Products › Server applications and development
Server applications and development
CMS, e-commerce and websites
Content management systems, online stores, plug-ins and forums.
For example: WordPress, Drupal, Joomla, Magento.
-
18 vulnerabilities added in the last 12 months
-
46 exploited vulnerabilities in the catalog, in total
-
3 added in the last 30 days
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 4, 2025 to Oct 3, 2025 | 1 |
| Oct 4, 2025 to Nov 2, 2025 | 4 |
| Nov 3, 2025 to Dec 2, 2025 | 0 |
| Dec 3, 2025 to Jan 1, 2026 | 0 |
| Jan 2, 2026 to Jan 31, 2026 | 0 |
| Feb 1, 2026 to Mar 2, 2026 | 0 |
| Mar 3, 2026 to Apr 1, 2026 | 1 |
| Apr 2, 2026 to May 1, 2026 | 1 |
| May 2, 2026 to May 31, 2026 | 1 |
| Jun 1, 2026 to Jun 30, 2026 | 2 |
| Jul 1, 2026 to Jul 30, 2026 | 6 |
| Jul 31, 2026 to Aug 29, 2026 | 0 |
| Aug 30, 2026 to Sep 28, 2026 (in progress) | 3 |
Affected brands
In alphabetical order, with their number of vulnerabilities in this category.
- Adobe 6 vulnerabilities · 4 in the last 12 months
- Balbooa 1 vulnerability · 1 in the last 12 months
- Craft CMS 4 vulnerabilities · 1 in the last 12 months
- dotCMS 1 vulnerability
- DotNetNuke (DNN) 3 vulnerabilities
- Drupal 5 vulnerabilities · 1 in the last 12 months
- Fuel CMS 1 vulnerability
- iCagenda 1 vulnerability · 1 in the last 12 months
- Joomla! 1 vulnerability
- Joomlack 1 vulnerability · 1 in the last 12 months
- JoomShaper 1 vulnerability · 1 in the last 12 months
- Kentico 4 vulnerabilities · 3 in the last 12 months
- Liferay 1 vulnerability
- Mirasvit 1 vulnerability · 1 in the last 12 months
- October CMS 1 vulnerability
- SAP 1 vulnerability
- Sitecore 4 vulnerabilities
- vBulletin 2 vulnerabilities
- Widget Factory (JCE) 1 vulnerability · 1 in the last 12 months
- WordPress 6 vulnerabilities · 3 in the last 12 months
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
See also
- Web and application servers 67 vulnerabilities
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.
Rank 1WordPress Core
CVE-2026-87902Recently addedHunt for compromise (CISA)
WordPress Core Remote File Inclusion Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 25, 2026
- CISA deadline
- 3 days
- CVSS severity
- 8.1 (high)
Rank 2Adobe Commerce (Magento)
CVE-2026-71362Recently addedHunt for compromise (CISA)
Adobe Commerce and Magento Incorrect Authorization Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 24, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.1 (critical)
Rank 3Adobe Commerce (Magento)
CVE-2026-75650Recently addedHunt for compromise (CISA)
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 8, 2026
- CISA deadline
- 3 days
- CVSS severity
- 10.0 (critical)
Rank 4Craft CMS
CVE-2025-32432Craft CMS Code Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Mar 20, 2026
- CISA deadline
- 14 days
- CVSS severity
- 10.0 (critical)
Rank 5Adobe Experience Manager (AEM)
CVE-2025-54253Adobe Experience Manager Forms Code Execution Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Oct 15, 2025
- CISA deadline
- 21 days
- CVSS severity
- 10.0 (critical)
Rank 6WordPress Core
CVE-2026-63030Hunt for compromise (CISA)
WordPress Core Interpretation Conflict Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jul 21, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 7iCagenda
CVE-2026-48939Hunt for compromise (CISA)
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jul 10, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 8Balbooa Forms
CVE-2026-56291Hunt for compromise (CISA)
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jul 10, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 9JoomShaper SP Page Builder
CVE-2026-48908Hunt for compromise (CISA)
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jul 7, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 10Joomlack Page Builder
CVE-2026-56290Hunt for compromise (CISA)
Joomlack Page Builder Improper Access Control Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jul 7, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Show 36 more vulnerabilities
Rank 11Widget Factory (JCE) JCE (Joomla Content Editor)
CVE-2026-48907Widget Factory Joomla Content Editor Improper Access Control Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jun 16, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 12Mirasvit Full Page Cache Warmer
CVE-2026-45247Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jun 3, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 13Drupal Core
CVE-2026-9082Drupal Core SQL Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- May 22, 2026
- CISA deadline
- 5 days
- CVSS severity
- 9.8 (critical)
Rank 14Kentico Xperience
CVE-2025-2746Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Oct 20, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 15Kentico Xperience
CVE-2025-2747Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Oct 20, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 16Adobe Commerce (Magento)
CVE-2025-54236Adobe Commerce and Magento Improper Input Validation Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Oct 24, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.1 (critical)
