Skip to content
English

Products › Server applications and development

Server applications and development

CMS, e-commerce and websites

Content management systems, online stores, plug-ins and forums.

For example: WordPress, Drupal, Joomla, Magento.

Category RSS feed

Pace of additions

Number of “CMS and websites” vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on September 28, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 4, 2025 to Oct 3, 20251
Oct 4, 2025 to Nov 2, 20254
Nov 3, 2025 to Dec 2, 20250
Dec 3, 2025 to Jan 1, 20260
Jan 2, 2026 to Jan 31, 20260
Feb 1, 2026 to Mar 2, 20260
Mar 3, 2026 to Apr 1, 20261
Apr 2, 2026 to May 1, 20261
May 2, 2026 to May 31, 20261
Jun 1, 2026 to Jun 30, 20262
Jul 1, 2026 to Jul 30, 20266
Jul 31, 2026 to Aug 29, 20260
Aug 30, 2026 to Sep 28, 2026 (in progress)3

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1WordPress Core

    CVE-2026-87902

    Recently addedHunt for compromise (CISA)

    WordPress Core Remote File Inclusion Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 25, 2026
    CISA deadline
    3 days
    CVSS severity
    8.1 (high)
  2. Rank 2Adobe Commerce (Magento)

    CVE-2026-71362

    Recently addedHunt for compromise (CISA)

    Adobe Commerce and Magento Incorrect Authorization Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 24, 2026
    CISA deadline
    3 days
    CVSS severity
    9.1 (critical)
  3. Rank 3Adobe Commerce (Magento)

    CVE-2026-75650

    Recently addedHunt for compromise (CISA)

    Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 8, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  4. Rank 4Craft CMS

    CVE-2025-32432

    Craft CMS Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 20, 2026
    CISA deadline
    14 days
    CVSS severity
    10.0 (critical)
  5. Rank 5Adobe Experience Manager (AEM)

    CVE-2025-54253

    Adobe Experience Manager Forms Code Execution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 15, 2025
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  6. Rank 6WordPress Core

    CVE-2026-63030

    Hunt for compromise (CISA)

    WordPress Core Interpretation Conflict Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 21, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  7. Rank 7iCagenda

    CVE-2026-48939

    Hunt for compromise (CISA)

    iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 10, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  8. Rank 8Balbooa Forms

    CVE-2026-56291

    Hunt for compromise (CISA)

    Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 10, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  9. Rank 9JoomShaper SP Page Builder

    CVE-2026-48908

    Hunt for compromise (CISA)

    JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 7, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  10. Rank 10Joomlack Page Builder

    CVE-2026-56290

    Hunt for compromise (CISA)

    Joomlack Page Builder Improper Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 7, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
Show 36 more vulnerabilities
  1. Rank 11Widget Factory (JCE) JCE (Joomla Content Editor)

    CVE-2026-48907

    Widget Factory Joomla Content Editor Improper Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 16, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  2. Rank 12Mirasvit Full Page Cache Warmer

    CVE-2026-45247

    Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 3, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  3. Rank 13Drupal Core

    CVE-2026-9082

    Drupal Core SQL Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 22, 2026
    CISA deadline
    5 days
    CVSS severity
    9.8 (critical)
  4. Rank 14Kentico Xperience

    CVE-2025-2746

    Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 20, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  5. Rank 15Kentico Xperience

    CVE-2025-2747

    Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 20, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  6. Rank 16Adobe Commerce (Magento)

    CVE-2025-54236

    Adobe Commerce and Magento Improper Input Validation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 24, 2025
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  7. Rank 17Kentico Xperience

    CVE-2025-2749

    Kentico Xperience Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 20, 2026
    CISA deadline
    14 days
    CVSS severity
    7.2 (high)
  8. Rank 18WordPress Core

    CVE-2026-60137

    WordPress Core SQL Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 21, 2026
    CISA deadline
    14 days
    CVSS severity
    5.9 (medium)
  9. Rank 19Craft CMS

