2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14071 | HIGH | 7.5 | 0.6% | Dec 21, 2025 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all ver... |
| CVE-2025-14054 | MEDIUM | 4.4 | 0.2% | Dec 21, 2025 | The WC Builder – WooCommerce Page Builder for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2025-14043 | MEDIUM | 5.3 | 0.3% | Dec 21, 2025 | The Tainacan plugin for WordPress is vulnerable to unauthorized metadata section creation due to missing authorization c... |
| CVE-2025-13838 | MEDIUM | 6.4 | 0.2% | Dec 21, 2025 | The WishSuite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter of the '... |
| CVE-2025-12980 | HIGH | 7.5 | 0.3% | Dec 21, 2025 | The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthor... |
| CVE-2025-11496 | MEDIUM | 6.1 | 0.2% | Dec 21, 2025 | The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2025-14989 | CRITICAL | 9.8 | 0.3% | Dec 21, 2025 | A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This issue affects some... |
| CVE-2025-14597 | — | — | — | Dec 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-12700 | — | — | — | Dec 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-34290 | HIGH | 7.8 | 0.1% | Dec 20, 2025 | Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerabili... |
| CVE-2025-7782 | HIGH | 7.6 | 0.2% | Dec 20, 2025 | The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to unauthorized modification of data due... |
| CVE-2025-7733 | MEDIUM | 4.3 | 0.2% | Dec 20, 2025 | The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Insecure Direct Object Reference in a... |
| CVE-2025-14298 | MEDIUM | 5.4 | 0.3% | Dec 20, 2025 | The FiboSearch – Ajax Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p... |
| CVE-2025-12492 | MEDIUM | 5.3 | 0.4% | Dec 20, 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi... |
| CVE-2025-13619 | CRITICAL | 9.8 | 0.3% | Dec 20, 2025 | The Flex Store Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.... |
| CVE-2025-12820 | MEDIUM | 5.3 | 0.2% | Dec 20, 2025 | The Pure WC Variation Swatches WordPress plugin through 1.1.7 does not have an authorization check when updating its set... |
| CVE-2025-14735 | MEDIUM | 4.4 | 0.2% | Dec 20, 2025 | The "Amazon affiliate lite Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings ... |
| CVE-2025-14734 | MEDIUM | 5.4 | 0.1% | Dec 20, 2025 | The Amazon affiliate lite Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2025-14721 | MEDIUM | 5.5 | 0.2% | Dec 20, 2025 | The Responsive and Swipe slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rsSli... |
| CVE-2025-14633 | MEDIUM | 5.3 | 0.3% | Dec 20, 2025 | The F70 Lead Document Download plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi... |
| CVE-2025-14591 | HIGH | 7.5 | 0.2% | Dec 20, 2025 | In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windo... |
| CVE-2025-14168 | MEDIUM | 4.3 | 0.1% | Dec 20, 2025 | The WP DB Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-14164 | MEDIUM | 4.3 | 0.1% | Dec 20, 2025 | The Quran Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-13624 | MEDIUM | 6.1 | 0.2% | Dec 20, 2025 | The Overstock Affiliate Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PH... |
| CVE-2025-13365 | MEDIUM | 6.1 | 0.1% | Dec 20, 2025 | The WP Hallo Welt plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now