2025 CVE Vulnerabilities
45,181 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13620 | MEDIUM | 5.3 | 0.3% | Dec 5, 2025 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions ... |
| CVE-2025-13739 | MEDIUM | 6.4 | 0.3% | Dec 5, 2025 | The CryptX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `cryptx` shortcode in all ... |
| CVE-2025-13682 | MEDIUM | 4.4 | 0.2% | Dec 5, 2025 | The Trail Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u... |
| CVE-2025-13678 | MEDIUM | 6.4 | 0.2% | Dec 5, 2025 | The Thai Lottery Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `thailottery` shortcod... |
| CVE-2025-13614 | HIGH | 8.1 | 0.3% | Dec 5, 2025 | The Cool Tag Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cool_tag_cloud' s... |
| CVE-2025-12879 | HIGH | 8.8 | 0.2% | Dec 5, 2025 | The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and i... |
| CVE-2025-12876 | MEDIUM | 5.3 | 0.3% | Dec 5, 2025 | The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data d... |
| CVE-2025-12851 | HIGH | 8.1 | 0.7% | Dec 5, 2025 | The My auctions allegro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including,... |
| CVE-2025-13684 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The ARK Related Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 2.19. This is due to m... |
| CVE-2025-12130 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to... |
| CVE-2025-13515 | MEDIUM | 6.1 | 0.2% | Dec 5, 2025 | The Nouri.sh Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF... |
| CVE-2025-12850 | HIGH | 7.5 | 0.3% | Dec 5, 2025 | The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versio... |
| CVE-2025-12374 | CRITICAL | 9.8 | 0.4% | Dec 5, 2025 | The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plu... |
| CVE-2025-12373 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The Torod – The smart shipping and delivery portal for e-shops and retailers plugin for WordPress is vulnerable to Cross... |
| CVE-2025-12355 | MEDIUM | 5.3 | 0.2% | Dec 5, 2025 | The Payaza plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on ... |
| CVE-2025-12354 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | The Live CSS Preview plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2025-12186 | MEDIUM | 4.4 | 0.2% | Dec 5, 2025 | The Weekly Planner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions ... |
| CVE-2025-12093 | MEDIUM | 5.3 | 0.2% | Dec 5, 2025 | The Voidek Employee Portal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o... |
| CVE-2025-66270 | MEDIUM | 4.7 | 0.2% | Dec 5, 2025 | The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect ... |
| CVE-2025-32900 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the di... |
| CVE-2025-13860 | MEDIUM | 6.4 | 0.2% | Dec 5, 2025 | The Easy Jump Links Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `h_tags` parameter i... |
| CVE-2025-13625 | MEDIUM | 6.1 | 0.2% | Dec 5, 2025 | The WP-SOS-Donate Donation Sidebar Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVE... |
| CVE-2025-13623 | MEDIUM | 6.1 | 0.2% | Dec 5, 2025 | The Twitscription plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO in al... |
| CVE-2025-13622 | MEDIUM | 6.1 | 0.2% | Dec 5, 2025 | The Jabbernotification plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the admin.php PATH_INFO ... |
| CVE-2025-13621 | MEDIUM | 6.1 | 0.1% | Dec 5, 2025 | The dream gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now