2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12663 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Jeba Cute forkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' parameter in the '... |
| CVE-2025-12662 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Coon Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter in the... |
| CVE-2025-12658 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Preload Current Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'complete' paramete... |
| CVE-2025-12652 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Ungapped Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prefillvalues' parameter... |
| CVE-2025-12651 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Live Photos on WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_src', 'img... |
| CVE-2025-12644 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Nonaki – Drag and Drop Email Template builder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2025-12637 | HIGH | 8.8 | 0.5% | Nov 11, 2025 | The Elastic Theme Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a dynamic code generation f... |
| CVE-2025-12632 | MEDIUM | 5.5 | 0.2% | Nov 11, 2025 | The RandomQuotr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ... |
| CVE-2025-12631 | MEDIUM | 4.4 | 0.2% | Nov 11, 2025 | The Squirrels Auto Inventory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all... |
| CVE-2025-12590 | MEDIUM | 6.1 | 0.1% | Nov 11, 2025 | The YSlider plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versi... |
| CVE-2025-12589 | MEDIUM | 6.1 | 0.1% | Nov 11, 2025 | The WP-Walla plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all vers... |
| CVE-2025-12588 | MEDIUM | 4.3 | 0.1% | Nov 11, 2025 | The USB Qr Code Scanner For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions... |
| CVE-2025-12538 | MEDIUM | 4.4 | 0.2% | Nov 11, 2025 | The Fleet Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u... |
| CVE-2025-12526 | MEDIUM | 4.3 | 0.2% | Nov 11, 2025 | The Private Google Calendars plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca... |
| CVE-2025-12132 | MEDIUM | 4.3 | 0.1% | Nov 11, 2025 | The WP Custom Admin Login Page Logo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up ... |
| CVE-2025-12126 | MEDIUM | 5.4 | 0.2% | Nov 11, 2025 | The The Total Book Project plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,... |
| CVE-2025-12021 | MEDIUM | 6.1 | 0.3% | Nov 11, 2025 | The WP-OAuth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'error_description' parameter ... |
| CVE-2025-12020 | MEDIUM | 4.9 | 0.2% | Nov 11, 2025 | The Double the Donation – A workplace giving tool to help your fundraising efforts plugin for WordPress is vulnerable to... |
| CVE-2025-12019 | MEDIUM | 5.5 | 0.4% | Nov 11, 2025 | The Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image metadata in all versions ... |
| CVE-2025-12010 | MEDIUM | 6.5 | 0.3% | Nov 11, 2025 | The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi... |
| CVE-2025-11999 | MEDIUM | 5.3 | 0.2% | Nov 11, 2025 | The Add Multiple Marker plugin for WordPress is vulnerable to unauthorized modification of data to due to a missing capa... |
| CVE-2025-11997 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Document Pro Elementor – Documentation & Knowledge Base plugin for WordPress is vulnerable to Information Exposure i... |
| CVE-2025-11996 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Find Unused Images plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check... |
| CVE-2025-11988 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including,... |
| CVE-2025-11986 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Crypto plugin for WordPress is vulnerable to Information exposure in all versions up to, and including, 2.22. This i... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now