Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 19 February 2026
RSS391 vulnerabilities published on 19 February 2026
Severity:
Melapress WP Activity Log: Malicious Code Can Run on Website
CVE-2026-25331
A security issue in Melapress WP Activity Log version 5.5.4 and earlier allows an attacker to inject malicious code into a website, potentially allowing them to steal user data or take control of the ...
6.5
XStore Core Plugin Allows Harmful Code to Run on Your Website
CVE-2026-25307
A security issue in the XStore Core plugin allows attackers to inject malicious code onto your website through user input. This could potentially allow them to steal sensitive information or take cont...
6.5
XStore: Malicious Code Can Run in Browser
CVE-2026-25305
XStore versions 9.6.4 and earlier may allow an attacker to inject malicious code into a website, potentially stealing user data or taking control of the site. This issue can be exploited by a hacker w...
6.5
Aruba HiSpeed Cache: Unauthorized Access to Sensitive Data
CVE-2026-23545
A security issue in Aruba HiSpeed Cache means that if the access control settings are not properly configured, attackers might be able to access sensitive data they shouldn't have access to. This affe...
6.5
CoCoTeaNet CyreneAdmin allows unauthorized access to System Info Endpoint
CVE-2026-2693
An unknown code issue in CoCoTeaNet CyreneAdmin's System Info Endpoint could allow unauthorized access. This could happen if an attacker sends a specific request to the /api/system/dashboard/getCount ...
5.3
CoCoTeaNet CyreneAdmin Image Handler Path Traversal Risk
CVE-2026-2692
An attacker can access unauthorized files on your server by manipulating a specific request to the CyreneAdmin image handler. This could potentially allow unauthorized access to sensitive information....
5.3
Shield Security plugin for WordPress allows attackers to steal sensitive data
CVE-2026-0722
The Shield Security plugin for WordPress has a security weakness that lets hackers trick site administrators into revealing sensitive information. This is a risk because it allows hackers to steal sen...
6.5
WordPress 2FA Plugin Allows Bypassing Security Checks
CVE-2025-13587
The Two Factor Authentication via Email plugin for WordPress has a security flaw that allows attackers to bypass the two-factor authentication process. This means that hackers can access accounts with...
6.5
Aruba HiSpeed Cache Plugin Allows Unauthenticated Configuration Changes
CVE-2025-11725
The Aruba HiSpeed Cache plugin for WordPress has a security issue that allows anyone to change its settings and enable/disable features without needing a password. This could lead to unintended change...
6.5
SPIP 4.4.8 and earlier allows malicious syndication URLs in private area
CVE-2026-27473
SPIP, a content management system, has a security flaw that allows an attacker to inject malicious code into the system. An attacker can exploit this vulnerability by setting a malicious link in a syn...
5.1
Buffer Overflow in CDATA FD614GS3-R850 Can Execute Unwanted Code
CVE-2025-69674
A security flaw in the CDATA FD614GS3-R850 software allows an attacker to potentially take control of the system by sending specific input to certain parameters. This could lead to unauthorized change...
6.4
Dealia – Request a Quote plugin: Malicious Code Can Be Injected
CVE-2026-2718
The Dealia – Request a Quote plugin for WordPress is open to a security risk that allows attackers to inject malicious code into pages. This can happen when a user with contributor-level access or abo...
6.4
Smart Auto Upload Images: Malicious Server Requests Can Be Sent
CVE-2026-23803
A bug in Smart Auto Upload Images allows an attacker to send malicious requests to servers on the internet, potentially causing harm to those systems. This affects versions 1.2.2 and earlier. Update t...
6.4
Advance Block Extend for WordPress allows attackers to inject malicious scripts
CVE-2026-1646
The Advance Block Extend plugin for WordPress contains a security flaw that allows attackers with Contributor-level access or above to inject malicious scripts on certain pages. This could lead to una...
6.4
Easy Author Image plugin: Malicious images can inject malicious scripts
CVE-2026-1373
The Easy Author Image plugin for WordPress is vulnerable to attacks that can inject malicious code into user profiles. This can happen when an authenticated user with limited access uploads a maliciou...
6.4
XO Event Calendar plugin allows hackers to inject malicious scripts in WordPress
CVE-2026-0556
The XO Event Calendar plugin for WordPress has a security flaw that allows hackers to inject malicious scripts into websites. This could allow them to take control of a website or steal sensitive info...
6.4
Groups Plugin for WordPress Allows Malicious Script Injection
CVE-2026-0549
The Groups plugin for WordPress has a security flaw that lets attackers inject malicious code on certain pages. This can harm users who visit those pages. Update to a newer version of the plugin to fi...
6.4
WordPress Font Awesome Field plugin allows hackers to inject malicious scripts
CVE-2025-14983
A security flaw in the WordPress Font Awesome Field plugin makes it possible for hackers to inject malicious code into website visitors' browsers. This can happen if a website is using an outdated ver...
6.4
YaMaps for WordPress plugin allows malicious scripts to run on any page
CVE-2025-14851
A security flaw in the YaMaps for WordPress plugin allows attackers with contributor-level access to inject malicious scripts on any page, which can be executed when users visit those pages. This can ...
6.4
DevVN Image Hotspot Plugin for WordPress allows hackers to inject malicious scripts
CVE-2025-14445
Attackers can inject malicious scripts into WordPress pages if they have author access or higher. This can happen when a user accesses a page with the injected script. It's recommended to update to th...
6.4
WordPress Easy Table of Contents plugin allows attackers to inject malicious scripts
CVE-2025-13738
The Easy Table of Contents plugin for WordPress is vulnerable to a security flaw that allows attackers to inject malicious scripts into pages. This could allow attackers to take control of a website, ...
6.4
s2Member Plugin for WordPress Allows Attackers to Inject Malicious Code
CVE-2025-13732
The s2Member plugin for WordPress can be exploited by attackers with Contributor-level access to inject malicious code into pages, which can be executed when users visit those pages. This can lead to ...
6.4
Apollo13 Framework Extensions for WordPress: Stored XSS via 'a13_alt_link' Parameter
CVE-2025-13617
The Apollo13 Framework Extensions plugin for WordPress has a security flaw that allows attackers with Contributor-level access to inject malicious code into certain pages. This could be used to harm u...
6.4
WordPress Album and Image Gallery plugin allows attackers to inject web scripts
CVE-2025-13612
The Album and Image Gallery plugin for WordPress allows attackers with contributor-level access or higher to inject malicious scripts into web pages, which can then be executed by users who visit thos...
6.4
StatCounter plugin for WordPress allows attackers to inject malicious scripts
CVE-2025-13048
The StatCounter plugin for WordPress has a security flaw that allows attackers to inject malicious scripts into your website, potentially harming visitors. This can happen if an attacker has contribut...
6.4