2025 CVE Vulnerabilities

45,181 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13856MEDIUM6.4The Extra Post Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the ex...
CVE-2025-13666MEDIUM5.3The Helloprint plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.2. This...
CVE-2025-13656MEDIUM6.4The Cute News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribu...
CVE-2025-13629MEDIUM4.3The WP Landing Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin...
CVE-2025-13626MEDIUM6.1The myLCO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter ...
CVE-2025-13358MEDIUM5.3The Accessiy By CodeConfig Accessibility plugin for WordPress is vulnerable to unauthorized page creation due to missing...
CVE-2025-13309MEDIUM4.3The Accessiy By CodeConfig Accessibility – Easy One-Click Accessibility Toolbar That Truly Matters plugin for WordPress ...
CVE-2025-13308MEDIUM5.4The Application Passwords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'reject_url' para...
CVE-2025-13137MEDIUM6.1The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to Reflected Cross-Site Script...
CVE-2025-12721MEDIUM5.3The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2025-12720MEDIUM5.3The g-FFL Cockpit plugin for WordPress is vulnerable to unauthorized modification of data due to IP-based authorization ...
CVE-2025-12717MEDIUM6.4The List Attachments Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_list' p...
CVE-2025-12715MEDIUM6.4The Canadian Nutrition Facts Label plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'percentage...
CVE-2025-12673CRITICAL9.8The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2025-12577MEDIUM4.3The Listar – Directory Listing & Classifieds WordPress Plugin plugin for WordPress is vulnerable to unauthorized modific...
CVE-2025-12574MEDIUM4.3The Listar – Directory Listing & Classifieds WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of...
CVE-2025-12091MEDIUM4.3The Search, Filters & Merchandising for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of d...
CVE-2025-13922MEDIUM6.5The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based bli...
CVE-2025-13292HIGH7.6A vulnerability in Apigee-X allowed an attacker to gain unauthorized read and write access to Apigee Analytics (AX) data...
CVE-2025-12505MEDIUM5.4The weDocs plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.1.14. This ...
CVE-2025-12510HIGH7.2The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, ...
CVE-2025-11263MEDIUM6.1The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the type parameter in all...
CVE-2025-66629MEDIUM4.3HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.4, some of HedgeDoc's OA...
CVE-2025-34291HIGH8.8Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote cod...
CVE-2025-14116MEDIUM4.7A vulnerability was detected in xerrors Yuxi-Know up to 0.4.0. This vulnerability affects the function OtherEmbedding.ae...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now