2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69350 | MEDIUM | 5.9 | 0.1% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Accord... |
| CVE-2025-69349 | MEDIUM | 5.4 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in Fahad Mahmood RSS Feed Widget rss-feed-widget allows Exploiting Incorrectly Confi... |
| CVE-2025-69348 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in CoolHappy The Events Calendar Countdown Addon countdown-for-the-events-calendar a... |
| CVE-2025-69346 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in WPCenter AffiliateX affiliatex allows Exploiting Incorrectly Configured Access Co... |
| CVE-2025-69345 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Exploitin... |
| CVE-2025-69341 | MEDIUM | 5.4 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-ad... |
| CVE-2025-69336 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Exploiting... |
| CVE-2025-69335 | MEDIUM | 6.5 | 0.1% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Team S... |
| CVE-2025-69334 | MEDIUM | 6.5 | 0.1% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist... |
| CVE-2025-69331 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configu... |
| CVE-2025-69327 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectl... |
| CVE-2025-63083 | MEDIUM | 6.1 | 0.2% | Jan 6, 2026 | Lack of output escaping leads to a XSS vector in the pagebreak plugin. |
| CVE-2025-63082 | MEDIUM | 6.1 | 0.2% | Jan 6, 2026 | Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags. |
| CVE-2025-46696 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application, version(s) versions 5.26 to 5.30, contain(s) an Executi... |
| CVE-2025-9637 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized access ... |
| CVE-2025-9318 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injec... |
| CVE-2025-14552 | MEDIUM | 6.4 | 0.2% | Jan 6, 2026 | The MediaPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mpp-uploader shortcode... |
| CVE-2025-9294 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of... |
| CVE-2025-5919 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | The Appointment Booking and Scheduling Calendar Plugin – WP Timetics plugin for WordPress is vulnerable to unauthorized ... |
| CVE-2025-13964 | MEDIUM | 5.3 | 0.2% | Jan 6, 2026 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a m... |
| CVE-2025-13766 | MEDIUM | 5.4 | 0.1% | Jan 6, 2026 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthoriz... |
| CVE-2025-14371 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized m... |
| CVE-2025-13812 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ... |
| CVE-2025-12067 | MEDIUM | 6.4 | 0.2% | Jan 6, 2026 | The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table C... |
| CVE-2025-4776 | MEDIUM | 6.4 | 0.2% | Jan 6, 2026 | The Phlox theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption` HTML attribute in all ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now