Application Security Detections Published in February 2026

Hitesh Kadu

Table of Contents

In February, Qualys TotalAppSec released QIDs targeting vulnerabilities in several widely used software products and frameworks, including:

Axios, Fabric.js, OpenSSL, ClipBucket, Atlassian, Jenkins, SolarWinds, Laravel, WordPress, Apache, Ivanti, Moodle, MLflow, vLLM, Grafana, N8n, Fortinet, React Native Community, pgAdmin, GitLab, Apache Airflow, Apache Hadoop, Apache Druid, Apache HertzBeat, Zohocorp, Dify, Roundcube, SAP, Oracle, BentoML, Cisco, BeyondTrust, Zimbra, MCPJam, Splunk, Alfresco, EasyCVR, Apigee, Axway, Ambassador, Couchbase, FreshRSS, Jeecg Boot, Seafile, Strapi, Tolgee, and Langflow

Details about the following QIDs can be found in our knowledge base. Please review reports of the scanned applications for these detections and, if any are identified, follow the steps provided in the knowledge base to ensure applications are protected against the reported vulnerabilities. Immediate resolution of these vulnerabilities as soon as they are detected should be a priority for all organizations. If not addressed, these vulnerabilities can pose security risks, such as breaches, unauthorized access, and various malicious activities. QID

