2025 CVE Vulnerabilities

45,209 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-41108CRITICAL9.8The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an attacker to send commands to t...
CVE-2025-11952MEDIUM6.1Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript co...
CVE-2025-11883MEDIUM6.4The Responsive Progress Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rprogress...
CVE-2025-11880MEDIUM6.4The SM CountDown Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's smcountdown s...
CVE-2025-11878MEDIUM6.4The ST Categories Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's st-categorie...
CVE-2025-11872MEDIUM6.4The Material Design Iconic Font Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2025-11870MEDIUM6.4The Simple Business Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'simple_business_data' sh...
CVE-2025-11867MEDIUM6.4The Bg Book Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `book_author` post meta,...
CVE-2025-11866MEDIUM6.4The Photographers galleries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcode att...
CVE-2025-11834MEDIUM6.4The WP AD Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'startindex' parameter of th...
CVE-2025-11830MEDIUM6.4The WP Restaurant Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' parameter o...
CVE-2025-11827MEDIUM6.4The Oboxmedia Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_widget' and 'after_w...
CVE-2025-11825MEDIUM6.4The Playerzbr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'urlmeta' post meta field in all...
CVE-2025-11824MEDIUM6.4The Cinza Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cgrid_skin_content' post meta ...
CVE-2025-11819MEDIUM6.4The WP-Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'roboshot' shortcode in all v...
CVE-2025-11818MEDIUM6.4The WP Responsive Meet The Team plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wprm_team' sh...
CVE-2025-11817MEDIUM6.4The Simple Tableau Viz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tableau' shortcode in ...
CVE-2025-11813MEDIUM6.4The Responsive iframe GoogleMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'responsive_ma...
CVE-2025-11811MEDIUM6.4The Simple Youtube Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embed_youtube' s...
CVE-2025-11810MEDIUM6.4The Print Button Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'print-button' shor...
CVE-2025-11809MEDIUM6.4The WP-Force Images Download plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpfid' shortcode...
CVE-2025-11807MEDIUM6.4The Mixlr Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mixlr' shortcode in all v...
CVE-2025-11804MEDIUM6.4The JB News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of...
CVE-2025-10138MEDIUM6.4The This-or-That plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'thisorthat' shortco...
CVE-2025-10047MEDIUM4.9The Email Tracker – Email Log, Email Open Tracking, Email Analytics & Email Management for WordPress Emails plugin for W...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now