Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 18 February 2026
RSS331 vulnerabilities published on 18 February 2026
Severity:
Old Orthanc Software Allows Unauthorised Access to Admin
CVE-2025-15581
If you use Orthanc version 1.12.10 or earlier, an attacker could gain full control of your system by exploiting a weakness in the way users are checked for permission. This is a serious issue, as it c...
4.7
Unrestricted File Upload in mingSoft MCMS 6.1.1
CVE-2026-2666
GHSA-r9wp-qq53-qvjx
A security issue in mingSoft MCMS 6.1.1 allows attackers to upload files without restriction, potentially allowing them to inject malicious code. This could lead to unauthorized access to sensitive da...
2.0
WordPress URL Shortify plugin can redirect users to malicious sites
CVE-2026-1277
The URL Shortify plugin for WordPress has a security flaw that allows attackers to trick users into visiting fake websites. This can happen when a user clicks on a suspicious link. Update the plugin t...
4.7
InvoicePlane: An attacker can hijack user sessions and steal data.
CVE-2026-26281
A security issue in InvoicePlane lets an authorized user with invoice management access execute malicious code in other users' browsers, potentially stealing their data or taking control of their sess...
4.4
Video Share VOD Plugin for WordPress Can Execute Malicious Code
CVE-2025-13727
The Video Share VOD plugin for WordPress, used to build video sharing sites, contains a security flaw. If an attacker with sufficient permissions edits the plugin settings, they can inject malicious c...
4.4
WordPress Community Events plugin allows malicious scripts to run on your site
CVE-2026-1649
An attacker with administrator access can inject malicious code into your site that will run when users visit specific pages. This can lead to a range of issues, including data theft and unauthorized ...
4.4
YayMail – WooCommerce Email Customizer plugin: Injected scripts on certain WordPress sites
CVE-2026-1943
A security issue in the YayMail plugin for WordPress can allow attackers to inject malicious code into certain pages on your website. This can happen if you have a multi-site installation and have res...
4.4
WordPress Private Comment plugin allows hackers to inject code via label text
CVE-2026-2281
The Private Comment plugin for WordPress has a security flaw that allows attackers to inject malicious code into certain pages. This could happen if an administrator with high-level access adds a mali...
4.4
WordPress Membership Plugin Vulnerable to Malicious Scripts in Invoices
CVE-2026-1304
The Membership Plugin for WordPress is at risk of being compromised by malicious scripts in the invoice settings. If an attacker gains admin access, they can inject scripts that will run when users vi...
4.4
WordPress Plugin Allows Hackers to Inject Malicious Code
CVE-2025-12037
A security flaw in the WP 404 Auto Redirect to Similar Post plugin for WordPress could allow hackers to inject malicious code into websites. This only affects WordPress sites with multi-site installat...
4.4
Tsinghua Unigroup Electronic Archives System allows remote file access
CVE-2026-2683
The Tsinghua Unigroup Electronic Archives System has a security flaw that allows an attacker to access files they shouldn't be able to. This could happen if someone with malicious intentions can trick...
5.3
LibreNMS Alert Rule Creation Allows Malicious JavaScript
CVE-2026-26989
GHSA-6xmx-xr9p-58p7
A security issue exists in LibreNMS that allows an attacker with admin access to inject malicious JavaScript into the Alert Rules page, which can be executed when viewed. This could allow an attacker ...
4.3
newbee-mall Multiple Endpoints Allow Attackers to Forge Requests
CVE-2026-2658
A security flaw in newbee-mall's Multiple Endpoints component could allow hackers to trick users into performing unintended actions. This means that attackers can potentially trick users into doing so...
5.3
Splunk: Malicious user can crash Splunk Web with crafted password change
CVE-2026-20139
A low-privileged user can intentionally slow down or shut down Splunk Web by changing their password with a specially crafted request. This can cause performance issues or make Splunk Web unresponsive...
4.3
Booking Calendar plugin for WordPress allows attackers to change other users' settings
CVE-2026-2230
Attackers with certain permissions can change the booking calendar settings for other users, disrupting their booking functionality. This can happen in versions up to 10.14.14 of the Booking Calendar ...
4.3
Jenkins: Unauthorized users can access build information
CVE-2026-27100
GHSA-wfhp-qgm8-5p5c
Old versions of Jenkins allow unauthorized users to see information about builds they shouldn't have access to, including job and build existence. This could be a security risk if your Jenkins instanc...
4.3
The Plus Addons for Elementor plugin allows unauthorized post creation
CVE-2026-2386
An attacker with Author-level access and above can create posts they shouldn't be able to. This can lead to unauthorized changes to your website. Update to version 6.4.8 or later to fix the issue.
4.3
Dam Spam plugin for WordPress allows attackers to delete comments
CVE-2026-2112
The Dam Spam plugin for WordPress has a security flaw that allows attackers to delete all pending comments without permission. This is a concern for sites using the plugin, as it can lead to comment d...
4.3
Kali Forms plugin for WordPress: unauthorized access to form data
CVE-2026-1860
The Kali Forms plugin for WordPress has a security issue that allows users with Contributor-level access to access and view form data that belongs to other users, including administrators. This could ...
4.3
EventPrime Plugin for WordPress Allows Admins' Posts to be Modified
CVE-2026-1655
An attacker with a WordPress account can modify posts created by administrators by manipulating a specific parameter. This is a risk for sites using the EventPrime plugin, especially if administrators...
4.3
Kadence WP plugin allows Contributors to upload malicious images to WordPress
CVE-2026-2633
The Kadence WP plugin for WordPress has a flaw that lets Contributors upload files from the internet to the WordPress Media Library. This is a security risk because Contributors shouldn't be able to d...
4.3
Kadence WP plugin exposes sensitive data through malicious server requests
CVE-2026-1857
The Kadence WP plugin for WordPress allows attackers with Contributor-level access and above to make unauthorized server requests, potentially exposing sensitive data like contacts, campaigns, and mai...
4.3
Taskbuilder Plugin Allows Attackers to Bypass Access Controls
CVE-2026-1640
The Taskbuilder plugin for WordPress has a security flaw that lets someone with a subscriber-level account or higher create comments on any project or task, even if they shouldn't be able to access it...
4.3
WP Plugin Info Card plugin: Attackers can trick admins into creating or modifying plugins
CVE-2026-2023
The WP Plugin Info Card plugin for WordPress is at risk because it doesn't properly check if requests are coming from a trusted source. This could allow attackers to trick an admin into creating or mo...
4.3
PDF Invoices & Packing Slips for WooCommerce plugin allows attackers to modify customer data
CVE-2026-1906
A security issue in the PDF Invoices & Packing Slips for WooCommerce plugin allows an attacker with a low-level account to change sensitive customer information. This could disrupt payments and lead t...
4.3