Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 20 February 2026
RSS391 vulnerabilities published on 20 February 2026
Severity:
AncoraThemes Blabber blabber allows attackers to read any PHP file on your server
CVE-2026-22378
A security issue in AncoraThemes Blabber blabber allows hackers to view and potentially access sensitive information on your server by exploiting a file inclusion flaw. This could lead to unauthorized...
8.1
Saveo: Attackers can access local files on your server
CVE-2026-22377
The Saveo software allows an attacker to access any file on your server by tricking the system into including the wrong file in a PHP program. This can lead to sensitive information being stolen or ma...
8.1
Parkivia Theme Allows Malicious Files to be Loaded
CVE-2026-22376
The Parkivia theme has a security issue that allows hackers to load any file on a website, potentially revealing sensitive information or taking control of the site. This is a concern because it could...
8.1
AncoraThemes Impacto Patronus May Download Harmful Files
CVE-2026-22375
A security issue in AncoraThemes Impacto Patronus could allow an attacker to trick the software into downloading and executing any file on the server. This could potentially lead to unauthorized acces...
8.1
AncoraThemes Zio Alberto: Malicious Files Can Be Loaded
CVE-2026-22374
An error in the Zio Alberto theme allows attackers to load and run malicious PHP files, which can compromise your website's security. This is a serious issue that affects versions up to 1.2.2 of the t...
8.1
Fooddy theme allows attackers to read local files
CVE-2026-22373
The Fooddy theme for websites has a security flaw that allows hackers to access and read files on the website's server. This is a concern because it could allow an attacker to access sensitive informa...
8.1
AncoraThemes Isida allows attackers to access local files via PHP code injection
CVE-2026-22372
A security issue in AncoraThemes Isida allows attackers to access and potentially read local files on a website. This could lead to sensitive information being exposed. Update to version 1.4.3 or late...
8.1
AncoraThemes Gustavo gustavo lets attackers read local files
CVE-2026-22371
A vulnerability in Gustavo, a theme for a website platform, allows attackers to access and read sensitive files on the server. This could lead to unauthorized access to confidential information. Updat...
8.1
PHP File Inclusion Flaw in Marveland Theme Allows Local File Access
CVE-2026-22370
The Marveland theme for PHP has a flaw that allows an attacker to access and potentially read sensitive files on the server. This could lead to unauthorized data exposure and other security issues. Up...
8.1
AncoraThemes Ironfit allows attackers to access sensitive files
CVE-2026-22369
An outdated version of AncoraThemes Ironfit allows hackers to access files on your server, potentially exposing sensitive information. This can happen if you're running a vulnerable version of Ironfit...
8.1
Redy PHP files can access local files on your server
CVE-2026-22368
A security issue in Redy allows an attacker to access and potentially read sensitive local files on your server. This can happen if an attacker tricks the system into including a malicious local file....
8.1
AncoraThemes Coworking: Malicious Files Can Be Loaded from Local Directory
CVE-2026-22367
A security issue in AncoraThemes Coworking allows hackers to load and execute local files on your website. This means that if someone gains unauthorized access, they could potentially read or modify s...
8.1
Axiomthemes Jude allows hackers to access local files on your server
CVE-2026-22366
A vulnerability in Axiomthemes Jude allows hackers to access local files on your server, which could lead to sensitive information being stolen or malicious code being executed. This affects versions ...
8.1
SevenTrees PHP Software Allows Access to Local Files
CVE-2026-22364
A security issue in SevenTrees, a PHP-based software, allows an attacker to access and potentially read local files. This is a concern because sensitive data could be exposed. Users should update to t...
8.1
Rhodos File Inclusion Flaw: Malicious Files Can be Loaded
CVE-2026-22363
A critical issue in Rhodos, a website builder, allows attackers to load malicious files from the local system. This means a hacker can potentially access and exploit sensitive data. Update to version ...
8.1
Photolia allows attackers to access local files through a malicious PHP file
CVE-2026-22362
Photolia has a security issue that allows an attacker to access sensitive local files on a website. This is a concern because it could allow unauthorized access to confidential data. Axiomthemes recom...
8.1
A-Mart E-commerce Platform Allows Access to Local Files
CVE-2026-22361
A-Mart's e-commerce platform has a security weakness that allows hackers to access and potentially view sensitive files on the same server. This is a concern because it could allow an attacker to stea...
8.1
Mikado-Themes FiveStar: Malicious Files Can Be Loaded from Server
CVE-2026-22344
The FiveStar plugin from Mikado-Themes allows attackers to load any file from the server, potentially revealing sensitive information or allowing unauthorized access. This issue affects versions of th...
8.1
EnOcean SmartServer IoT 4.60.009 and prior: Remote Code Execution
CVE-2026-20761
Attackers can send malicious messages to EnOcean SmartServer IoT devices, potentially allowing them to run unauthorized commands on the device. This could lead to unauthorized access or disruption of ...
8.1
Belletrist Theme Can Access Local Files
CVE-2025-69410
The Belletrist theme for WordPress allows an attacker to access any file on the website, potentially revealing sensitive information or allowing them to make unauthorized changes. This issue affects v...
8.1
Axiomthemes PJ | Life & Business Coaching allows Malicious File Access
CVE-2025-69409
A vulnerability in the Axiomthemes PJ | Life & Business Coaching website allows an attacker to access and potentially view sensitive files on the server. This is a security risk because it could allow...
8.1
Mikado-Themes HealthFirst allows attackers to read local files
CVE-2025-69408
The HealthFirst plugin from Mikado-Themes has a security issue that allows hackers to access and read files on your website. This is a concern because it could lead to sensitive information being stol...
8.1
Struktur Themes Allows Attackers to Access Local Files via Malicious URLs
CVE-2025-69407
Struktur, a popular theme for websites, contains a security flaw that allows hackers to access sensitive files on your server. This means that if you're using an affected version, attackers could pote...
8.1
FreightCo ThemeREX allows hackers to access local files
CVE-2025-69406
A security issue in FreightCo's ThemeREX allows unauthorized access to local files on a website, potentially exposing sensitive information. This affects websites using FreightCo ThemeREX version 1.1....
8.1
ThemeREX R&F rf Allows Malicious File Access on Server
CVE-2025-69402
A security flaw in ThemeREX R&F rf allows hackers to access and read local files on your server. This could lead to sensitive information being stolen or your website being compromised. To fix this, u...
8.1