Feed live

The CMS vulnerability ledger.

Every published CVE that touches a CMS, plugin, theme, or page builder — indexed, scored, and cross-referenced against the components running on your sites.

Total CVEs tracked
347,113
All time
Critical · Active
11,964
CVSS ≥ 9.0
New · 14 days
2,722
Newly disclosed
Feed last synced
2 hrs ago
Data freshness

What we track

Every CMS CVE. One place.

A CVE is a public record for a known security vulnerability. Each one gets a unique ID, a plain-language description of the problem, and a CVSS score that shows how serious it is. CVE numbers are assigned by MITRE and synced with NIST's National Vulnerability Database (NVD), so they appear consistently across security tools, advisories, and patch notes.

This database covers every CVE that affects a content management system: WordPress, Joomla, Drupal, Magento, TYPO3, WooCommerce, Elementor, Divi, and the thousands of plugins, themes, and extensions built on top of them. It is not a general-purpose vulnerability database. It covers the software layer that runs websites, so site owners, developers, and security teams can quickly check whether something on their sites has a known vulnerability.

The feed pulls from official CVE sources and is updated continuously. The "Feed last synced" counter above shows how old the newest record in the database is. When it says "3 hrs ago", every CVE published in the past three hours is already searchable here. New CVEs usually show up within minutes of NVD publication.

Understanding severity

What the CVSS score means

Every CVE gets a CVSS 3.x score from 0 to 10. The score is calculated from six factors: whether the attack works over the network or needs physical access, how complex the exploit is, whether the attacker needs an existing account, whether a victim has to take some action, and the potential impact on confidentiality, integrity, and availability.

Critical 9.0–10.0 Remote, no auth, max impact
High 7.0–8.9 Serious, remotely exploitable
Medium 4.0–6.9 Often requires auth or conditions
Low 0.1–3.9 Limited exploitability or impact

Some CVEs are published without a CVSS score and updated by NVD analysts days or weeks later. Entries without a score show a dash until scoring is complete.

How this differs from NVD and Wordfence

The NVD covers everything: server operating systems, networking hardware, enterprise applications, IoT firmware. That makes it slow and noisy when you only care about CMS vulnerabilities. Wordfence Intelligence is thorough for WordPress but does not cover Joomla, Drupal, or other CMS platforms. This database covers CMS software only, updated to the hour.

Showing 1–30 CVEs
Sorted by Published · Newest first
CVE ID Severity CVSS Title Published
CVE-2026-66611 high 7.1/10 Aug 20, 2026 3d ago
CVE-2026-66595 medium 5.9/10 Aug 20, 2026 3d ago
CVE-2026-66586 medium 6.6/10 Aug 20, 2026 3d ago
CVE-2025-53999 medium 6.5/10 Aug 20, 2026 3d ago
CVE-2026-74021 high 7.5/10 Aug 20, 2026 3d ago
CVE-2026-66602 high 8.8/10 Aug 18, 2026 4d ago
CVE-2026-74015 critical 9.3/10 Aug 18, 2026 5d ago
CVE-2026-74009 medium 5.3/10 Aug 18, 2026 5d ago
CVE-2026-74006 medium 4.3/10 Aug 18, 2026 5d ago
CVE-2026-74003 medium 4.3/10 Aug 18, 2026 5d ago
CVE-2026-73995 medium 5.4/10 Aug 18, 2026 5d ago
CVE-2026-73404 medium 6.5/10 Aug 18, 2026 5d ago
CVE-2026-73398 medium 6.5/10 Aug 18, 2026 5d ago
CVE-2026-73396 high 7.1/10 Aug 18, 2026 5d ago
CVE-2026-73392 critical 9.3/10 Aug 18, 2026 5d ago
CVE-2026-73382 high 7.1/10 Aug 18, 2026 5d ago
CVE-2026-73379 medium 6.5/10 Aug 18, 2026 5d ago
CVE-2026-73377 high 7.5/10 Aug 18, 2026 5d ago
CVE-2026-73365 critical 9.3/10 Aug 18, 2026 5d ago
CVE-2026-73360 high 7.1/10 Aug 18, 2026 5d ago
CVE-2026-73358 high 7.1/10 Aug 18, 2026 5d ago
CVE-2026-73352 medium 6.5/10 Aug 18, 2026 5d ago
CVE-2026-73350 high 8.2/10 Aug 18, 2026 5d ago
CVE-2026-73343 critical 10.0/10 Aug 18, 2026 5d ago
CVE-2026-73341 critical 9.8/10 Aug 18, 2026 5d ago
CVE-2026-73190 high 7.1/10 Aug 18, 2026 5d ago
CVE-2026-73187 critical 9.3/10 Aug 18, 2026 5d ago
CVE-2026-68567 high 7.1/10 Aug 18, 2026 5d ago
CVE-2026-66679 medium 6.5/10 Aug 18, 2026 5d ago
CVE-2026-66646 medium 6.5/10 Aug 18, 2026 5d ago
Page 1
Prev 1 2