2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14875 | MEDIUM | 6.1 | 0.2% | Jan 7, 2026 | The HBLPAY Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ... |
| CVE-2025-14867 | MEDIUM | 6.5 | 0.3% | Jan 7, 2026 | The Flashcard plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.9 via the 'so... |
| CVE-2025-14845 | MEDIUM | 4.3 | 0.2% | Jan 7, 2026 | The NS IE Compatibility Fixer plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up... |
| CVE-2025-14842 | MEDIUM | 6.1 | 0.4% | Jan 7, 2026 | The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited upload of files wi... |
| CVE-2025-14835 | HIGH | 7.1 | 0.3% | Jan 7, 2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ paramet... |
| CVE-2025-14804 | HIGH | 7.7 | 0.2% | Jan 7, 2026 | The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership of the fil... |
| CVE-2025-14802 | MEDIUM | 5.4 | 0.3% | Jan 7, 2026 | The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to unauthorized file deletion in versions up to, and i... |
| CVE-2025-14796 | MEDIUM | 6.4 | 0.3% | Jan 7, 2026 | The My Album Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image titles in all versions ... |
| CVE-2025-14792 | MEDIUM | 4.4 | 0.2% | Jan 7, 2026 | The Key Figures plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the kf_field_figure_default_color_... |
| CVE-2025-14719 | MEDIUM | 4.9 | 0.2% | Jan 7, 2026 | The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and es... |
| CVE-2025-14631 | MEDIUM | 6.5 | 0.2% | Jan 7, 2026 | A NULL Pointer Dereference vulnerability in TP-Link Archer BE400 V1(802.11 modules) allows an adjacent attacker to cau... |
| CVE-2025-14626 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The QR Code for WooCommerce order emails, PDF invoices, packing slips plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2025-14625 | MEDIUM | 6.7 | 0.1% | Jan 7, 2026 | Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard on Windows (Nios II Command Shell module... |
| CVE-2025-14614 | MEDIUM | 6.7 | 0.1% | Jan 7, 2026 | Insecure Temporary File vulnerability in Altera Quartus Prime Standard Installer (SFX) on Windows, Altera Quartus Pr... |
| CVE-2025-14468 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u... |
| CVE-2025-14465 | MEDIUM | 4.3 | 0.1% | Jan 7, 2026 | The Sticky Action Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-14460 | MEDIUM | 5.3 | 0.4% | Jan 7, 2026 | The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized order status modificatio... |
| CVE-2025-14453 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The My Album Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style_css' shortcode att... |
| CVE-2025-14370 | MEDIUM | 4.3 | 0.2% | Jan 7, 2026 | The Quote Comments plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0... |
| CVE-2025-14352 | MEDIUM | 5.3 | 0.2% | Jan 7, 2026 | The Awesome Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to incorrect autho... |
| CVE-2025-14147 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Easy GitHub Gist Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter... |
| CVE-2025-14145 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Niche Hero | Beautifully-designed blocks in seconds plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2025-14144 | MEDIUM | 6.4 | 0.2% | Jan 7, 2026 | The Mstoic Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'start' parameter of the... |
| CVE-2025-14131 | MEDIUM | 6.1 | 0.3% | Jan 7, 2026 | The WP Widget Changer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']... |
| CVE-2025-14130 | MEDIUM | 6.1 | 0.3% | Jan 7, 2026 | The Post Like Dislike plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now