2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14137 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | The Simple AL Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']`... |
| CVE-2025-14132 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | The Category Dropdown List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_S... |
| CVE-2025-14129 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | The Like DisLike Voting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF... |
| CVE-2025-14125 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | The Complag plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable... |
| CVE-2025-14119 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The App Landing Template Blocks for WPBakery (Visual Composer) Page Builder plugin for WordPress is vulnerable to Stored... |
| CVE-2025-14064 | MEDIUM | 5.4 | 0.2% | Dec 12, 2025 | The BuddyTask plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capabi... |
| CVE-2025-14062 | MEDIUM | 4.3 | 0.1% | Dec 12, 2025 | The Animated Pixel Marquee Creator plugin for WordPress is vulnerable to Cross-Site Request Forgery via the 'marquee' pa... |
| CVE-2025-14048 | MEDIUM | 4.4 | 0.2% | Dec 12, 2025 | The SimplyConvert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'simplyconvert_hash' option ... |
| CVE-2025-14045 | MEDIUM | 4.3 | 0.2% | Dec 12, 2025 | The URL Media Uploader plugin for WordPress is vulnerable to unauthorized safe file uploads due to a missing capability ... |
| CVE-2025-14035 | MEDIUM | 4.4 | 0.3% | Dec 12, 2025 | The DebateMaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color options in the plugin s... |
| CVE-2025-14032 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in th... |
| CVE-2025-13989 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The WP Dropzone plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'callback' shortcode attribute... |
| CVE-2025-13988 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | The 评论小秘书 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable i... |
| CVE-2025-13987 | MEDIUM | 4.3 | 0.1% | Dec 12, 2025 | The Purchase and Expense Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2025-13975 | MEDIUM | 4.4 | 0.2% | Dec 12, 2025 | The Contact Form 7 with ChatWork plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_token' a... |
| CVE-2025-13972 | MEDIUM | 4.9 | 0.4% | Dec 12, 2025 | The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file read via the 'wht_download_big_object_origin' para... |
| CVE-2025-13971 | MEDIUM | 4.4 | 0.2% | Dec 12, 2025 | The TWW Protein Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Header' setting in... |
| CVE-2025-13969 | MEDIUM | 6.4 | 0.3% | Dec 12, 2025 | The Reviews Sorted plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'space' parameter of the [r... |
| CVE-2025-13966 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Paypal Payment Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'buttom_image' pa... |
| CVE-2025-13963 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The FX Currency Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fxcc_conve... |
| CVE-2025-13962 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Divelogs Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'latestdive' shor... |
| CVE-2025-13961 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Data Visualizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'visualize' short... |
| CVE-2025-13960 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The GPXpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gpxpress' shortcode in ... |
| CVE-2025-13906 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The WP Flot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linechart' shortcode in ... |
| CVE-2025-13904 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The WPGancio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gancio-event' shortcode... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now