Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,607
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,741 - 10,760 of 13,241 CVEs
CVE-2025-69294 HIGH - 8.8

Deserialization of Untrusted Data vulnerability in fuelthemes PeakShops peakshops allows Object Injection.This issue affects PeakShops: from n/a through <= 1.5.9.

Vendor: fuelthemes
Product: PeakShops
Published: Feb 20, 2026
Source: NVD
CVE-2025-69063 HIGH - 8.6

Missing Authorization vulnerability in Saad Iqbal New User Approve new-user-approve allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects New User Approve: from n/a through <= 3.2.0.

Vendor: Saad Iqbal
Product: New User Approve
Published: Feb 20, 2026
Source: NVD
CVE-2025-68880 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in peterwsterling Simple Archive Generator simple-archive-generator allows Reflected XSS.This issue affects Simple Archive Generator: from n/a through <= 5.2.

Vendor: peterwsterling
Product: Simple Archive Generator
Published: Feb 20, 2026
Source: NVD
CVE-2025-68863 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zack Katz iContact for Gravity Forms gravity-forms-icontact allows Reflected XSS.This issue affects iContact for Gravity Forms: from n/a through <= 1.3.2.

Vendor: Zack Katz
Product: iContact for Gravity Forms
Published: Feb 20, 2026
Source: NVD
CVE-2025-68862 HIGH - 7.7

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Murtaza Bhurgri Woo File Dropzone woo-file-dropzone allows Path Traversal.This issue affects Woo File Dropzone: from n/a through <= 1.1.7.

Vendor: Murtaza Bhurgri
Product: Woo File Dropzone
Published: Feb 20, 2026
Source: NVD
CVE-2025-68856 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in keeswolters Mopinion Feedback Form mopinion-feedback-form allows DOM-Based XSS.This issue affects Mopinion Feedback Form: from n/a through <= 1.1.1.

Vendor: keeswolters
Product: Mopinion Feedback Form
Published: Feb 20, 2026
Source: NVD
CVE-2025-68854 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in harman79 ID Arrays id-arrays allows DOM-Based XSS.This issue affects ID Arrays: from n/a through <= 2.1.2.

Vendor: harman79
Product: ID Arrays
Published: Feb 20, 2026
Source: NVD
CVE-2025-68853 HIGH - 8.8

Deserialization of Untrusted Data vulnerability in Kleor Contact Manager contact-manager allows Object Injection.This issue affects Contact Manager: from n/a through <= 9.1.1.

Vendor: Kleor
Product: Contact Manager
Published: Feb 20, 2026
Source: NVD
CVE-2025-68852 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webmuehle Court Reservation court-reservation allows Reflected XSS.This issue affects Court Reservation: from n/a through <= 1.10.9.

Vendor: webmuehle
Product: Court Reservation
Published: Feb 20, 2026
Source: NVD
CVE-2025-68848 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in anmari amr cron manager amr-cron-manager allows Reflected XSS.This issue affects amr cron manager: from n/a through <= 2.3.

Vendor: anmari
Product: amr cron manager
Published: Feb 20, 2026
Source: NVD
CVE-2025-68847 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in itex iSape isape allows Reflected XSS.This issue affects iSape: from n/a through <= 0.72.

Vendor: itex
Product: iSape
Published: Feb 20, 2026
Source: NVD
CVE-2025-68846 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paris Holley Asynchronous Javascript asynchronous-javascript allows Reflected XSS.This issue affects Asynchronous Javascript: from n/a through <= 1.3.5.

Vendor: Paris Holley
Product: Asynchronous Javascript
Published: Feb 20, 2026
Source: NVD
CVE-2025-68845 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aThemeArt Translations eDS Responsive Menu eds-responsive-menu allows Reflected XSS.This issue affects eDS Responsive Menu: from n/a through <= 1.2.

Vendor: aThemeArt Translations
Product: eDS Responsive Menu
Published: Feb 20, 2026
Source: NVD
CVE-2025-68844 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DaleAB Membee Login membees-member-login-widget allows Reflected XSS.This issue affects Membee Login: from n/a through <= 2.3.6.

Vendor: DaleAB
Product: Membee Login
Published: Feb 20, 2026
Source: NVD
CVE-2025-68843 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bas Schuiling FeedWordPress Advanced Filters faf allows Reflected XSS.This issue affects FeedWordPress Advanced Filters: from n/a through <= 0.6.2.

Vendor: Bas Schuiling
Product: FeedWordPress Advanced Filters
Published: Feb 20, 2026
Source: NVD
CVE-2025-68842 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in totalbounty Widget Logic Visual widget-logic-visual allows Reflected XSS.This issue affects Widget Logic Visual: from n/a through <= 1.52.

Vendor: totalbounty
Product: Widget Logic Visual
Published: Feb 20, 2026
Source: NVD
CVE-2025-68841 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themepul TopperPack โ€“ Complete Elementor Addons, Theme &amp; CPT Builder topper-pack allows PHP Local File Inclusion.This issue affects TopperPack โ€“ Complete Element...

Vendor: Themepul
Product: TopperPack โ€“ Complete Elementor Addons, Theme &amp; CPT Builder
Published: Feb 20, 2026
Source: NVD
CVE-2025-68543 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Diza diza allows PHP Local File Inclusion.This issue affects Diza: from n/a through <= 1.3.15.

Vendor: thembay
Product: Diza
Published: Feb 20, 2026
Source: NVD
CVE-2025-68539 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Fana fana allows PHP Local File Inclusion.This issue affects Fana: from n/a through <= 1.1.35.

Vendor: thembay
Product: Fana
Published: Feb 20, 2026
Source: NVD
CVE-2025-68536 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Zota zota allows PHP Local File Inclusion.This issue affects Zota: from n/a through <= 1.3.14.

Vendor: thembay
Product: Zota
Published: Feb 20, 2026
Source: NVD