📝

CMS / Site Builder

slug: cms

🛡 Related vulnerabilities 69

ID Title
CVE-2026-18323 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
CVE-2026-16601 The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
CVE-2026-18328 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
CVE-2026-72696 Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job:...
CVE-2026-72695 Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
CVE-2026-56707 Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
CVE-2026-14279 The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
CVE-2026-73680 Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
CVE-2026-19794 The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
CVE-2026-19758 A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
CVE-2026-18146 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
CVE-2026-15426 The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
CVE-2026-18325 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
CVE-2026-16636 The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
CVE-2026-15991 The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible...
CVE-2026-71291 Bolt CMS renders content field values through Twig's full application-level Environment with no...
CVE-2026-7520 The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
CVE-2026-7444 The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2026-6627 The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
CVE-2026-6147 The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
CVE-2026-66473 Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
CVE-2026-65447 Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
CVE-2026-65446 Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
CVE-2026-65443 Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
CVE-2026-65442 Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
CVE-2026-65441 Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.
CVE-2026-65437 Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <=...
CVE-2026-61953 Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
CVE-2026-63030 KEV WordPress Core — WordPress Core Interpretation Conflict Vulnerability
CVE-2026-58054 MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when...

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →