2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14835HIGH7.1The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ paramet...
CVE-2025-14804HIGH7.7The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership of the fil...
CVE-2025-14802MEDIUM5.4The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to unauthorized file deletion in versions up to, and i...
CVE-2025-14796MEDIUM6.4The My Album Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image titles in all versions ...
CVE-2025-14792MEDIUM4.4The Key Figures plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the kf_field_figure_default_color_...
CVE-2025-14719MEDIUM4.9The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and es...
CVE-2025-14631MEDIUM6.5A NULL Pointer Dereference vulnerability in TP-Link Archer BE400 V1(802.11 modules) allows  an adjacent attacker to cau...
CVE-2025-14626MEDIUM6.4The QR Code for WooCommerce order emails, PDF invoices, packing slips plugin for WordPress is vulnerable to Stored Cross...
CVE-2025-14625MEDIUM6.7Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard on Windows (Nios II Command Shell module...
CVE-2025-14614MEDIUM6.7Insecure Temporary File vulnerability in Altera Quartus Prime Standard  Installer (SFX) on Windows, Altera Quartus Pr...
CVE-2025-14468MEDIUM4.3The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u...
CVE-2025-14465MEDIUM4.3The Sticky Action Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-14460MEDIUM5.3The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized order status modificatio...
CVE-2025-14453MEDIUM6.4The My Album Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style_css' shortcode att...
CVE-2025-14370MEDIUM4.3The Quote Comments plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0...
CVE-2025-14352MEDIUM5.3The Awesome Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to incorrect autho...
CVE-2025-14147MEDIUM6.4The Easy GitHub Gist Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter...
CVE-2025-14145MEDIUM6.4The Niche Hero | Beautifully-designed blocks in seconds plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2025-14144MEDIUM6.4The Mstoic Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'start' parameter of the...
CVE-2025-14131MEDIUM6.1The WP Widget Changer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']...
CVE-2025-14130MEDIUM6.1The Post Like Dislike plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']...
CVE-2025-14128MEDIUM6.1The Stumble! for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_S...
CVE-2025-14127MEDIUM6.1The Testimonial Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF'...
CVE-2025-14122MEDIUM6.4The AD Sliding FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliding_faq' shortcode in ...
CVE-2025-14121MEDIUM6.4The EDD Download Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'edd_download_info_link'...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now