Feed live

The CMS vulnerability ledger.

Every published CVE that touches a CMS, plugin, theme, or page builder — indexed, scored, and cross-referenced against the components running on your sites.

Total CVEs tracked
353,835
All time
Critical · Active
12,544
CVSS ≥ 9.0
New · 14 days
1,418
Newly disclosed
Feed last synced
55 mins ago
Data freshness

What we track

Every CMS CVE. One place.

A CVE is a public record for a known security vulnerability. Each one gets a unique ID, a plain-language description of the problem, and a CVSS score that shows how serious it is. CVE numbers are assigned by MITRE and synced with NIST's National Vulnerability Database (NVD), so they appear consistently across security tools, advisories, and patch notes.

This database covers every CVE that affects a content management system: WordPress, Joomla, Drupal, Magento, TYPO3, WooCommerce, Elementor, Divi, and the thousands of plugins, themes, and extensions built on top of them. It is not a general-purpose vulnerability database. It covers the software layer that runs websites, so site owners, developers, and security teams can quickly check whether something on their sites has a known vulnerability.

The feed pulls from official CVE sources and is updated continuously. The "Feed last synced" counter above shows how old the newest record in the database is. When it says "3 hrs ago", every CVE published in the past three hours is already searchable here. New CVEs usually show up within minutes of NVD publication.

Understanding severity

What the CVSS score means

Every CVE gets a CVSS 3.x score from 0 to 10. The score is calculated from six factors: whether the attack works over the network or needs physical access, how complex the exploit is, whether the attacker needs an existing account, whether a victim has to take some action, and the potential impact on confidentiality, integrity, and availability.

Critical 9.0–10.0 Remote, no auth, max impact
High 7.0–8.9 Serious, remotely exploitable
Medium 4.0–6.9 Often requires auth or conditions
Low 0.1–3.9 Limited exploitability or impact

Some CVEs are published without a CVSS score and updated by NVD analysts days or weeks later. Entries without a score show a dash until scoring is complete.

How this differs from NVD and Wordfence

The NVD covers everything: server operating systems, networking hardware, enterprise applications, IoT firmware. That makes it slow and noisy when you only care about CMS vulnerabilities. Wordfence Intelligence is thorough for WordPress but does not cover Joomla, Drupal, or other CMS platforms. This database covers CMS software only, updated to the hour.

Showing 1–30 CVEs
Sorted by Published · Newest first
CVE ID Severity CVSS Title Published
CVE-2026-66666 medium 6.9/10 Oct 6, 2026 today
CVE-2026-42700 medium 6.5/10 Oct 5, 2026 yesterday
CVE-2026-105421 medium 5.3/10 Oct 5, 2026 yesterday
CVE-2026-104402 medium 4.3/10 Oct 4, 2026 2d ago
CVE-2026-97307 high 7.5/10 Oct 4, 2026 2d ago
CVE-2026-103355 critical 9.3/10 Oct 4, 2026 2d ago
CVE-2026-103344 high 7.1/10 Oct 4, 2026 2d ago
CVE-2026-97276 high 7.1/10 Oct 4, 2026 2d ago
CVE-2026-103062 high 7.1/10 Oct 4, 2026 2d ago
CVE-2026-103354 high 7.1/10 Oct 4, 2026 2d ago
CVE-2026-96451 high 8.8/10 Oct 3, 2026 3d ago
CVE-2026-103342 high 7.1/10 Oct 3, 2026 3d ago
CVE-2026-103065 high 8.2/10 Oct 3, 2026 3d ago
CVE-2026-39601 low 3.7/10 Oct 2, 2026 4d ago
CVE-2026-32585 medium 6.5/10 Oct 2, 2026 4d ago
CVE-2026-104403 medium 5.3/10 Oct 2, 2026 4d ago
CVE-2026-94180 medium 4.3/10 Oct 2, 2026 4d ago
CVE-2026-84925 medium 6.1/10 Oct 2, 2026 4d ago
CVE-2026-97273 high 7.1/10 Oct 1, 2026 5d ago
CVE-2026-97258 medium 6.5/10 Oct 1, 2026 5d ago
CVE-2026-62073 high 7.5/10 Oct 1, 2026 5d ago
CVE-2026-62059 high 7.6/10 Oct 1, 2026 5d ago
CVE-2026-103064 medium 6.5/10 Oct 1, 2026 5d ago
CVE-2026-102382 medium 4.3/10 Oct 1, 2026 5d ago
CVE-2026-103341 medium 5.3/10 Oct 1, 2026 5d ago
CVE-2026-103336 medium 5.3/10 Oct 1, 2026 5d ago
CVE-2026-94171 high 7.1/10 Sep 30, 2026 6d ago
CVE-2026-97287 high 8.5/10 Sep 30, 2026 6d ago
CVE-2026-96326 high 7.2/10 Sep 29, 2026 7d ago
CVE-2026-96752 high 7.2/10 Sep 25, 2026 11d ago
Page 1
Prev 1 2 …