QIDTitle
151079Axios Denial of Service (DoS) Vulnerability (CVE-2026-25639)
151080Fabric.js Cross Site Scripting (XSS) Vulnerability (CVE-2026-27013)
520102Open Secure Sockets Layer (OpenSSL) Denial of Service (DoS) Vulnerabilities (CVE-2025-15468, CVE-2025-66199)
520103Open Secure Sockets Layer (OpenSSL) dgst Input Truncation Vulnerability (CVE-2025-15469)
520104Open Secure Sockets Layer (OpenSSL) Denial of Service (DoS) Vulnerabilities (CVE-2025-68160, CVE-2025-69421, CVE-2026-22796)
520105ClipBucket V5 Blind SQL Injection Vulnerability (CVE-2026-21875)
520106Open Secure Sockets Layer (OpenSSL) Denial of Service (DoS) Vulnerabilities (CVE-2025-69419, CVE-2025-69420, CVE-2026-22795)
520107Open Secure Sockets Layer (OpenSSL) OCB Partial Block Encryption Vulnerability (CVE-2025-69418)
520108Atlassian Crowd Data Center and Server XML External Entity Injection (XXE) Vulnerability (CVE-2026-21569)
520109ClipBucket V5 Remote Code Execution Vulnerability (CVE-2026-25728)
520110ClipBucket V5 Server-Side Request Forgery Vulnerability (CVE-2026-26005)
520111Jenkins Core Stored Cross-site Scripting (XSS) Vulnerability (CVE-2026-27099)
520112Jenkins Core Build Information Disclosure Vulnerability (CVE-2026-27100)
520113SolarWinds Serv-U Broken Access Control Remote Code Execution Vulnerability (CVE-2025-40538)
520114SolarWinds Serv-U Type Confusion Remote Code Execution Vulnerabilities (CVE-2025-40539, CVE-2025-40540)
520115SolarWinds Serv-U IDOR Remote Code Execution Vulnerability (CVE-2025-40541)
530825Laravel Bagisto Missing Authentication Vulnerability (CVE-2026-21446)
530852WordPress Aora Theme: Local File Inclusion Vulnerability (CVE-2025-68985)
530853WordPress Academy LMS Plugin: Account Takeover Vulnerability (CVE-2025-15521)
530854WordPress Membership Plugin: Missing Authentication Vulnerability (CVE-2025-14844)
530855WordPress ACF Extended Plugin: Privilege Escalation Vulnerability (CVE-2025-14533)
530856WordPress Dokan Lite Plugin: Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2025-14977)
530863Apache bRPC Command Injection Vulnerability (CVE-2025-60021)
530864WordPress Creator LMS Plugin: Missing Authorization Vulnerability (CVE-2025-15347)
530865WordPress NotificationX Plugin: Cross-Site Scripting Vulnerability (CVE-2025-15380)
530866WordPress Nexter Extension Plugin: PHP Object Injection Vulnerability (CVE-2026-0726)
530874WordPress LA-Studio Element Kit Plugin: Privilege Escalation Vulnerability (CVE-2026-0920)
530875WordPress Demo Importer Plus Plugin: XML External Entity Injection (XXE) Vulnerability (CVE-2025-14478)
530876WordPress Hustle Plugin: Arbitrary File Upload Vulnerability (CVE-2026-0911)
530879WordPress Frontis Blocks Plugin: Server-Side Request Forgery (SSRF) Vulnerability (CVE-2026-0807)
530880WordPress User Submitted Posts Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-0800)
530885WordPress Melapress Role Editor Plugin: Privilege Escalation Vulnerability (CVE-2025-14866)
530886WordPress Kalrav AI Agent Plugin: Arbitrary File Upload Vulnerability (CVE-2025-13374)
530887WordPress LazyTasks Plugin: Privilege Escalation Vulnerability (CVE-2025-68869)
530890Ivanti Endpoint Manager Mobile (EPMM) Remote Code Execution (RCE) Vulnerabilities (CVE-2026-1281, CVE-2026-1340)
530891WordPress Snow Monkey Forms Plugin: Arbitrary File Deletion Vulnerability (CVE-2026-1056)
530892WordPress Prowess Theme: Local File Inclusion Vulnerability (CVE-2026-24531)
530893Moodle Remote Code Execution (RCE) Vulnerability (CVE-2025-67847)
530894WordPress Simple User Registration Plugin: Privilege Escalation Vulnerability (CVE-2026-0844)
530895WordPress Search Atlas SEO Plugin: Authentication Bypass Vulnerability (CVE-2025-14386)
530896MLflow Remote Code Execution (RCE) Vulnerability (CVE-2025-10279)
530897WordPress BuddyPress Plugin: Arbitrary Shortcode Execution Vulnerability (CVE-2024-11976)
530898WordPress Omnipress Plugin: Local File Inclusion Vulnerability (CVE-2026-24538)
