Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CMS — Vulnerabilities & Security Advisories 314

All 314 CVE vulnerabilities found in CMS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting Content Management Systems. It collects recorded flaws across multiple CMS vendors, spanning advisories published over the last five years. Readers can track vendor-specific security updates, analyze common weakness classes such as SQL injection and cross-site scripting, and review the historical vulnerability trends for any given product. The data is organized by vendor and weakness type, enabling detailed comparison and trend analysis. No specific CVE identifiers are listed in this overview; the focus remains on patterns, frequencies, and remediation guidance. This resource supports security teams, developers, and IT managers who need to prioritize patches and assess risk exposure across their managed platforms.

Vendor: Mambo

CVE ID Title CVSS Severity Published
CVE-2026-105985 Authenticated RCE via render-components Entry Type overrides CWE-1336 8.8 High 2026-10-06
CVE-2026-92594 Craft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQL CWE-200 7.5 High 2026-09-16
CVE-2026-92593 Craft CMS 5.10.0 before 5.10.13 Authenticated Remote Code Execution CWE-94 8.8 High 2026-09-16
CVE-2026-92592 Craft CMS before 4.18.6 Remote Code Execution via signed cookie CWE-1336 8.8 High 2026-09-16
CVE-2026-92591 Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer CWE-636 5.9 Medium 2026-09-16
CVE-2026-92590 Craft CMS 5.7.0 before 5.10.13 Stored XSS via Generated Fields CWE-79 5.4 Medium 2026-09-16
CVE-2026-92589 Craft CMS 5.0.0 before 5.10.13 Broken Access Control via nested-elements/reorder CWE-862 4.3 Medium 2026-09-16
CVE-2026-90709 Yot CMS Admin Console admin.php eval code injection CWE-94 4.7 Medium 2026-09-14
CVE-2026-90708 Yot CMS Cookie global.php login sql injection CWE-89 7.3 High 2026-09-14
CVE-2026-79987 Low-privilege RCE through element-search eager loading CWE-470 8.8 High 2026-09-10
CVE-2026-86732 Craft CMS before 5.10.12 Remote Code Execution via element-index CWE-94 8.8 High 2026-09-08
CVE-2026-86731 Craft CMS 5.0.0-RC1 before 5.10.12 Permission Escalation via UsersController CWE-862 6.5 Medium 2026-09-08
CVE-2026-86730 Craft CMS 5.0.0-RC1 before 5.10.12 Behavior Injection RCE CWE-94 8.8 High 2026-09-08
CVE-2026-86308 light0011 cms Debug Mode config.php information disclosure CWE-200 5.3 Medium 2026-09-07
CVE-2026-86307 light0011 cms cross-site request forgery CWE-352 4.3 Medium 2026-09-07
CVE-2026-86306 light0011 cms Cookie Helper UserModel.class.php improper authentication CWE-287 7.3 High 2026-09-07
CVE-2026-86305 light0011 cms Upload.class.php upload unrestricted upload CWE-434 7.3 High 2026-09-07
CVE-2026-85382 light0011 cms Chapter Content Output oneChapter.tpl htmlspecialchars_decode cross site scripting CWE-79 4.3 Medium 2026-09-04
CVE-2026-85381 light0011 cms Chapter Controller ChapterController.class.php authorization CWE-639 5.3 Medium 2026-09-04
CVE-2026-85380 light0011 cms UEditor controller.php catchimage server-side request forgery CWE-918 7.3 High 2026-09-04
CVE-2026-85379 light0011 cms Query Builder ChapterController.class.php searchChapter sql injection CWE-89 7.3 High 2026-09-04
CVE-2026-85378 light0011 cms Chapter Controller ChapterController.class.php _initialize authorization CWE-639 7.3 High 2026-09-03
CVE-2026-79991 Authenticated SQL Injection via nested eager-loading criteria CWE-89 7.1 High 2026-09-02
CVE-2026-79990 GQL entry mutation `siteId` bypasses schema site scope, enabling cross-site content read/write/delete CWE-639 8.7 High 2026-09-02
CVE-2026-79989 Arbitrary user password reset leading to administrator account takeover CWE-285 8.7 High 2026-09-02
CVE-2026-84802 Craft CMS 5.7.0 before 5.10.12 Information Disclosure via AssetsController CWE-862 4.3 Medium 2026-09-02
CVE-2026-84801 Craft CMS 5.0.0-RC1 before 5.10.11 Authentication Bypass via administrateUsers CWE-862 8.8 High 2026-09-02
CVE-2026-84800 Craft CMS 5.0.0-RC1 before 5.10.11 File Overwrite via assets/replace-file CWE-862 7.1 High 2026-09-02
CVE-2026-84798 Craft CMS before 5.10.11 Authorization Bypass via actionDeleteForSite CWE-862 7.1 High 2026-09-02
CVE-2026-84799 Craft CMS before 5.11.0 PII Disclosure via GraphQL User Relations CWE-285 4.3 Medium 2026-09-02

All 314 known CVE vulnerabilities affecting CMS with full Chinese analysis, references, and POCs where available.