Vendor
wordpress
On CISA KEV2Public exploit12Avg CVSS6.3
CVEs in the catalog
110
since 2019-12
Months in the top 100
8
months with a stored rank
Best rank
#11
one month recomputed
Affected scope
Products and weakness classes
Products
| Product | CVEs | Share |
|---|---|---|
| wordpress | 18 | 16% |
| wordpress develop | 17 | 15% |
| adserve | 2 | 2% |
| geo controller | 2 | 2% |
| max addons pro for bricks | 2 | 2% |
| royal addons for elementor addons and templates kit for elementor | 2 | 2% |
| royal elementor addons | 2 | 2% |
| absolutely glamorous custom admin | 1 | 0.9% |
| acf on the go | 1 | 0.9% |
| agca absolutely glamorous custom admin wordpress plugin | 1 | 0.9% |
| buddypress | 1 | 0.9% |
| buddypress cover | 1 | 0.9% |
Weakness classes
| Weakness | CVEs | Share |
|---|---|---|
| CWE-79 | 36 | 33% |
| CWE-862 | 15 | 14% |
| CWE-352 | 7 | 6% |
| CWE-89 | 6 | 5% |
| CWE-200 | 5 | 5% |
| CWE-434 | 4 | 4% |
| CWE-80 | 4 | 4% |
| CWE-288 | 3 | 3% |
Latest CVEs
15 most recently published
Enriched records open their full page; the rest open their catalog record.
| CVE | Weakness | Signals | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-65640 | CWE-434 | 1 | 8.8 | 2026-08-17 |
| CVE-2026-64638 | CWE-79 | 1 | 8.9 | 2026-08-07 |
| CVE-2026-45293 | CWE-95 | none yet | 8.6 | 2026-07-28 |
| CVE-2026-63030 | CWE-436 | 1 | 9.8 | 2026-07-17 |
| CVE-2026-60137 | CWE-89 | 1 | 5.9 | 2026-07-17 |
| CVE-2020-37233 | CWE-79 | none yet | 6.4 | 2026-05-16 |
| CVE-2023-54333 | CWE-89 | none yet | 8.2 | 2026-01-13 |
| CVE-2025-58674 | CWE-79 | none yet | 5.9 | 2025-09-23 |
| CVE-2025-58246 | CWE-201 | none yet | 4.3 | 2025-09-23 |
| CVE-2025-54352 | CWE-669 | 1 | 3.7 | 2025-07-21 |
| CVE-2023-25454 | CWE-862 | none yet | 6.5 | 2024-12-09 |
| CVE-2024-11292 | CWE-200 | none yet | 5.3 | 2024-12-06 |
| CVE-2024-11178 | CWE-288 | none yet | 8.1 | 2024-12-06 |
| CVE-2024-10311 | CWE-288 | none yet | 7.5 | 2024-11-15 |
| CVE-2024-9927 | CWE-287 | none yet | 7.2 | 2024-10-23 |