Skip to main content

Year archive

CVEs published in 2025

Archive summary

48,162 CVEs published in 2025 — 3,936 Critical, 15,187 High, 24,285 Medium, 3,397 Low, 1,357 Unrated.

CVE-2024-38778

Published Jan 2, 2025

Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search fulltext-search.This issue affects WP Fast Total Search: from n/a through <= 1.69.234.

CVSS 4.3 · Medium

CVE-2024-38764

Published Jan 2, 2025

Cross-Site Request Forgery (CSRF) vulnerability in Marsian allows Cross Site Request Forgery.This issue affects i-transform: from n/a through 3.0.9.

CVSS 4.3 · Medium

CVE-2024-56302

Published Jan 2, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jorisderuiter ConvertCalculator for WordPress convertcalculator allows Stored…

CVSS 6.5 · Medium

CVE-2024-56267

Published Jan 2, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in html5maps Interactive UK Map interactive-uk-map allows Stored XSS.This issue…

CVSS 7.1 · High

CVE-2024-56264

Published Jan 2, 2025

Unrestricted Upload of File with Dangerous Type vulnerability in Beee ACF City Selector acf-city-selector allows Upload a Web Shell to a Web Server.This issue affects ACF City Sel…

CVSS 6.6 · Medium

CVE-2024-56263

Published Jan 2, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GS Plugins GS Shots for Dribbble gs-dribbble-portfolio allows DOM-Based XSS.T…

CVSS 6.5 · Medium

CVE-2024-56262

Published Jan 2, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GS Plugins GS Coaches gs-coach allows Stored XSS.This issue affects GS Coache…

CVSS 6.5 · Medium

CVE-2024-56261

Published Jan 2, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GS Plugins Project Showcase gs-projects allows Stored XSS.This issue affects…

CVSS 6.5 · Medium

CVE-2024-56260

Published Jan 2, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StorePlugin ShopElement shopelement allows Stored XSS.This issue affects Shop…

CVSS 6.5 · Medium

CVE-2024-56259

Published Jan 2, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paolo GeoDirectory geodirectory allows Stored XSS.This issue affects GeoDirec…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56258

Published Jan 2, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlockArt Magazine Blocks magazine-blocks allows Stored XSS.This issue affects…

CVSS 6.5 · Medium

CVE-2024-56255

Published Jan 2, 2025

Missing Authorization vulnerability in Stiofan AyeCode Connect ayecode-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AyeCode C…

CVSS 4.3 · Medium

CVE-2024-56254

Published Jan 2, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moveaddons Move Addons for Elementor move-addons allows Stored XSS.This issue…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56253

Published Jan 2, 2025

Missing Authorization vulnerability in supsystic Data Tables Generator by Supsystic data-tables-generator-by-supsystic allows Exploiting Incorrectly Configured Access Control Secu…

CVSS 5.4 · Medium

CVE-2024-56252

Published Jan 2, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themelooks Enter Addons enteraddons allows Stored XSS.This issue affects Ente…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56251

Published Jan 2, 2025

Cross-Site Request Forgery (CSRF) vulnerability in Event Espresso Event Espresso 4 Decaf event-espresso-decaf allows Cross Site Request Forgery.This issue affects Event Espresso 4…

CVSS 4.3 · Medium

CVE-2024-56250

Published Jan 2, 2025

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Greg Ross Just Writing Statistics just-writing-statistics allows SQL Injectio…

CVSS 7.6 · High

CVE-2024-56249

Published Jan 2, 2025

Unrestricted Upload of File with Dangerous Type vulnerability in Ludwig You WPMasterToolKit wpmastertoolkit allows Upload a Web Shell to a Web Server.This issue affects WPMasterTo…

CVSS 9.1 · Critical

CVE-2024-56248

Published Jan 2, 2025

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You WPMasterToolKit wpmastertoolkit allows Path Traversal.This issue affects…

CVSS 4.9 · Medium

CVE-2024-56247

Published Jan 2, 2025

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AF themes WP Post Author wp-post-author allows SQL Injection.This issue affec…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-56246

Published Jan 2, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor allows DOM-Based XSS.…

CVSS 6.5 · Medium

CVE-2024-56245

Published Jan 2, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leap13 Premium Blocks – Gutenberg Blocks for WordPress premium-blocks-for-gut…

CVSS 6.5 · Medium
Showing 47,976-48,000 of 48,162 CVEsPage 1920 of 1927