Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 18 February 2026
RSS331 vulnerabilities published on 18 February 2026
Severity:
OpenClaw Browser Upload Allows Attackers to Read Local Files
CVE-2026-26329
GHSA-cv7m-c9jx-vg7q
A security issue in OpenClaw allows attackers who are already authenticated to access and read files on the server by uploading malicious file paths. This could compromise sensitive data. To fix this ...
7.1
iMessage Group Authorization Bypass via DM Pairing
CVE-2026-26328
GHSA-g34w-4xqq-h79m
A vulnerability in OpenClaw's iMessage group authorization allows a sender approved via direct message pairing to access group conversations even if they're not explicitly allowed. This could lead to ...
6.5
OpenClaw allows attackers to hijack connections and credentials
CVE-2026-26327
GHSA-pv58-549p-qh99
A vulnerability in OpenClaw allows an attacker on a shared network to trick devices into connecting to a fake endpoint and accepting a fake certificate, potentially stealing login credentials. This is...
7.1
IPFire 2.21 Core Update 127: Malicious Scripts Can Run in Admin Sessions
CVE-2019-25399
Attackers can inject malicious scripts into the IPFire web interface, potentially taking control of administrator sessions. This could allow unauthorized access to sensitive settings. Update to the la...
5.1
Complianz Cookie Consent Plugin on WordPress Can Execute Malicious Code
CVE-2025-11185
The Complianz Cookie Consent plugin for WordPress has a security flaw that allows attackers with some access rights to inject malicious code into website pages, which can be executed when users visit ...
6.4
WP Event Aggregator plugin for WordPress allows malicious scripts to run on sites
CVE-2026-1941
An attacker with contributor access can inject malicious code into event pages. Users should update to a patched version of the plugin to prevent unauthorized scripts from running on their site.
6.4
WordPress InteractiveCalculator Plugin Allows Attackers to Inject Malicious Scripts
CVE-2026-1807
The InteractiveCalculator plugin for WordPress fails to properly check user input, allowing attackers with contributor-level access to inject malicious scripts into pages that can be executed when use...
6.4
Popup Box WordPress plugin can run malicious scripts on your site
CVE-2025-12122
The Popup Box WordPress plugin has a security flaw that allows attackers to inject malicious code on your site if they have contributor-level access. This means they can run unauthorized scripts on yo...
6.4
WordPress VK All in One Expansion Unit plugin allows attackers to inject malicious scripts
CVE-2025-11737
An attacker with Contributor-level access can inject malicious scripts into WordPress pages, which can execute when users visit those pages. This can lead to unauthorized actions, data theft, or other...
6.4
Display During Conditional Shortcode plugin for WordPress allows malicious scripts to run
CVE-2025-6460
The Display During Conditional Shortcode plugin for WordPress has a security flaw that lets attackers inject malicious code into pages, which can run when users visit those pages. This can happen if a...
6.4
Filestack WordPress Plugin: Malicious Code Injection via Filepicker Shortcode
CVE-2025-13959
The Filestack plugin for WordPress allows attackers to inject malicious code into pages that users can access, potentially harming your site and its users. This affects all versions up to 2.0.8. Updat...
6.4
A weakness has been identified in GoogTech sms-ssm up to e8534c766fd13f5f94c01dab475d75f286918a8d. Affected by this issue is the function preHandle of the file LoginInterceptor.java of the componen...
CVE-2026-2676
A weakness has been identified in GoogTech sms-ssm up to e8534c766fd13f5f94c01dab475d75f286918a8d. Affected by this issue is the function preHandle of the file LoginInterceptor.java of the component A...
5.3
live555 Fork: Memory Corruption Via Remote Attack
CVE-2026-1200
An attacker can exploit a weakness in the live555 fork's code, causing the program to crash or behave erratically, potentially leading to data loss or security breaches. This affects users of the rgau...
6.3
huanzi-qch base-admin allows attackers to upload malicious files
CVE-2026-2665
A security issue in the huanzi-qch base-admin system allows attackers to upload any type of file without restrictions, potentially leading to malicious code execution. This is a risk because it allows...
5.3
Alixhan xh-admin-backend SQL Injection Risk in Database Queries
CVE-2026-2663
Alixhan xh-admin-backend versions up to 1.7.0 are at risk of a SQL injection attack, which could allow an attacker to manipulate database queries. This could lead to unauthorized access to sensitive d...
5.3
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Key Software Solutions Inc. INFOREX- General Information Management System allows XSS Th...
CVE-2025-8308
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Key Software Solutions Inc. INFOREX- General Information Management System allows XSS Throu...
6.3
MajorDoMo shoutbox allows attackers to steal admin session
CVE-2026-27178
The MajorDoMo shoutbox is vulnerable to a security threat that allows attackers to steal sensitive information from administrators. This can happen when an attacker injects malicious code into the sho...
5.3
MajorDoMo: Stored XSS Allows Malicious Code Injection
CVE-2026-27177
The MajorDoMo system has a security flaw that could allow an attacker to inject malicious code into the system. This could potentially allow an attacker to access sensitive information or take control...
5.3
MajorDoMo: Malicious Code Can Be Injected into Web Pages
CVE-2026-27176
The MajorDoMo software contains a security flaw that lets attackers inject malicious code onto web pages. This could allow hackers to take control of user sessions or steal sensitive information. Upda...
5.1
IPFire VPN Configuration Parameter Cross-Site Scripting Flaw
CVE-2019-25398
IPFire VPN configuration parameters can be exploited to inject malicious scripts into administrator browsers, potentially allowing attackers to take control of the system. This affects the ovpnmain.cg...
5.1
IPFire: Malicious Scripts Can Be Injected Through Hosts.cgi
CVE-2019-25397
IPFire's hosts.cgi script is vulnerable to an attack where an attacker can inject malicious code into a user's browser, potentially allowing the attacker to steal sensitive information or take control...
5.1
IPFire Update 127: Malicious Scripts Can Be Injected via Browser
CVE-2019-25396
Attackers can inject malicious scripts into IPFire's update process, potentially harming users' computers. This could happen if a user visits a malicious website or opens a malicious email that contai...
5.1
Bematech MP-4200 TH Printer: Malicious Code Injection Risk
CVE-2019-25356
If an attacker knows your login credentials, they can inject malicious code into your printer's settings page, allowing them to access sensitive data or take control of your printer. This risk exists ...
5.1
LibreNMS Email Field XSS Attack Can Steal Your Session
CVE-2026-26987
GHSA-gqx7-99jw-6fpr
A security flaw in LibreNMS allows an attacker to trick you into revealing your login credentials. This can happen when you visit a malicious website or open a phishing email that includes a link to t...
5.3
Ultimate Member Plugin for WordPress allows attackers to inject malicious code via links
CVE-2026-1404
The Ultimate Member plugin for WordPress is vulnerable to a type of cyber attack that can inject malicious code into websites. This can happen if a user clicks on a link that has been designed to tric...
6.1