2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12754MEDIUM6.4The Geopost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter of the 'geopost...
CVE-2025-12753MEDIUM6.4The Chart Expert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pmzez_chart' shortcode in al...
CVE-2025-12711MEDIUM6.4The Share to Google Classroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the share_to_google ...
CVE-2025-12672MEDIUM6.4The Flickr Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'div_height' parameter of the ...
CVE-2025-12671MEDIUM6.4The WP-Iconics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_icon...
CVE-2025-12668MEDIUM6.4The WP Count Down Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the...
CVE-2025-12667MEDIUM6.4The GitHub Gist Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of th...
CVE-2025-12665MEDIUM4.3The Ninja Countdown | Fastest Countdown Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a...
CVE-2025-12663MEDIUM6.4The Jeba Cute forkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' parameter in the '...
CVE-2025-12662MEDIUM6.4The Coon Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter in the...
CVE-2025-12658MEDIUM6.4The Preload Current Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'complete' paramete...
CVE-2025-12652MEDIUM6.4The Ungapped Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prefillvalues' parameter...
CVE-2025-12651MEDIUM6.4The Live Photos on WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_src', 'img...
CVE-2025-12644MEDIUM6.4The Nonaki – Drag and Drop Email Template builder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2025-12632MEDIUM5.5The RandomQuotr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ...
CVE-2025-12631MEDIUM4.4The Squirrels Auto Inventory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all...
CVE-2025-12590MEDIUM6.1The YSlider plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versi...
CVE-2025-12589MEDIUM6.1The WP-Walla plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all vers...
CVE-2025-12588MEDIUM4.3The USB Qr Code Scanner For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
CVE-2025-12538MEDIUM4.4The Fleet Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u...
CVE-2025-12526MEDIUM4.3The Private Google Calendars plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca...
CVE-2025-12132MEDIUM4.3The WP Custom Admin Login Page Logo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up ...
CVE-2025-12126MEDIUM5.4The The Total Book Project plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,...
CVE-2025-12021MEDIUM6.1The WP-OAuth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'error_description' parameter ...
CVE-2025-12020MEDIUM4.9The Double the Donation – A workplace giving tool to help your fundraising efforts plugin for WordPress is vulnerable to...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now