Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,589
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,841 - 10,860 of 13,241 CVEs
CVE-2026-25326 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows PHP Local File Inclusion.This issue affects CMSMasters Content Composer: from n/a through <=...

Vendor: cmsmasters
Product: CMSMasters Content Composer
Published: Feb 19, 2026
Source: NVD
CVE-2026-25316 HIGH - 7.2

Deserialization of Untrusted Data vulnerability in Brainstorm Force CartFlows cartflows allows Object Injection.This issue affects CartFlows: from n/a through <= 2.1.19.

Vendor: Brainstorm Force
Product: CartFlows
Published: Feb 19, 2026
Source: NVD
CVE-2026-23805 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yoren Chang Media Search Enhanced media-search-enhanced allows SQL Injection.This issue affects Media Search Enhanced: from n/a through <= 0.9.1.

Vendor: Yoren Chang
Product: Media Search Enhanced
Published: Feb 19, 2026
Source: NVD
CVE-2026-23547 HIGH - 7.1

Missing Authorization vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CMSMasters Content Composer: from n/a through <= 2.5.8.

Vendor: cmsmasters
Product: CMSMasters Content Composer
Published: Feb 19, 2026
Source: NVD
CVE-2026-23544 HIGH - 8.8

Deserialization of Untrusted Data vulnerability in codetipi Valenti valenti allows Object Injection.This issue affects Valenti: from n/a through <= 5.6.3.5.

Vendor: codetipi
Product: Valenti
Published: Feb 19, 2026
Source: NVD
CVE-2026-22333 HIGH - 7.2

Deserialization of Untrusted Data vulnerability in YITHEMES YITH WooCommerce Compare yith-woocommerce-compare allows Object Injection.This issue affects YITH WooCommerce Compare: from n/a through <= 3.6.0.

Vendor: YITHEMES
Product: YITH WooCommerce Compare
Published: Feb 19, 2026
Source: NVD
CVE-2026-2691 HIGH - 7.3

A vulnerability has been found in itsourcecode Event Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/manage_register.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been dis...

Vendor: admerc
Product: event_management_system
Published: Feb 19, 2026
Source: NVD
CVE-2026-2690 HIGH - 7.3

A flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login of the component Admin Login. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack ...

Vendor: admerc
Product: event_management_system
Published: Feb 19, 2026
Source: NVD
CVE-2026-2689 HIGH - 7.3

A vulnerability was detected in itsourcecode Event Management System 1.0. Affected is an unknown function of the file /admin/manage_booking.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.

Vendor: admerc
Product: event_management_system
Published: Feb 19, 2026
Source: NVD
CVE-2026-0974 HIGH - 8.8

The Orderable โ€“ WordPress Restaurant Online Ordering System and Food Ordering Plugin plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the 'install_plugin' function in all versions up to, and including, 1.20.0. This makes it possibl...

Published: Feb 19, 2026
Source: NVD
CVE-2026-0912 HIGH - 8.8

The Toret Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'trman_save_option' function and on the 'trman_save_option_items' in all versions up to, and including, 1.2.7. ...

Published: Feb 19, 2026
Source: NVD
CVE-2025-4960 HIGH - 7.8

The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege escalation vulnerability due to multiple flaws in its implementation. It fails to properly authenticate clients over the XPC protocol and does not correctly enforce macOSโ€™s authorizati...

Published: Feb 19, 2026
Source: NVD
CVE-2025-4521 HIGH - 8.8

The IDonate โ€“ Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the idonate_donor_profile() function in versions 2.1.5 to 2.1.9. This makes it possible for authenticated attackers, with Subscriber-level...

Published: Feb 19, 2026
Source: NVD
CVE-2025-15041 HIGH - 7.2

The BackWPup โ€“ WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the save_site_option() function in all versions up to, and including, 5.6.2. This makes it possible ...

Vendor: wp_media
Product: BackWPup โ€“ WordPress Backup & Restore Plugin
Published: Feb 19, 2026
Source: NVD
CVE-2025-14452 HIGH - 7.2

The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to injec...

Vendor: bompus
Product: WP Customer Reviews
Published: Feb 19, 2026
Source: NVD
CVE-2025-13603 HIGH - 8.8

The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and including, 2.0. This is due to insufficient capability checks and lack of nonce verification on the "wpag_htaccess_callback" function This makes it possible for authentica...

Vendor: husainali52
Product: WP AUDIO GALLERY
Published: Feb 19, 2026
Source: NVD
CVE-2025-12975 HIGH - 7.2

The CTX Feed โ€“ WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the woo_feed_plugin_installing() function in all versions up to, and including, 6.6.11. This makes it possible for authenticated attac...

Vendor: wahid0003
Product: Product Feed Manager for WooCommerce โ€“ CTX Feed โ€“ Support 220+ Shopping & Social Channels
Published: Feb 19, 2026
Source: NVD
CVE-2025-12845 HIGH - 8.8

The Tablesome Table โ€“ Contact Form DB โ€“ WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to unauthorized access of data that leads to privilege escalation due to a missing capability check on the get_table_data() function in versions 0.5.4 to 1.2.1. This makes it possible...

Vendor: essekia
Product: Tablesome Table โ€“ Contact Form DB โ€“ WPForms, CF7, Gravity, Forminator, Fluent
Published: Feb 19, 2026
Source: NVD
CVE-2025-12821 HIGH - 8.8

The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.6.1. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary fi...

Vendor: spicethemes
Product: NewsBlogger
Published: Feb 19, 2026
Source: NVD
CVE-2025-12707 HIGH - 7.5

The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all versions up to, and including, 3.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it pos...

Vendor: owthub
Product: Library Management System
Published: Feb 19, 2026
Source: NVD