Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 19 February 2026
RSS391 vulnerabilities published on 19 February 2026
Severity:
Smartsupp Plugin Allows Malicious Code Injection via Chat Input
CVE-2025-12448
The Smartsupp plugin for WordPress has a security flaw that lets attackers inject malicious code into website pages. This can happen if an attacker with a basic account or higher can trick a website u...
6.4
Printful WooCommerce Plugin Exposes Internal Data Through Unvalidated API
CVE-2025-12375
The Printful WooCommerce plugin for WordPress contains a security flaw that allows an attacker with contributor access to make unauthorized requests to internal services, potentially exposing sensitiv...
6.4
Renden WordPress Theme: Malicious Code Injection via Post Title
CVE-2025-12117
The Renden WordPress theme has a security flaw that allows authenticated users with Contributor-level access or higher to inject malicious code into website pages. This code can run on any user's brow...
6.4
Drift WordPress Theme: Malicious Code Injection via Post Titles
CVE-2025-12116
The Drift WordPress theme has a security risk that allows attackers with admin access to inject malicious code into posts. This could lead to unauthorized actions or data theft, and it's essential to ...
6.4
Pannellum: Malicious Content Can Run Without User Interaction
CVE-2026-27210
GHSA-8423-w5wx-h2r6
Websites using Pannellum's viewer may be at risk of a security threat if an attacker can upload a malicious configuration file. This could allow an attacker to take control of the website, replacing i...
5.3
Feathers OAuth Setup Allows Attackers to Take Over Accounts
CVE-2026-27191
GHSA-ppf9-4ffw-hh4p
Feathers OAuth setup can be tricked into redirecting users to malicious sites, allowing attackers to steal access tokens and impersonate users. To fix this, update Feathers to the latest version and e...
7.4
Leaf Kit doesn't properly escape certain special characters in HTML
CVE-2026-27120
GHSA-4hfh-fch3-5q7p
Leaf Kit, a templating engine, has a bug that can allow hackers to inject malicious code into web pages. This can happen when a user-controlled value is used in an HTML attribute. To stay safe, update...
6.1
Cilium: Network Security Policy Bypass with Certain Configurations
CVE-2026-26963
GHSA-5r23-prx4-mqg3
A security issue in Cilium allows unauthorized traffic to bypass network security policies when specific features are enabled. This can happen if you're using Cilium 1.18 between versions 1.18.0 and 1...
6.1
SPIP Before 4.4.9: Private Area XSS Attack Risk
CVE-2026-27474
An attacker can inject malicious code into the private area of SPIP, potentially allowing them to steal sensitive information or take control of user accounts. This is because the software doesn't pro...
4.8
SPIP 4.4.7 and earlier allows malicious code to run in the admin area
CVE-2026-26223
SPIP, a web software, has a security flaw that allows an attacker to inject malicious code into the admin area, potentially allowing them to take control of sensitive parts of the site. This could lea...
5.1
SPIP Login Page Can Redirect Users to Malicious Sites
CVE-2025-71244
If you use SPIP in AJAX mode, a hacker could trick your users into visiting a fake login page that sends them to a different website. This only affects sites that have customized their login page to w...
5.1
SPIP: Malicious scripts can be injected in private area
CVE-2025-71241
If you use SPIP, an attacker might be able to inject malicious scripts in the private area, potentially harming your users. This could lead to unauthorized actions or data theft. Update to the latest ...
4.8
Comodo Dome Firewall: Malicious Scripts Can Be Injected in User Input
CVE-2019-25430
An attacker can inject malicious scripts into Comodo Dome Firewall 2.7.0 by sending fake user input, potentially allowing them to take control of a user's browser. This could lead to unauthorized acce...
5.1
Comodo Dome Firewall: Malicious Script Injection via Firewall Settings
CVE-2019-25429
Comodo Dome Firewall version 2.7.0 has a security flaw that lets hackers inject malicious code into users' browsers by manipulating firewall settings. This can happen when a user visits a compromised ...
5.1
Comodo Dome Firewall 2.7.0 allows attackers to inject malicious scripts
CVE-2019-25428
The Comodo Dome Firewall 2.7.0 has a security flaw that lets attackers send malicious code to users' browsers through the Comodo Dome Firewall's settings page. This could allow attackers to steal sens...
5.1
Comodo Dome Firewall 2.7.0 allows malicious scripts to be injected into user browsers
CVE-2019-25427
The Comodo Dome Firewall version 2.7.0 has a security weakness that lets hackers inject malicious code into users' web browsers. This can happen when a user visits a website that has been set up to ex...
5.1
Comodo Dome Firewall 2.7.0 Allows Malicious Script Injection
CVE-2019-25426
Comodo Dome Firewall's dnsmasq endpoint can be tricked into executing malicious scripts in users' browsers. This can happen if an attacker sends a specially crafted request to the firewall. Users shou...
5.1
Comodo Dome Firewall allows attackers to inject malicious scripts
CVE-2019-25425
Comodo Dome Firewall, a security product, has a weakness that allows hackers to inject malicious code into an administrator's web browser. This can happen when an attacker sends a specially crafted me...
5.1
Comodo Dome Firewall 2.7.0 allows attackers to steal user session data
CVE-2019-25424
A security flaw in Comodo Dome Firewall 2.7.0 allows hackers to steal sensitive user data by sending a special type of request to the firewall's configuration page. This could happen if a user clicks ...
5.1
Comodo Dome Firewall 2.7.0 allows malicious script injection in admin browser
CVE-2019-25423
If an attacker sends a special message to the Comodo Dome Firewall, they can trick an administrator's web browser into running malicious scripts, potentially allowing them to take control of the syste...
5.1
Comodo Dome Firewall 2.7.0 Allows Malicious Scripts to Run on Admin Browsers
CVE-2019-25422
Comodo Dome Firewall 2.7.0 has a security weakness that allows hackers to inject malicious code into an administrator's web browser. This can happen if an administrator views a specially crafted webpa...
5.3
Comodo Dome Firewall 2.7.0 allows attackers to inject malicious scripts via firewall policy
CVE-2019-25421
Comodo's firewall software has a security flaw that could let hackers inject code into the system. This could allow them to take control of the firewall or store malicious scripts, compromising the se...
5.1
Comodo Dome Firewall allows malicious scripts to be injected via user input
CVE-2019-25420
Comodo Dome Firewall version 2.7.0 has a security flaw that lets attackers inject malicious code into users' browsers by tricking them into visiting a malicious website. This could allow the attacker ...
5.1
Comodo Dome Firewall 2.7.0 allows attackers to inject malicious scripts
CVE-2019-25418
Comodo Dome Firewall version 2.7.0 contains a security flaw that lets hackers inject malicious code into users' browsers, potentially stealing sensitive information. This can happen when an attacker s...
5.1
Comodo Dome Firewall 2.7.0: Malicious Script Injection in Administrator Browsers
CVE-2019-25417
Comodo Dome Firewall version 2.7.0 has a security weakness that lets attackers inject malicious code into your administrator's web browser. This can happen when a specially crafted input is sent to th...
5.1