2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14071HIGH7.5The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all ver...
CVE-2025-14054MEDIUM4.4The WC Builder – WooCommerce Page Builder for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2025-14043MEDIUM5.3The Tainacan plugin for WordPress is vulnerable to unauthorized metadata section creation due to missing authorization c...
CVE-2025-13838MEDIUM6.4The WishSuite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter of the '...
CVE-2025-12980HIGH7.5The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthor...
CVE-2025-11496MEDIUM6.1The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2025-14989CRITICAL9.8A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This issue affects some...
CVE-2025-14597——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-12700——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-34290HIGH7.8Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerabili...
CVE-2025-7782HIGH7.6The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to unauthorized modification of data due...
CVE-2025-7733MEDIUM4.3The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Insecure Direct Object Reference in a...
CVE-2025-14298MEDIUM5.4The FiboSearch – Ajax Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p...
CVE-2025-12492MEDIUM5.3The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2025-13619CRITICAL9.8The Flex Store Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1....
CVE-2025-12820MEDIUM5.3The Pure WC Variation Swatches WordPress plugin through 1.1.7 does not have an authorization check when updating its set...
CVE-2025-14735MEDIUM4.4The "Amazon affiliate lite Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings ...
CVE-2025-14734MEDIUM5.4The Amazon affiliate lite Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-14721MEDIUM5.5The Responsive and Swipe slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rsSli...
CVE-2025-14633MEDIUM5.3The F70 Lead Document Download plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi...
CVE-2025-14591HIGH7.5In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windo...
CVE-2025-14168MEDIUM4.3The WP DB Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-14164MEDIUM4.3The Quran Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-13624MEDIUM6.1The Overstock Affiliate Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PH...
CVE-2025-13365MEDIUM6.1The WP Hallo Welt plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now