Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 20 February 2026
RSS391 vulnerabilities published on 20 February 2026
Severity:
WordPress SOHO Theme Allows Hackers to Run Malicious Code on Your Site
CVE-2025-69368
The SOHO - Photography WordPress Theme has a security issue that allows hackers to inject malicious code into your website. This could lead to unauthorized actions being performed on your site. Update...
7.1
Oyster Photography Theme Allows Malicious Content Injection
CVE-2025-69367
The Oyster Photography Theme has a security flaw that allows hackers to inject malicious content into websites built with this theme. This could potentially let attackers steal sensitive information o...
7.1
Prestige Theme Allows Hackers to Inject Malicious Code
CVE-2025-69330
An attacker can inject malicious code into Prestige websites, potentially stealing user data or taking control of the site. This happens when a user clicks on a specially crafted link. To protect agai...
7.1
NEX-Forms WordPress Plugin Allows Malicious Code Injection
CVE-2025-69326
A security issue in the NEX-Forms WordPress plugin allows attackers to inject malicious code into web pages, potentially stealing sensitive information or taking control of user sessions. This issue a...
7.1
Stored Cross-Site Scripting in Basix NEX-Forms
CVE-2025-69324
A security flaw in NEX-Forms can allow hackers to inject malicious code into your website, potentially stealing user data or taking control of your site. This issue affects all versions of NEX-Forms u...
7.1
Slimstat Analytics: Malicious Code Injection Through Reflected XSS
CVE-2025-69323
A security flaw in Slimstat Analytics allows hackers to inject malicious code into your website, potentially stealing user data or taking control of your site. This issue affects all versions of Slims...
7.1
DesignThemes Core Features allows malicious scripts to run on your site
CVE-2025-69302
An attacker can inject malicious code into your website, potentially stealing user data or taking control of your site. This issue affects DesignThemes Core Features from an unknown version up to 2.3....
7.1
Aardvark 4.6.3 and earlier: Malicious code can be injected into web pages
CVE-2025-69296
The Aardvark software does not properly filter user input, which allows an attacker to inject malicious code into web pages. This can happen when a user clicks on a link or visits a webpage with malic...
7.1
Simple Archive Generator Allows Hackers to Steal User Data
CVE-2025-68880
Simple Archive Generator software has a security flaw that allows hackers to steal user data or take control of a website. This flaw can happen when a user clicks on a malicious link or visits a compr...
7.1
iContact for Gravity Forms allows hackers to inject malicious code via web link
CVE-2025-68863
A security weakness in iContact for Gravity Forms allows hackers to inject malicious code into a website by tricking users into clicking on a specially crafted link. This could lead to unauthorized ac...
7.1
Mopinion Feedback Form can run malicious code on your website
CVE-2025-68856
The Mopinion Feedback Form plugin may allow attackers to inject malicious code into your website, potentially stealing user data or taking control of your site. This affects versions up to 1.1.1. Upda...
7.1
ID Arrays: Unfiltered Input Can Inject Malicious Web Code
CVE-2025-68854
ID Arrays, a software used to generate IDs, contains a security flaw that allows hackers to inject malicious code into web pages. This could potentially steal user data or take control of a user's bro...
7.1
Court Reservation Software Lets Hackers Steal Data via Email Links
CVE-2025-68852
The Court Reservation software has a security flaw that allows hackers to trick users into revealing sensitive information or taking unwanted actions when they click on a malicious email link. This co...
7.1
Malicious Links Can Hijack amr-cron-manager Web Interface
CVE-2025-68848
A security issue in amr-cron-manager allows hackers to inject malicious code into the web interface if a user clicks on a specially crafted link. This could potentially allow an attacker to steal sens...
7.1
iSape Web Application Allows Malicious Script Injection
CVE-2025-68847
A security issue in iSape, a web application, allows hackers to inject malicious code into websites. This could lead to unauthorized access to sensitive information or disruption of service. Update to...
7.1
Asynchronous Javascript allows hackers to inject malicious code through user input
CVE-2025-68846
A security flaw in Asynchronous Javascript versions 1.3.5 and earlier allows hackers to inject malicious code into a web page through user input, potentially stealing sensitive information or taking c...
7.1
eDS Responsive Menu - Unfiltered User Input Can Execute Malicious Scripts
CVE-2025-68845
The eDS Responsive Menu plugin, used in some websites, has a security flaw that allows attackers to inject malicious code into web pages. This could happen if a user clicks on a specially crafted link...
7.1
Membee Login Widget Allows Malicious Code Injection
CVE-2025-68844
A security issue in the Membee Login Widget allows hackers to inject malicious code into web pages, potentially stealing sensitive information or taking control of user sessions. This affects Membee L...
7.1
FeedWordPress Advanced Filters: Malicious Code Injection Risk
CVE-2025-68843
A security issue in FeedWordPress Advanced Filters could allow hackers to inject malicious code into websites, potentially stealing sensitive information or taking control of user accounts. This issue...
7.1
TotalBounty Widget Logic Visual allows Malicious Code to Run in Browsers
CVE-2025-68842
A security flaw in the TotalBounty Widget Logic Visual allows an attacker to inject malicious code into web pages, potentially stealing user data or taking control of user sessions. This issue affects...
7.1
Mollie Payments for WooCommerce allows attackers to inject malicious code into web pages
CVE-2025-68501
A weakness in Mollie Payments for WooCommerce makes it possible for attackers to inject malicious code into web pages, potentially allowing them to steal sensitive information or take control of users...
7.1
Crocoblock JetEngine: Malicious Code Can Run on Your Site
CVE-2025-68495
If you're using Crocoblock JetEngine, a malicious person can inject code into your website through a vulnerable feature. This allows them to potentially steal user data or take control of your site. U...
7.1
Incorrect Access Control in Directorist Allows Unauthorized Access
CVE-2025-68069
A security issue in Directorist allows unauthorized access to certain features, which could lead to sensitive information disclosure or unintended changes. Directorist versions 8.5.10 and below are af...
7.1
Export Media URLs in Atlas Gondal Export Media URLs can cause malicious scripts to run
CVE-2025-68037
A security issue in Export Media URLs in Atlas Gondal's Export Media URLs (versions 2.2 and earlier) allows attackers to inject malicious code into web pages. This can lead to unauthorized actions on ...
7.1
Faraz SMS Plugin Allows Malicious Code to Run on Your Website
CVE-2025-68031
A security issue in Faraz SMS Plugin allows attackers to inject malicious code into your website, potentially allowing them to steal user data or take control of your site. This affects the Faraz SMS ...
7.1