2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13413 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | The Country Blocker for AdSense plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ... |
| CVE-2025-13113 | MEDIUM | 5.3 | 0.3% | Feb 19, 2026 | The Web Accessibility by accessiBe plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ... |
| CVE-2025-13091 | MEDIUM | 4.3 | 0.3% | Feb 19, 2026 | The Shopire theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on ... |
| CVE-2025-13079 | MEDIUM | 5.3 | 0.4% | Feb 19, 2026 | The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to au... |
| CVE-2025-13048 | MEDIUM | 6.4 | 0.2% | Feb 19, 2026 | The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2025-12975 | HIGH | 7.2 | 0.8% | Feb 19, 2026 | The CTX Feed – WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin inst... |
| CVE-2025-12884 | MEDIUM | 4.3 | 0.3% | Feb 19, 2026 | The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to authorization bypass in versions up to, an... |
| CVE-2025-12882 | CRITICAL | 9.8 | 0.4% | Feb 19, 2026 | The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. ... |
| CVE-2025-12845 | HIGH | 8.8 | 0.4% | Feb 19, 2026 | The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to ... |
| CVE-2025-12821 | HIGH | 8.8 | 0.3% | Feb 19, 2026 | The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.6.1. This is... |
| CVE-2025-12707 | HIGH | 7.5 | 0.4% | Feb 19, 2026 | The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all version... |
| CVE-2025-12500 | MEDIUM | 5.3 | 0.3% | Feb 19, 2026 | The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to unauthenticated limi... |
| CVE-2025-12451 | MEDIUM | 4.4 | 0.2% | Feb 19, 2026 | The Easy SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versi... |
| CVE-2025-12448 | MEDIUM | 6.4 | 0.3% | Feb 19, 2026 | The Smartsupp – live chat, AI shopping assistant and chatbots plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2025-12375 | MEDIUM | 6.4 | 0.3% | Feb 19, 2026 | The Printful Integration for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio... |
| CVE-2025-12172 | MEDIUM | 4.3 | 0.1% | Feb 19, 2026 | The Mailchimp List Subscribe Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to... |
| CVE-2025-12117 | MEDIUM | 6.4 | 0.2% | Feb 19, 2026 | The Renden theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, an... |
| CVE-2025-12116 | MEDIUM | 6.4 | 0.2% | Feb 19, 2026 | The Drift theme for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and... |
| CVE-2025-12081 | MEDIUM | 4.3 | 0.3% | Feb 19, 2026 | The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap... |
| CVE-2025-12027 | MEDIUM | 4.3 | 0.3% | Feb 19, 2026 | The Mesmerize Companion plugin for WordPress is vulnerable to unauthorized access and modification of data due to a miss... |
| CVE-2025-11754 | HIGH | 7.5 | 0.4% | Feb 19, 2026 | The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch... |
| CVE-2025-11725 | MEDIUM | 6.5 | 0.3% | Feb 19, 2026 | The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil... |
| CVE-2025-11706 | MEDIUM | 6.1 | 0.3% | Feb 19, 2026 | The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the dbstatus parameter ... |
| CVE-2025-15585 | MEDIUM | 6.7 | 0.2% | Feb 19, 2026 | Fileflows versions before 25.05.2 are affected by an authenticated SQL injection vulnerability in the library-file searc... |
| CVE-2025-15581 | MEDIUM | 4.7 | 0.4% | Feb 18, 2026 | Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authenticati... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now