2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-11894MEDIUM5.3The Shelf Planner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch...
CVE-2025-11891MEDIUM5.3The Shelf Planner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2025-11886MEDIUM4.3The CTL Arcade Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin...
CVE-2025-11882MEDIUM6.4The Simple Donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's simpledonate shortc...
CVE-2025-11874MEDIUM5.4The Slippy Slider – Responsive Touch Navigation Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2025-11873MEDIUM6.4The WP BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode in all ...
CVE-2025-11869MEDIUM6.4The Precise Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wrap_id` shortcode attrib...
CVE-2025-11863MEDIUM6.4The My Geo Posts Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mygeo_city' shortcode i...
CVE-2025-11860MEDIUM6.4The Twitter Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ottwitter_feed' shortcode in...
CVE-2025-11859MEDIUM6.4The Paypal Donation Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypal' shortco...
CVE-2025-11856MEDIUM6.4The Eventbee Ticketing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eventbeeticketw...
CVE-2025-11829MEDIUM6.4The Five9 Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'toolbar' attribute of the...
CVE-2025-11828MEDIUM6.4The Magazine Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headerHtmlTag' attribu...
CVE-2025-11822MEDIUM6.4The WP Bootstrap Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bootstrap_tab' shortcod...
CVE-2025-11821MEDIUM6.4The Woocommerce – Products By Custom Tax plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'woo_...
CVE-2025-11805MEDIUM6.4The Skip to Timestamp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skipto' shortcode in al...
CVE-2025-11532MEDIUM5.3The Wisly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1...
CVE-2025-11521HIGH8.1The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to arbitrary file uploads due to i...
CVE-2025-11457CRITICAL9.8The EasyCommerce – AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin plugin for WordPress is vulnerable to Privile...
CVE-2025-11451HIGH7.5The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads i...
CVE-2025-11170CRITICAL9.8The WP移行専用プラグイン for CPI plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation...
CVE-2025-11168HIGH8.8The Mementor Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.5...
CVE-2025-11129MEDIUM6.4The Include Fussball.de Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api' and 'typ...
CVE-2025-42940HIGH7.5SAP CommonCryptoLib does not perform necessary boundary checks during pre-authentication parsing of manipulated ASN.1 da...
CVE-2025-42924MEDIUM6.1SAP S/4HANA landscape SAP E-Recruiting BSP allows an unauthenticated attacker to craft malicious links, when clicked the...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now