2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14128 | MEDIUM | 6.1 | 0.3% | Jan 7, 2026 | The Stumble! for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_S... |
| CVE-2025-14127 | MEDIUM | 6.1 | 0.3% | Jan 7, 2026 | The Testimonial Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF'... |
| CVE-2025-14122 | MEDIUM | 6.4 | 0.3% | Jan 7, 2026 | The AD Sliding FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliding_faq' shortcode in ... |
| CVE-2025-14121 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The EDD Download Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'edd_download_info_link'... |
| CVE-2025-14118 | MEDIUM | 6.1 | 0.3% | Jan 7, 2026 | The Starred Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the PHP_SELF variable in all... |
| CVE-2025-14114 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The 1180px Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attrib... |
| CVE-2025-14113 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Viitor Button Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' shortcode ... |
| CVE-2025-14112 | MEDIUM | 6.4 | 0.3% | Jan 7, 2026 | The Snillrik Restaurant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'menu_style' shortcode... |
| CVE-2025-14110 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The WP Js List Pages Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortc... |
| CVE-2025-14109 | MEDIUM | 6.4 | 0.3% | Jan 7, 2026 | The AH Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'column' shortcode attribute... |
| CVE-2025-14077 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The Simcast plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0... |
| CVE-2025-14070 | HIGH | 7.5 | 0.4% | Jan 7, 2026 | The Reviewify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ... |
| CVE-2025-14059 | MEDIUM | 6.5 | 0.2% | Jan 7, 2026 | The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and inc... |
| CVE-2025-14057 | MEDIUM | 4.4 | 0.3% | Jan 7, 2026 | The Multi-column Tag Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver... |
| CVE-2025-14053 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Wish To Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all version... |
| CVE-2025-14028 | MEDIUM | 4.4 | 0.3% | Jan 7, 2026 | The Contact Us Simple Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v... |
| CVE-2025-13990 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The Mamurjor Employee Info plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2025-13974 | MEDIUM | 4.4 | 0.3% | Jan 7, 2026 | The Email Customizer for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email templat... |
| CVE-2025-13887 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The AI BotKit – AI Chatbot & Live Support for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2025-13849 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Cool YT Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'videoid' parameter in all ... |
| CVE-2025-13848 | MEDIUM | 6.4 | 0.3% | Jan 7, 2026 | The STM Gallery 1.9 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'composicion' parameter in... |
| CVE-2025-13847 | MEDIUM | 6.4 | 0.3% | Jan 7, 2026 | The PhotoFade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'time' parameter in all versions... |
| CVE-2025-13841 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Smart App Banners plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' and 'verticalalig... |
| CVE-2025-13801 | HIGH | 7.5 | 1.7% | Jan 7, 2026 | The Yoco Payments plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.9.0 via t... |
| CVE-2025-13722 | MEDIUM | 5.3 | 0.2% | Jan 7, 2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now