530899vLLM Remote Code Execution (RCE) Vulnerability (CVE-2026-22778)
530900ClipBucket V5 Default Credentials
530901Apache Syncope Reflected Cross-Site Scripting Vulnerability (CVE-2026-23794)
530902WordPress WP FOFT Loader Plugin: Arbitrary File Upload Vulnerability (CVE-2026-1756)
530903Grafana Privilege Escalation Vulnerability (CVE-2026-21721)
530904Apache Syncope XML External Entity Vulnerability (CVE-2026-23795)
530905SolarWinds Web Help Desk Remote Code Execution (RCE) Vulnerability (CVE-2025-40551)
530906WordPress Gyan Elements Plugin: Local File Inclusion Vulnerability (CVE-2026-23978)
530907Grafana Denial of Service (DoS) Vulnerability (CVE-2026-21720)
530908SolarWinds Web Help Desk Hardcoded Credentials Vulnerability (CVE-2025-40537)
530909N8n Python Sandbox Escape Vulnerability (CVE-2026-25115)
530910Apache StreamPark Weak Encryption Algorithm Vulnerability (CVE-2025-54981)
530911WordPress Tutor LMS Plugin: Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2026-1375)
530912WordPress OS DataHub Maps Plugin: Arbitrary File Upload Vulnerability (CVE-2026-1730)
530913N8n Command Execution Vulnerability (CVE-2026-25049)
530914WordPress WP Duplicate Plugin: Missing Authorization Vulnerability (CVE-2026-1499)
530915WordPress JAY Login and Register Plugin: Privilege Escalation Vulnerabilities (CVE-2025-15100, CVE-2025-15027)
530916FortiClientEMS SQL Injection Vulnerability (CVE-2026-21643)
530917WordPress Popup Builder Block Plugin: SQL Injection Vulnerability (CVE-2025-13192)
530918SolarWinds Web Help Desk Authentication Bypass Vulnerabilities (CVE-2025-40552, CVE-2025-40554)
530919SolarWinds Web Help Desk Deserialization Remote Code Execution Vulnerability (CVE-2025-40553)
530920WordPress SportsPress Plugin: Local File Inclusion Vulnerability (CVE-2025-15368)
530921React Native Community CLI OS Command Injection Vulnerability (CVE-2025-11953)
530922Fortinet FortiOS LDAP Authentication Bypass Vulnerability (CVE-2026-22153)
530923pgAdmin Secret Key Disclosure Vulnerability (CVE-2026-1707)
530924WordPress Golo Theme: Local File Inclusion Vulnerability (CVE-2026-23975)
530925WordPress WPvivid Backup Restore Plugin: Arbitrary File Upload Vulnerability (CVE-2026-1357)
530926GitLab CE/EE Incomplete Validation Vulnerability (CVE-2025-7659)
530927GitLab CE/EE Denial of Service Vulnerability (CVE-2025-8099)
530928Apache Airflow DAG Import Error Information Disclosure Vulnerability (CVE-2026-24098)
530929Apache Airflow Task Log Authorization Bypass Vulnerability (CVE-2026-22922)
530930WordPress Ninja Forms Plugin: Information Disclosure Vulnerability (CVE-2026-2268)
530931Apache Hadoop Out-of-bounds Write Vulnerability (CVE-2025-27821)
530932Apache Druid Authentication Bypass Vulnerability (CVE-2026-23906)
530933Apache HertzBeat XPath Injection Vulnerability (CVE-2026-24343)
530934GitLab CE/EE Denial of Service Vulnerability (CVE-2026-0958)
530935Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability (CVE-2026-1602)
530936Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability (CVE-2026-1603)
530937WordPress WC Frontend Manager Plugin: Missing Authorization Vulnerability (CVE-2026-0845)
530938WordPress Name Directory Plugin: Cross-Site Scripting (XSS) Vulnerability (CVE-2026-1866)
530939GitLab CE/EE Cross-Site Scripting Vulnerability (CVE-2025-14560)
530940GitLab CE/EE HTML Injection Vulnerability (CVE-2026-0595)
530941Zohocorp ManageEngine ADSelfService Plus Account Takeover Vulnerability (CVE-2025-1723)
530942Dify Cross-Site Scripting (XSS) Vulnerability (CVE-2026-26023)
530943Roundcube Webmail Improper Remote Image Blocking Vulnerability (CVE-2026-25916)
530944Roundcube Webmail CSS Injection Vulnerability (CVE-2026-26079)
530945WordPress AdForest Theme: Authentication Bypass Vulnerability (CVE-2026-1729)
530946GitLab CE/EE Denial of Service Vulnerability (CVE-2026-1458)
530947GitLab CE/EE Denial of Service Vulnerability (CVE-2026-1456)
