Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CMS — Vulnerabilities & Security Advisories 276

All 276 CVE vulnerabilities found in CMS, with AI-generated Chinese analysis, references, and POCs.

This vulnerability aggregation page provides a comprehensive security overview for the Content Management System (CMS) category, focusing on common weakness types and critical tags. The page collects and aggregates data regarding diverse security flaws, including injection attacks, cross-site scripting, broken access control, and configuration errors, covering historical records from 2010 through the current year. This extensive time range allows users to analyze long-term security trends and the evolution of threat landscapes within widely used CMS platforms. Visitors can discover detailed information by tracking specific vendor advisories to understand how manufacturers respond to emerging threats. Additionally, the resource enables users to deepen their understanding of specific weakness classes by examining how they manifest across different products. It also facilitates the lookup of a particular product's vulnerability history, offering insights into its security posture over time. This structured approach helps security professionals, developers, and analysts assess risks more effectively without sifting through unorganized data. By centralizing these details, the page serves as a vital reference for evaluating the safety of various content management solutions. It supports informed decision-making in software selection, patch management, and vulnerability remediation strategies. The aggregated data highlights recurring patterns and critical gaps, providing a clearer picture of the overall security hygiene within the CMS ecosystem. This resource is designed to streamline the process of identifying and addressing potential security exposures in web-based content platforms.

Vendor: Mambo

CVE IDTitleCVSSSeverityPublished
CVE-2026-19975 Azuriom CMS Money Transfer ProfileController.php transferMoney toctou CWE-367 3.1 Low2026-08-17
CVE-2026-72787 Craft CMS 5.0.0-RC1 before 5.10.8 Stored XSS via Draft Name CWE-79 6.4 Medium2026-08-12
CVE-2026-72786 Craft CMS 5.0.0-RC1 before 5.10.8 Authentication Bypass via Password Reset CWE-285 6.5 Medium2026-08-12
CVE-2026-72785 Craft CMS before 5.10.6 Authorization Bypass via structures/move-element CWE-863 4.3 Medium2026-08-11
CVE-2026-72784 Craft CMS 5.0.0-RC1 before 5.10.6 SSRF via GraphQL asset mutation CWE-918 5.4 Medium2026-08-11
CVE-2026-72783 Craft CMS 5.0.0-RC1 before 5.10.6 Path Traversal via ensurePathIsContained CWE-22 6.2 Medium2026-08-11
CVE-2026-72782 Craft CMS 5.0.0-RC1 before 5.10.6 Environment Variable Leak CWE-668 6.5 Medium2026-08-11
CVE-2026-72781 Craft CMS 5.0.0-RC1 before 5.10.7 Remote Code Execution via Twig Sandbox Escape CWE-693 8.8 High2026-08-11
CVE-2026-72780 Craft CMS before 5.10.5 WebAuthn Assertion Replay via login-with-passkey CWE-294 6.5 Medium2026-08-11
CVE-2026-72779 Craft CMS 5.0.0-RC1 before 5.10.6 Arbitrary File Read via SplFileObject CWE-184 4.5 Medium2026-08-11
CVE-2026-72778 Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.config CWE-915 8.8 High2026-08-11
CVE-2026-71435 Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template CWE-79 6.1 Medium2026-08-06
CVE-2026-71434 Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types CWE-434 5.3 Medium2026-08-06
CVE-2026-64662 Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries CWE-639 6.5 Medium2026-08-06
CVE-2026-64663 Statamic: Unsafe method invocation via Antlers template resolution allows data destruction CWE-470 6.5 Medium2026-08-06
CVE-2026-64665 Statamic: Account takeover via OAuth email matching without email-verification check CWE-287 8.1 High2026-08-06
CVE-2026-64664 Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence CWE-200 4.3 Medium2026-08-06
CVE-2026-5134 SQLi in Loca Software's CMS CWE-89 9.8 Critical2026-08-06
CVE-2026-71293 Statamic CMS Unguarded Exposure of 2FA Recovery Codes via Antlers current_user Variable CWE-200 6.2 Medium2026-08-05
CVE-2026-16219 Croogo CMS Admin File Manager FileManager.php isEditable path traversal CWE-22 6.3 Medium2026-07-19
CVE-2026-16205 Pluck CMS Albums albums.admin.php htmlspecialchars_decode cross site scripting CWE-79 2.4 Low2026-07-19
CVE-2026-54243 Statamic: CSV formula injection in form submission exports CWE-1236 6.1 Medium2026-07-17
CVE-2026-54242 Statamic: Server-Side Request Forgery via Glide (DNS rebinding) CWE-367 4.9 Medium2026-07-17
CVE-2026-54244 Statamic: Incorrect authorization lets view-only users submit Live Preview content reserved for editors CWE-863 3.5 Low2026-07-17
CVE-2026-12257 Remote code execution in Mura Software’s CMS CWE-94--2026-07-13
CVE-2026-14794 Craft CMS Charts Endpoint ChartsController.php actionGetNewUsersData improper authorization CWE-285 4.3 Medium2026-07-06
CVE-2026-14793 Craft CMS reorder-sets Endpoint GlobalsController.php actionReorderSets authorization CWE-639 4.3 Medium2026-07-06
CVE-2026-50282 Craft CMS: Unauthorized Deletion of Destination Folders During Forced Moves CWE-862--2026-07-02
CVE-2026-50281 Craft CMS: Mass assignment via id in newAttributes during bulk duplicate overwrites existing elements CWE-915--2026-07-02
CVE-2026-50280 Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check CWE-284--2026-07-01

All 276 known CVE vulnerabilities affecting CMS with full Chinese analysis, references, and POCs where available.