of Untrusted Data Vulnerability
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 34
October CMSCVE-2021-32648
October CMS Improper Authentication
CVSS severity 9.1critical
Added Jan 18, 2022
- Rank 35
Sitecore Experience Platform / Manager (XP / XM)CVE-2025-53690
Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability
CVSS severity 9.0critical
Added Sep 4, 2025
- Rank 36
Sitecore Experience Platform / Manager (XP / XM)CVE-2019-9875
Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
CVE from 2019, added in 2025
CVSS severity 8.8high
Added Mar 26, 2025
- Rank 37
Drupal CoreCVE-2020-13671
Drupal core Un-restricted Upload of File
CVE from 2020, added in 2022
CVSS severity 8.8high
Added Jan 18, 2022
- Rank 38
DotNetNuke (DNN)CVE-2017-9822
DotNetNuke (DNN) Remote Code Execution Vulnerability
RansomwareCVE from 2017, added in 2021
CVSS severity 8.8high
Added Nov 3, 2021
- Rank 39
Craft CMSCVE-2025-23209
Craft CMS Code Injection Vulnerability
CVSS severity 8.1high
Added Feb 20, 2025
- Rank 40
Drupal CoreCVE-2019-6340
Drupal Core Remote Code Execution Vulnerability
CVE from 2019, added in 2022
CVSS severity 8.1high
Added Mar 25, 2022
- Rank 41
DotNetNuke (DNN)CVE-2018-15811
DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability
CVE from 2018, added in 2021
CVSS severity 7.5high
Added Nov 3, 2021
- Rank 42
DotNetNuke (DNN)CVE-2018-18325
DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability
CVE from 2018, added in 2021
CVSS severity 7.5high
Added Nov 3, 2021
- Rank 43
WordPress PluginsCVE-2020-11738
WordPress Snap Creek Duplicator Plugin File Download Vulnerability
CVSS severity 7.5high
Added Nov 3, 2021
- Rank 44
WordPress PluginsCVE-2019-9978
WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability
CVE from 2019, added in 2021
CVSS severity 6.1medium
Added Nov 3, 2021
- Rank 45
Craft CMSCVE-2025-35939
Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability
CVSS severity 5.3medium
Added Jun 2, 2025
- Rank 46
Joomla!CVE-2023-23752
Joomla! Improper Access Control Vulnerability
CVSS severity 5.3medium
Added Jan 8, 2024
Filed under another category
This vulnerability also concerns this type of product, but is counted in its main category. My radar finds it when you follow this category.
Progress Telerik UI for ASP.NET AJAXCVE-2017-9248
Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability
CVE from 2017, added in 2021
CVSS severity 9.8critical
Added Nov 3, 2021
Follow and verify
Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.