2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12754 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Geopost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter of the 'geopost... |
| CVE-2025-12753 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Chart Expert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pmzez_chart' shortcode in al... |
| CVE-2025-12711 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Share to Google Classroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the share_to_google ... |
| CVE-2025-12672 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Flickr Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'div_height' parameter of the ... |
| CVE-2025-12671 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The WP-Iconics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_icon... |
| CVE-2025-12668 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The WP Count Down Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the... |
| CVE-2025-12667 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The GitHub Gist Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of th... |
| CVE-2025-12665 | MEDIUM | 4.3 | 0.2% | Nov 11, 2025 | The Ninja Countdown | Fastest Countdown Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a... |
| CVE-2025-12663 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Jeba Cute forkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' parameter in the '... |
| CVE-2025-12662 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Coon Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter in the... |
| CVE-2025-12658 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Preload Current Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'complete' paramete... |
| CVE-2025-12652 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Ungapped Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prefillvalues' parameter... |
| CVE-2025-12651 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Live Photos on WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_src', 'img... |
| CVE-2025-12644 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Nonaki – Drag and Drop Email Template builder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2025-12632 | MEDIUM | 5.5 | 0.2% | Nov 11, 2025 | The RandomQuotr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ... |
| CVE-2025-12631 | MEDIUM | 4.4 | 0.2% | Nov 11, 2025 | The Squirrels Auto Inventory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all... |
| CVE-2025-12590 | MEDIUM | 6.1 | 0.1% | Nov 11, 2025 | The YSlider plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versi... |
| CVE-2025-12589 | MEDIUM | 6.1 | 0.1% | Nov 11, 2025 | The WP-Walla plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all vers... |
| CVE-2025-12588 | MEDIUM | 4.3 | 0.1% | Nov 11, 2025 | The USB Qr Code Scanner For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions... |
| CVE-2025-12538 | MEDIUM | 4.4 | 0.2% | Nov 11, 2025 | The Fleet Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u... |
| CVE-2025-12526 | MEDIUM | 4.3 | 0.2% | Nov 11, 2025 | The Private Google Calendars plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca... |
| CVE-2025-12132 | MEDIUM | 4.3 | 0.1% | Nov 11, 2025 | The WP Custom Admin Login Page Logo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up ... |
| CVE-2025-12126 | MEDIUM | 5.4 | 0.2% | Nov 11, 2025 | The The Total Book Project plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,... |
| CVE-2025-12021 | MEDIUM | 6.1 | 0.3% | Nov 11, 2025 | The WP-OAuth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'error_description' parameter ... |
| CVE-2025-12020 | MEDIUM | 4.9 | 0.2% | Nov 11, 2025 | The Double the Donation – A workplace giving tool to help your fundraising efforts plugin for WordPress is vulnerable to... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now