LiveActive security incident?Get immediate response
CVE archive

January 2025

Browse CVE records published in January 2025, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 3893 matching CVEs · Page 17 of 78.

High · CVSS 8.1

CVE-2025-69004: WordPress Bajaar - Highly Customizable WooCommerce WordPress Theme theme <= 2.1.0 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in XpeedStudio Bajaar - Highly Customizable WooCommerce WordPress Theme bajaar allows PHP Local File Inclusion.This issue affects Bajaar - Highly Customizable WooCommerce WordPress Theme: from n/a through <= 2.1.0.

Published Jan 22, 2026 · Updated Apr 28, 2026