    CVE-2024-56145

    Craft CMS Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 2, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. Rank 20Sitecore Experience Platform / Manager (XP / XM)

    CVE-2019-9874

    CVE from 2019, added in 2025

    Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 26, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  11. Rank 21SAP Commerce Cloud (Hybris)

    CVE-2019-0344

    CVE from 2019, added in 2024

    SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 30, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  12. Rank 22Adobe Commerce (Magento)

    CVE-2024-34102

    Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 17, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  13. Rank 23dotCMS

    CVE-2022-26352

    Ransomware

    dotCMS Unrestricted Upload of File Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  14. Rank 24Drupal Core

    CVE-2018-7602

    RansomwareCVE from 2018, added in 2022

    Drupal Core Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  15. Rank 25Kentico Xperience

    CVE-2019-10068

    CVE from 2019, added in 2022

    Kentico Xperience Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  16. Rank 26Sitecore Experience Platform / Manager (XP / XM)

    CVE-2021-42237

    Ransomware

    Sitecore XP Remote Command Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  17. Rank 27Adobe Commerce (Magento)

    CVE-2022-24086

    Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  18. Rank 28Fuel CMS

    CVE-2020-17463

    Fuel CMS SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    182 days
    CVSS severity
    9.8 (critical)
  19. Rank 29Drupal Core

    CVE-2018-7600

    RansomwareCVE from 2018, added in 2021

    Drupal Core Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  20. Rank 30vBulletin

    CVE-2019-16759

    CVE from 2019, added in 2021

    vBulletin PHP Module Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  21. Rank 31vBulletin

    CVE-2020-17496

    vBulletin PHP Module Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  22. Rank 32WordPress Plugins

    CVE-2020-25213

    WordPress File Manager Plugin Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  23. Rank 33Liferay Portal / DXP

    CVE-2020-7961

    Liferay Portal Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  24. Rank 34October CMS

    CVE-2021-32648

    October CMS Improper Authentication

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    14 days
    CVSS severity
    9.1 (critical)
  25. Rank 35Sitecore Experience Platform / Manager (XP / XM)

    CVE-2025-53690

    Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 4, 2025
    CISA deadline
    21 days
    CVSS severity
    9.0 (critical)
  26. Rank 36Sitecore Experience Platform / Manager (XP / XM)

    CVE-2019-9875

    CVE from 2019, added in 2025

    Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 26, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  27. Rank 37Drupal Core

    CVE-2020-13671

    CVE from 2020, added in 2022

    Drupal core Un-restricted Upload of File

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  28. Rank 38DotNetNuke (DNN)

    CVE-2017-9822

    RansomwareCVE from 2017, added in 2021

    DotNetNuke (DNN) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  29. Rank 39Craft CMS

    CVE-2025-23209

    Craft CMS Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 20, 2025
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  30. Rank 40Drupal Core

    CVE-2019-6340

    CVE from 2019, added in 2022

    Drupal Core Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  31. Rank 41DotNetNuke (DNN)

    CVE-2018-15811

    CVE from 2018, added in 2021

    DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  32. Rank 42DotNetNuke (DNN)

    CVE-2018-18325

    CVE from 2018, added in 2021

    DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  33. Rank 43WordPress Plugins

    CVE-2020-11738

    WordPress Snap Creek Duplicator Plugin File Download Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  34. Rank 44WordPress Plugins

    CVE-2019-9978

    CVE from 2019, added in 2021

    WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.1 (medium)
  35. Rank 45Craft CMS

    CVE-2025-35939

    Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 2, 2025
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)
  36. Rank 46Joomla!

    CVE-2023-23752

    Joomla! Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 8, 2024
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)

Filed under another category

This vulnerability also concerns this type of product, but is counted in its main category. My radar finds it when you follow this category.

  1. Progress Telerik UI for ASP.NET AJAX

    CVE-2017-9248

    CVE from 2017, added in 2021

    Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.