2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-11834MEDIUM6.4The WP AD Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'startindex' parameter of th...
CVE-2025-11830MEDIUM6.4The WP Restaurant Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' parameter o...
CVE-2025-11827MEDIUM6.4The Oboxmedia Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_widget' and 'after_w...
CVE-2025-11825MEDIUM6.4The Playerzbr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'urlmeta' post meta field in all...
CVE-2025-11824MEDIUM6.4The Cinza Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cgrid_skin_content' post meta ...
CVE-2025-11819MEDIUM6.4The WP-Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'roboshot' shortcode in all v...
CVE-2025-11818MEDIUM6.4The WP Responsive Meet The Team plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wprm_team' sh...
CVE-2025-11817MEDIUM6.4The Simple Tableau Viz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tableau' shortcode in ...
CVE-2025-11813MEDIUM6.4The Responsive iframe GoogleMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'responsive_ma...
CVE-2025-11811MEDIUM6.4The Simple Youtube Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embed_youtube' s...
CVE-2025-11810MEDIUM6.4The Print Button Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'print-button' shor...
CVE-2025-11809MEDIUM6.4The WP-Force Images Download plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpfid' shortcode...
CVE-2025-11807MEDIUM6.4The Mixlr Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mixlr' shortcode in all v...
CVE-2025-11804MEDIUM6.4The JB News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of...
CVE-2025-10138MEDIUM6.4The This-or-That plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'thisorthat' shortco...
CVE-2025-10047MEDIUM4.9The Email Tracker – Email Log, Email Open Tracking, Email Analytics & Email Management for WordPress Emails plugin for W...
CVE-2025-41720MEDIUM4.3A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserv...
CVE-2025-12033MEDIUM4.4The Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website pl...
CVE-2025-10588MEDIUM4.3The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Cross-Site Request Forger...
CVE-2025-10570MEDIUM4.3The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all ...
CVE-2025-5983MEDIUM6.5The Meta Tag Manager WordPress plugin before 3.3 does not restrict which roles can create http-equiv refresh meta tags.
CVE-2025-10651MEDIUM5.5The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'order_mail' setting in...
CVE-2025-10638MEDIUM5.3The NS Maintenance Mode for WP WordPress plugin through 1.3.1 lacks authorization in its subscriber export function allo...
CVE-2025-22167MEDIUM6.5This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain ...
CVE-2025-62661MEDIUM6.9Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension, Mediawiki - Growth...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now