Rank 17Kentico Xperience
CVE-2025-2749Kentico Xperience Path Traversal Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Apr 20, 2026
- CISA deadline
- 14 days
- CVSS severity
- 7.2 (high)
Rank 18WordPress Core
CVE-2026-60137WordPress Core SQL Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jul 21, 2026
- CISA deadline
- 14 days
- CVSS severity
- 5.9 (medium)
Rank 19Craft CMS
CVE-2024-56145Craft CMS Code Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 2, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 20Sitecore Experience Platform / Manager (XP / XM)
CVE-2019-9874CVE from 2019, added in 2025
Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 26, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 21SAP Commerce Cloud (Hybris)
CVE-2019-0344CVE from 2019, added in 2024
SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 30, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 22Adobe Commerce (Magento)
CVE-2024-34102Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 17, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 23dotCMS
CVE-2022-26352Ransomware
dotCMS Unrestricted Upload of File Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 24Drupal Core
CVE-2018-7602RansomwareCVE from 2018, added in 2022
Drupal Core Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 13, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 25Kentico Xperience
CVE-2019-10068CVE from 2019, added in 2022
Kentico Xperience Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 26Sitecore Experience Platform / Manager (XP / XM)
CVE-2021-42237Ransomware
Sitecore XP Remote Command Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 27Adobe Commerce (Magento)
CVE-2022-24086Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 15, 2022
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 28Fuel CMS
CVE-2020-17463Fuel CMS SQL Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 10, 2021
- CISA deadline
- 182 days
- CVSS severity
- 9.8 (critical)
Rank 29Drupal Core
CVE-2018-7600RansomwareCVE from 2018, added in 2021
Drupal Core Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 30vBulletin
CVE-2019-16759CVE from 2019, added in 2021
vBulletin PHP Module Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 31vBulletin
CVE-2020-17496vBulletin PHP Module Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 32WordPress Plugins
CVE-2020-25213WordPress File Manager Plugin Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 33Liferay Portal / DXP
CVE-2020-7961Liferay Portal Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 34October CMS
CVE-2021-32648October CMS Improper Authentication
Added more than a year ago: ranked by severity.
- Added
- Jan 18, 2022
- CISA deadline
- 14 days
- CVSS severity
- 9.1 (critical)
Rank 35Sitecore Experience Platform / Manager (XP / XM)
CVE-2025-53690Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 4, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.0 (critical)
Rank 36Sitecore Experience Platform / Manager (XP / XM)
CVE-2019-9875CVE from 2019, added in 2025
Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 26, 2025
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 37Drupal Core
CVE-2020-13671CVE from 2020, added in 2022
Drupal core Un-restricted Upload of File
Added more than a year ago: ranked by severity.
- Added
- Jan 18, 2022
- CISA deadline
- 181 days
- CVSS severity
- 8.8 (high)
Rank 38DotNetNuke (DNN)
CVE-2017-9822RansomwareCVE from 2017, added in 2021
DotNetNuke (DNN) Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 8.8 (high)
Rank 39Craft CMS
CVE-2025-23209Craft CMS Code Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 20, 2025
- CISA deadline
- 21 days
- CVSS severity
- 8.1 (high)
Rank 40Drupal Core
CVE-2019-6340CVE from 2019, added in 2022
Drupal Core Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.1 (high)
Rank 41DotNetNuke (DNN)
CVE-2018-15811CVE from 2018, added in 2021
DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.5 (high)
Rank 42DotNetNuke (DNN)
CVE-2018-18325CVE from 2018, added in 2021
DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.5 (high)
Rank 43WordPress Plugins
CVE-2020-11738WordPress Snap Creek Duplicator Plugin File Download Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.5 (high)
Rank 44WordPress Plugins
CVE-2019-9978CVE from 2019, added in 2021
WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 6.1 (medium)
Rank 45Craft CMS
CVE-2025-35939Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 2, 2025
- CISA deadline
- 21 days
- CVSS severity
- 5.3 (medium)
Rank 46Joomla!
CVE-2023-23752Joomla! Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 8, 2024
- CISA deadline
- 21 days
- CVSS severity
- 5.3 (medium)
Filed under another category
This vulnerability also concerns this type of product, but is counted in its main category. My radar finds it when you follow this category.
Progress Telerik UI for ASP.NET AJAX
CVE-2017-9248CVE from 2017, added in 2021
Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Follow and verify
Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.