Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 20 February 2026

RSS

391 vulnerabilities published on 20 February 2026

Severity:
Capella: Malicious data can inject objects into your system
CVE-2025-69370
A security weakness in Capella versions up to 2.5.5 makes it possible for attackers to inject malicious code into your system. This could potentially lead to unauthorized access or data corruption. We...
9.8
Prestige Untrusted Data Can Be Injected, Causing Malicious Execution
CVE-2025-69329
The Prestige software is vulnerable to a security threat that could allow an attacker to inject malicious code into the system. This could lead to unauthorized actions being taken on the system. To st...
9.8
PhotoMe ThemeGoods PhotoMe Untrusted Data Deserialization Risk
CVE-2025-69301
PhotoMe users are at risk of data tampering if an attacker sends specially crafted data. This affects PhotoMe versions up to 5.6.11. Update to version 5.6.12 or later to fix the issue.
9.8
BoldThemes Ippsum ippsum: Untrusted Data Can Execute Code
CVE-2025-68541
The BoldThemes Ippsum ippsum software does not properly handle untrusted input, which can lead to malicious code being executed. This can potentially allow an attacker to take control of the affected ...
9.8
Travelicious Travel and Hotel Booking Website Allows Untrusted Data Injection
CVE-2025-67997
The Travelicious website has a weakness that could allow an attacker to inject malicious data, potentially leading to unauthorized changes to the website's behavior. This issue affects all versions of...
9.8
BoldThemes Nestin: Untrusted Data Can Be Injected into Nestin
CVE-2025-67996
Nestin, a plugin for BoldThemes, contains a security flaw that lets attackers inject malicious code into the application. This can happen when the plugin is not properly configured or when user input ...
9.8
PatioTime Software Allows Attackers to Inject Malicious Data
CVE-2025-67995
The PatioTime software fails to properly validate user input, allowing attackers to inject malicious objects. This means a hacker could potentially take control of your system or steal sensitive infor...
9.8
Talentics Software: Malicious SQL Code Can Be Injected
CVE-2025-10970
A security issue in Talentics software allows an attacker to inject malicious code into the database, potentially stealing sensitive information or disrupting the system. This could happen if an attac...
9.8
Acronis Software Fails to Verify User Identity, Exposing Sensitive Data
CVE-2025-30410
If not updated, Acronis Cyber Protect Cloud Agent, Acronis Cyber Protect 16, and Acronis Cyber Protect 15 may allow unauthorized access to sensitive information and potentially allow attackers to mani...
9.8
Joomla Tassos Framework plugin allows unauthorized access to internal functionality
CVE-2026-21627
The Tassos Framework plugin for Joomla has a security issue that could let attackers access internal functions without permission. This could potentially allow them to do things they shouldn't be able...
9.5
Key Systems Global Facilities Management Software Privilege Escalation Vulnerability
CVE-2026-26722
A security issue in Key Systems Global Facilities Management Software could let an attacker access sensitive areas of a building's management system by exploiting a weakness in the way users log in. T...
9.4
Smanga 3.2.7 allows attackers to reset any user's password
CVE-2025-70833
An attacker can reset any user's password, including the administrator's, without needing a password. This could allow them to take full control of the affected account. Update Smanga to a fixed versi...
9.4
Fast-XML-Parser: Entity Name Regex Injection via Period Allows XSS
CVE-2026-25896 GHSA-m7jm-9gc2-mpf2
An attacker can use a specially crafted XML file to bypass security checks and inject malicious code into the parsed output, potentially leading to cross-site scripting attacks. This issue affects the...
9.3
SQL Injection in Download Manager Addons for Elementor
CVE-2026-24956
A security flaw in Download Manager Addons for Elementor allows hackers to access sensitive data. This affects the plugin if you're using version 1.3.0 or earlier. Update to the latest version to prot...
9.3
Emerce Core SQL Injection Risk: Data Exposure
CVE-2025-69366
A security issue in Emerce Core allows attackers to access sensitive data without permission, potentially leading to unauthorized access to customer information. This affects versions 1.0 to 1.8 of Em...
9.3
Uroan Core: Malicious SQL Queries Can Be Injected
CVE-2025-69365
The Uroan Core software has a security flaw that allows hackers to inject malicious SQL commands. This could allow an attacker to access sensitive data or disrupt the website. Update to version 1.4.5 ...
9.3
Wolmart Core: Blind SQL Injection in User Data
CVE-2025-69337
A fault in Wolmart Core's database handling allows attackers to extract sensitive information by manipulating user input. This could, for example, allow hackers to access user passwords or other sensi...
9.3
Woodly Core Allows Hackers to Access Sensitive Data
CVE-2025-69310
A security flaw in Woodly Core software allows hackers to potentially access sensitive user data by manipulating the way the software interacts with its database. This could lead to unauthorized acces...
9.3
Saasplate Core: Malicious SQL Queries Can Access Sensitive Data
CVE-2025-69309
An issue in Saasplate Core allows attackers to inject malicious SQL code, potentially exposing sensitive data. This affects users of Saasplate Core versions up to 1.2.8. To protect your data, update t...
9.3
Nestbyte Core: Data stolen from database due to SQL attack
CVE-2025-69308
The Nestbyte Core software has a security flaw that could allow an attacker to access sensitive data in the database without being detected. This means that unauthorized access to confidential informa...
9.3
Medinik Core: Unsecured Input Can Expose Sensitive Data
CVE-2025-69307
The Medinik Core software has a security flaw that makes it vulnerable to a type of attack that can extract sensitive information from a database. This could allow an attacker to access confidential d...
9.3
Electio Core Theme Allows Hackers to Access Your Database
CVE-2025-69306
A security flaw in Electio Core theme allows attackers to access your website's database without you knowing. This means they can potentially steal sensitive information or disrupt your site. Update t...
9.3
Crete Core: Malicious SQL Code Can Be Injected into Database
CVE-2025-69305
A security issue in Crete Core's database system allows an attacker to inject malicious SQL code, potentially allowing them to access or modify sensitive information. This affects Crete Core versions ...
9.3
Allmart: SQL Injection in TeconceTheme Allmart allmart-core
CVE-2025-69304
A security issue in Allmart's TeconceTheme allmart-core software allows attackers to access sensitive data by manipulating SQL commands. This could lead to unauthorized access to sensitive information...
9.3
Coven Core: Data Exposure through SQL Injection
CVE-2025-69295
Coven Core plugins may allow unauthorized access to sensitive data. This is a serious issue because attackers can extract confidential information from your website. Update to Coven Core version 1.4 o...
9.3