530948WordPress CleanTalk Spam Protect Plugin: Authorization Bypass Vulnerability (CVE-2026-1490)
530949GitLab EE Denial of Service Vulnerability (CVE-2026-1387)
530950GitLab EE Server-Side Request Forgery Vulnerability (CVE-2025-12575)
530951WordPress MIDI-Synth Plugin: Arbitrary File Upload Vulnerability (CVE-2026-1306)
530952WordPress WowRevenue Plugin: Missing Authorization Vulnerability (CVE-2026-2001)
530953GitLab CE/EE Improper Validation Vulnerability (CVE-2026-1094)
530954GitLab CE/EE Server-Side Request Forgery Vulnerability (CVE-2025-12073)
530955GitLab EE Authorization Bypass Vulnerability (CVE-2026-1080)
530956WordPress WpForo Forum Plugin: PHP Object Injection Vulnerability (CVE-2026-0910)
530957WordPress Lazy Blocks Plugin: Remote Code Execution (RCE) Vulnerability (CVE-2026-1560)
530958BeyondTrust Privileged Remote Access (PRA) Remote Code Execution (RCE) Vulnerability (CVE-2026-1731)
530959Zimbra Server-Side Request Forgery (SSRF) Vulnerability (CVE-2020-7796)
530960WordPress Videospire Core Theme: Privilege Escalation Vulnerability (CVE-2025-15096)
530961WordPress FastDup Plugin: Missing Authorization Vulnerability (CVE-2026-1104)
530962WordPress Ecwid Shopping Cart Plugin: Privilege Escalation Vulnerability (CVE-2026-1750)
530963MCPJam Inspector Remote Code Execution Vulnerability (CVE-2026-23744)
530964Apache Tomcat HTTP/0.9 Security Constraint Bypass Vulnerability (CVE-2026-24733)
530965Apache Tomcat OCSP Validation Bypass Vulnerability (CVE-2026-24734)
530966Apache Tomcat Client Certificate Bypass Vulnerability (CVE-2025-66614)
530967WordPress Lucky Wheel Giveaway Plugin: Remote Code Execution (RCE) Vulnerability (CVE-2025-14541)
530968WordPress Starfish Reviews Plugin: Missing Authorization Vulnerability (CVE-2025-15157)
530969Zohocorp ManageEngine ADSelfService Plus SQL Injection Vulnerability (CVE-2026-1367)
530970Splunk Enterprise/Cloud Platform Path Traversal Vulnerability (CVE-2026-20137)
530971Splunk Enterprise/Cloud Platform Denial of Service Vulnerability (CVE-2026-20139)
530972WordPress YayMail Plugin: Missing Authorization Vulnerability (CVE-2026-1937)
530973WordPress Lizza LMS Pro Plugin: Privilege Escalation Vulnerability (CVE-2025-13563)
530974WordPress ElementsKit Lite Plugin: Missing Authentication Vulnerability (CVE-2026-23693)
530975WordPress Slider Future Plugin: Arbitrary File Upload Vulnerability (CVE-2026-1405)
530976Splunk Enterprise Sensitive Information Disclosure Vulnerability (CVE-2026-20138)
530977Splunk Enterprise Improper Access Control Vulnerability (CVE-2026-20141)
530978Splunk Enterprise/Cloud Platform Sensitive Information Disclosure Vulnerability (CVE-2026-20144)
580908Business Logic Flaw in Subscription Duration Validation
580909Privilege Escalation Through Access Tier Manipulation
580910Referral Program Abuse via Referral Code Reuse
580911Alfresco CMS Detection
580912EasyCVR Information Disclosure Vulnerability (CVE-2025-1595)
580913Apigee Login Panel Detected
580914Axway API Manager Panel Detected
580915BeyondTrust Privileged Access Management Detected
580916Ambassador API Gateway Diagnostics Exposure
580917SOAP-based ASP.NET Web Services Collection Detected
580918AsyncAPI Spec Inventory Detected
580919Couchbase Buckets Unauthenticated REST API Detected
580920FreshRSS Google Reader API Exposure
580921FreshRSS Fever API Exposure
580922Jeecg Boot Swagger Bootstrap UI Detected
580923Redfish API Detected
580924Seafile API Detected
580925Strapi API Detected
580926Tolgee API Detected
580927Langflow AI CORS Misconfiguration Vulnerability (CVE-2025-34291)

What’s Next

Leverage the QID list to guide your remediation efforts and strengthen your risk posture.

Looking for more context or remediation tips? Head to Qualys KnowledgeBase for detailed analysis, actionable guidance, and expert-backed support.

Share your Comments

Comments

Your email address will not be published. Required fields are marked *