Feed live

The CMS vulnerability ledger.

Every published CVE that touches a CMS, plugin, theme, or page builder — indexed, scored, and cross-referenced against the components running on your sites.

Total CVEs tracked
350,619
All time
Critical · Active
12,323
CVSS ≥ 9.0
New · 14 days
1,132
Newly disclosed
Feed last synced
2 hrs ago
Data freshness

What we track

Every CMS CVE. One place.

A CVE is a public record for a known security vulnerability. Each one gets a unique ID, a plain-language description of the problem, and a CVSS score that shows how serious it is. CVE numbers are assigned by MITRE and synced with NIST's National Vulnerability Database (NVD), so they appear consistently across security tools, advisories, and patch notes.

This database covers every CVE that affects a content management system: WordPress, Joomla, Drupal, Magento, TYPO3, WooCommerce, Elementor, Divi, and the thousands of plugins, themes, and extensions built on top of them. It is not a general-purpose vulnerability database. It covers the software layer that runs websites, so site owners, developers, and security teams can quickly check whether something on their sites has a known vulnerability.

The feed pulls from official CVE sources and is updated continuously. The "Feed last synced" counter above shows how old the newest record in the database is. When it says "3 hrs ago", every CVE published in the past three hours is already searchable here. New CVEs usually show up within minutes of NVD publication.

Understanding severity

What the CVSS score means

Every CVE gets a CVSS 3.x score from 0 to 10. The score is calculated from six factors: whether the attack works over the network or needs physical access, how complex the exploit is, whether the attacker needs an existing account, whether a victim has to take some action, and the potential impact on confidentiality, integrity, and availability.

Critical 9.0–10.0 Remote, no auth, max impact
High 7.0–8.9 Serious, remotely exploitable
Medium 4.0–6.9 Often requires auth or conditions
Low 0.1–3.9 Limited exploitability or impact

Some CVEs are published without a CVSS score and updated by NVD analysts days or weeks later. Entries without a score show a dash until scoring is complete.

How this differs from NVD and Wordfence

The NVD covers everything: server operating systems, networking hardware, enterprise applications, IoT firmware. That makes it slow and noisy when you only care about CMS vulnerabilities. Wordfence Intelligence is thorough for WordPress but does not cover Joomla, Drupal, or other CMS platforms. This database covers CMS software only, updated to the hour.

Showing 1–30 CVEs
Sorted by Published · Newest first
CVE ID Severity CVSS Title Published
CVE-2026-16482 high 7.5/10 Sep 12, 2026 today
CVE-2026-77705 Sep 12, 2026 today
CVE-2026-81789 high 8.6/10 Sep 10, 2026 2d ago
CVE-2026-85305 medium 5.4/10 Sep 3, 2026 9d ago
CVE-2026-84847 high 7.5/10 Sep 3, 2026 9d ago
CVE-2026-84812 high 7.1/10 Sep 3, 2026 9d ago
CVE-2026-84774 medium 6.1/10 Sep 3, 2026 9d ago
CVE-2026-84766 medium 5.9/10 Sep 3, 2026 9d ago
CVE-2026-84758 medium 6.5/10 Sep 3, 2026 9d ago
CVE-2026-84753 critical 9.8/10 Sep 3, 2026 9d ago
CVE-2026-84215 medium 6.5/10 Sep 3, 2026 9d ago
CVE-2026-81773 high 7.1/10 Sep 3, 2026 9d ago
CVE-2026-81292 high 7.1/10 Sep 3, 2026 9d ago
CVE-2026-84849 medium 6.5/10 Sep 3, 2026 9d ago
CVE-2026-84815 medium 5.8/10 Sep 3, 2026 9d ago
CVE-2026-84217 medium 5.4/10 Sep 2, 2026 10d ago
CVE-2026-84835 medium 5.3/10 Sep 2, 2026 10d ago
CVE-2026-66652 medium 5.4/10 Sep 2, 2026 10d ago
CVE-2026-81772 high 8.8/10 Sep 2, 2026 10d ago
CVE-2026-84781 medium 6.5/10 Sep 2, 2026 10d ago
CVE-2026-82883 high 7.1/10 Sep 2, 2026 10d ago
CVE-2026-18550 critical 9.8/10 Sep 1, 2026 11d ago
CVE-2026-82226 critical 9.8/10 Aug 31, 2026 12d ago
CVE-2026-81778 medium 6.5/10 Aug 31, 2026 12d ago
CVE-2026-81762 medium 6.5/10 Aug 31, 2026 12d ago
CVE-2026-81296 high 7.5/10 Aug 31, 2026 12d ago
CVE-2026-81280 medium 6.5/10 Aug 31, 2026 12d ago
CVE-2026-83492 medium 6.9/10 Aug 31, 2026 12d ago
CVE-2026-74010 medium 5.3/10 Aug 31, 2026 12d ago
CVE-2026-82220 medium 5.3/10 Aug 28, 2026 15d ago
Page 1
Prev 1 2