2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11894 | MEDIUM | 5.3 | 0.2% | Nov 11, 2025 | The Shelf Planner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch... |
| CVE-2025-11891 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Shelf Planner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2025-11886 | MEDIUM | 4.3 | 0.1% | Nov 11, 2025 | The CTL Arcade Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2025-11882 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Simple Donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's simpledonate shortc... |
| CVE-2025-11874 | MEDIUM | 5.4 | 0.2% | Nov 11, 2025 | The Slippy Slider – Responsive Touch Navigation Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2025-11873 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The WP BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode in all ... |
| CVE-2025-11869 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Precise Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wrap_id` shortcode attrib... |
| CVE-2025-11863 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The My Geo Posts Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mygeo_city' shortcode i... |
| CVE-2025-11860 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Twitter Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ottwitter_feed' shortcode in... |
| CVE-2025-11859 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Paypal Donation Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypal' shortco... |
| CVE-2025-11856 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Eventbee Ticketing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eventbeeticketw... |
| CVE-2025-11829 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Five9 Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'toolbar' attribute of the... |
| CVE-2025-11828 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Magazine Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headerHtmlTag' attribu... |
| CVE-2025-11822 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The WP Bootstrap Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bootstrap_tab' shortcod... |
| CVE-2025-11821 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Woocommerce – Products By Custom Tax plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'woo_... |
| CVE-2025-11805 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Skip to Timestamp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skipto' shortcode in al... |
| CVE-2025-11532 | MEDIUM | 5.3 | 0.2% | Nov 11, 2025 | The Wisly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1... |
| CVE-2025-11521 | HIGH | 8.1 | 0.4% | Nov 11, 2025 | The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to arbitrary file uploads due to i... |
| CVE-2025-11457 | CRITICAL | 9.8 | 0.3% | Nov 11, 2025 | The EasyCommerce – AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin plugin for WordPress is vulnerable to Privile... |
| CVE-2025-11451 | HIGH | 7.5 | 0.4% | Nov 11, 2025 | The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads i... |
| CVE-2025-11170 | CRITICAL | 9.8 | 0.7% | Nov 11, 2025 | The WP移行専用プラグイン for CPI plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation... |
| CVE-2025-11168 | HIGH | 8.8 | 0.3% | Nov 11, 2025 | The Mementor Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.5... |
| CVE-2025-11129 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Include Fussball.de Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api' and 'typ... |
| CVE-2025-42940 | HIGH | 7.5 | 0.4% | Nov 11, 2025 | SAP CommonCryptoLib does not perform necessary boundary checks during pre-authentication parsing of manipulated ASN.1 da... |
| CVE-2025-42924 | MEDIUM | 6.1 | 0.2% | Nov 11, 2025 | SAP S/4HANA landscape SAP E-Recruiting BSP allows an unauthenticated attacker to craft malicious links, when clicked the... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now