2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13896MEDIUM6.4The Social Feed Gallery Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' paramet...
CVE-2025-13894MEDIUM6.1The CSV Sumotto plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` vari...
CVE-2025-13863MEDIUM6.4The RevInsite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `token` parameter in all version...
CVE-2025-13857MEDIUM6.4The Yet Another WebClap for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' p...
CVE-2025-13856MEDIUM6.4The Extra Post Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the ex...
CVE-2025-13666MEDIUM5.3The Helloprint plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.2. This...
CVE-2025-13656MEDIUM6.4The Cute News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribu...
CVE-2025-13629MEDIUM4.3The WP Landing Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin...
CVE-2025-13626MEDIUM6.1The myLCO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter ...
CVE-2025-13358MEDIUM5.3The Accessiy By CodeConfig Accessibility plugin for WordPress is vulnerable to unauthorized page creation due to missing...
CVE-2025-13309MEDIUM4.3The Accessiy By CodeConfig Accessibility – Easy One-Click Accessibility Toolbar That Truly Matters plugin for WordPress ...
CVE-2025-13308MEDIUM5.4The Application Passwords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'reject_url' para...
CVE-2025-13137MEDIUM6.1The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to Reflected Cross-Site Script...
CVE-2025-12721MEDIUM5.3The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2025-12720MEDIUM5.3The g-FFL Cockpit plugin for WordPress is vulnerable to unauthorized modification of data due to IP-based authorization ...
CVE-2025-12717MEDIUM6.4The List Attachments Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_list' p...
CVE-2025-12715MEDIUM6.4The Canadian Nutrition Facts Label plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'percentage...
CVE-2025-12577MEDIUM4.3The Listar – Directory Listing & Classifieds WordPress Plugin plugin for WordPress is vulnerable to unauthorized modific...
CVE-2025-12574MEDIUM4.3The Listar – Directory Listing & Classifieds WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of...
CVE-2025-12091MEDIUM4.3The Search, Filters & Merchandising for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of d...
CVE-2025-13922MEDIUM6.5The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based bli...
CVE-2025-12505MEDIUM5.4The weDocs plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.1.14. This ...
CVE-2025-11263MEDIUM6.1The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the type parameter in all...
CVE-2025-66629MEDIUM4.3HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.4, some of HedgeDoc's OA...
CVE-2025-14116MEDIUM4.7A vulnerability was detected in xerrors Yuxi-Know up to 0.4.0. This vulnerability affects the function OtherEmbedding.ae...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now