2025 CVE Vulnerabilities
45,181 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13856 | MEDIUM | 6.4 | 0.2% | Dec 6, 2025 | The Extra Post Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the ex... |
| CVE-2025-13666 | MEDIUM | 5.3 | 0.2% | Dec 6, 2025 | The Helloprint plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.2. This... |
| CVE-2025-13656 | MEDIUM | 6.4 | 0.2% | Dec 6, 2025 | The Cute News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribu... |
| CVE-2025-13629 | MEDIUM | 4.3 | 0.1% | Dec 6, 2025 | The WP Landing Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2025-13626 | MEDIUM | 6.1 | 0.2% | Dec 6, 2025 | The myLCO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter ... |
| CVE-2025-13358 | MEDIUM | 5.3 | 0.2% | Dec 6, 2025 | The Accessiy By CodeConfig Accessibility plugin for WordPress is vulnerable to unauthorized page creation due to missing... |
| CVE-2025-13309 | MEDIUM | 4.3 | 0.2% | Dec 6, 2025 | The Accessiy By CodeConfig Accessibility – Easy One-Click Accessibility Toolbar That Truly Matters plugin for WordPress ... |
| CVE-2025-13308 | MEDIUM | 5.4 | 0.2% | Dec 6, 2025 | The Application Passwords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'reject_url' para... |
| CVE-2025-13137 | MEDIUM | 6.1 | 0.2% | Dec 6, 2025 | The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to Reflected Cross-Site Script... |
| CVE-2025-12721 | MEDIUM | 5.3 | 0.2% | Dec 6, 2025 | The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2025-12720 | MEDIUM | 5.3 | 0.2% | Dec 6, 2025 | The g-FFL Cockpit plugin for WordPress is vulnerable to unauthorized modification of data due to IP-based authorization ... |
| CVE-2025-12717 | MEDIUM | 6.4 | 0.2% | Dec 6, 2025 | The List Attachments Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_list' p... |
| CVE-2025-12715 | MEDIUM | 6.4 | 0.2% | Dec 6, 2025 | The Canadian Nutrition Facts Label plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'percentage... |
| CVE-2025-12673 | CRITICAL | 9.8 | 0.6% | Dec 6, 2025 | The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat... |
| CVE-2025-12577 | MEDIUM | 4.3 | 0.2% | Dec 6, 2025 | The Listar – Directory Listing & Classifieds WordPress Plugin plugin for WordPress is vulnerable to unauthorized modific... |
| CVE-2025-12574 | MEDIUM | 4.3 | 0.2% | Dec 6, 2025 | The Listar – Directory Listing & Classifieds WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of... |
| CVE-2025-12091 | MEDIUM | 4.3 | 0.2% | Dec 6, 2025 | The Search, Filters & Merchandising for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of d... |
| CVE-2025-13922 | MEDIUM | 6.5 | 0.3% | Dec 6, 2025 | The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based bli... |
| CVE-2025-13292 | HIGH | 7.6 | 0.2% | Dec 6, 2025 | A vulnerability in Apigee-X allowed an attacker to gain unauthorized read and write access to Apigee Analytics (AX) data... |
| CVE-2025-12505 | MEDIUM | 5.4 | 0.2% | Dec 6, 2025 | The weDocs plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.1.14. This ... |
| CVE-2025-12510 | HIGH | 7.2 | 0.4% | Dec 6, 2025 | The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, ... |
| CVE-2025-11263 | MEDIUM | 6.1 | 0.2% | Dec 6, 2025 | The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the type parameter in all... |
| CVE-2025-66629 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.4, some of HedgeDoc's OA... |
| CVE-2025-34291 | HIGH | 8.8 | 78.9% | Dec 5, 2025 | Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote cod... |
| CVE-2025-14116 | MEDIUM | 4.7 | 0.2% | Dec 5, 2025 | A vulnerability was detected in xerrors Yuxi-Know up to 0.4.0. This vulnerability affects the function OtherEmbedding.ae... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now