Skip to content

The detected platform version has known high-severity security vulnerabilities

A CVE (Common Vulnerabilities and Exposures) is a publicly catalogued, known security flaw in software, tracked in the National Vulnerability Database (NVD). This check identifies the content management system (CMS) or platform version running the site and cross-references it against that database. On this site, the detected platform version has one or more CVEs rated HIGH severity, one tier below the most critical rating. High-severity CVEs aren't as urgent as critical ones, but they are actively exploited by automated scanning tools that specifically hunt the internet for unpatched installations of known-vulnerable software. Every day the platform stays on this version is a day it's a live target for exactly this kind of automated attack, not a hypothetical one. Your developer should schedule the patch or version upgrade within the week rather than treating it as routine backlog. Staying on a supported version branch that still receives security updates matters as much as the immediate patch, and subscribing to the platform's own security mailing list helps catch newly disclosed CVEs early, before they become widely exploited.

Why this matters

High-severity CVEs aren't as urgent as critical ones, but they are actively exploited by automated scanning tools that specifically hunt the internet for unpatched installations of known-vulnerable software. Every day the platform stays on this version is a day it's a live target for exactly this kind of automated attack, not a hypothetical one.

How to fix it

Your developer should schedule the patch or version upgrade within the week rather than treating it as routine backlog. Staying on a supported version branch that still receives security updates matters as much as the immediate patch, and subscribing to the platform's own security mailing list helps catch newly disclosed CVEs early, before they become widely exploited.