2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69341 | MEDIUM | 5.4 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-ad... |
| CVE-2025-69336 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Exploiting... |
| CVE-2025-69335 | MEDIUM | 6.5 | 0.1% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Team S... |
| CVE-2025-69334 | MEDIUM | 6.5 | 0.1% | Jan 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist... |
| CVE-2025-69331 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configu... |
| CVE-2025-69327 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectl... |
| CVE-2025-63083 | MEDIUM | 6.1 | 0.2% | Jan 6, 2026 | Lack of output escaping leads to a XSS vector in the pagebreak plugin. |
| CVE-2025-63082 | MEDIUM | 6.1 | 0.2% | Jan 6, 2026 | Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags. |
| CVE-2025-46696 | MEDIUM | 6.7 | 0.1% | Jan 6, 2026 | Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application, version(s) versions 5.26 to 5.30, contain(s) an Executi... |
| CVE-2025-9637 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized access ... |
| CVE-2025-9318 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injec... |
| CVE-2025-14552 | MEDIUM | 6.4 | 0.2% | Jan 6, 2026 | The MediaPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mpp-uploader shortcode... |
| CVE-2025-9294 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of... |
| CVE-2025-5919 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | The Appointment Booking and Scheduling Calendar Plugin – WP Timetics plugin for WordPress is vulnerable to unauthorized ... |
| CVE-2025-13964 | MEDIUM | 5.3 | 0.2% | Jan 6, 2026 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a m... |
| CVE-2025-13766 | MEDIUM | 5.4 | 0.1% | Jan 6, 2026 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthoriz... |
| CVE-2025-14371 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized m... |
| CVE-2025-13812 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ... |
| CVE-2025-12067 | MEDIUM | 6.4 | 0.2% | Jan 6, 2026 | The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table C... |
| CVE-2025-4776 | MEDIUM | 6.4 | 0.2% | Jan 6, 2026 | The Phlox theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption` HTML attribute in all ... |
| CVE-2025-13215 | MEDIUM | 5.3 | 0.2% | Jan 6, 2026 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all vers... |
| CVE-2025-14441 | MEDIUM | 4.3 | 0.2% | Jan 6, 2026 | The Popupkit plugin for WordPress is vulnerable to arbitrary subscriber data deletion due to missing authorization on th... |
| CVE-2025-14438 | MEDIUM | 6.4 | 0.2% | Jan 6, 2026 | The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, ... |
| CVE-2025-14120 | MEDIUM | 6.4 | 0.2% | Jan 6, 2026 | The URL Image Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver... |
| CVE-2025-14153 | MEDIUM | 6.5 | 0.2% | Jan 6, 2026 | The Page Expire Popup/Redirection for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the '... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now