2025 CVE Vulnerabilities

45,266 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-28947HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-28946HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-27361HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thhake Photo Expre...
CVE-2025-25173HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FasterThemes FastB...
CVE-2025-25171HIGH8.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Convers Lab WP SmartPay smartpay allows Authen...
CVE-2025-24774HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla WPCRM - C...
CVE-2025-24769HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-24765HIGH7.7Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RobMarsh Image Shadow im...
CVE-2025-24760HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-23973HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dugudlabs SpecFit-...
CVE-2025-23967CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpopal GG Bought T...
CVE-2025-6761HIGH7.3A vulnerability was found in Kingdee Cloud-Starry-Sky Enterprise Edition 6.x/7.x/8.x/9.0. It has been rated as critical....
CVE-2025-5398MEDIUM5.4The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2025-2940HIGH7.2The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all vers...
CVE-2025-6689MEDIUM5.4The FL3R Accessibility Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fl3racce...
CVE-2025-6688CRITICAL9.8The Simple Payment plugin for WordPress is vulnerable to Authentication Bypass in versions 1.3.6 to 2.3.8. This is due t...
CVE-2025-6550MEDIUM5.4The The Pack Elementor addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slider_options’ ...
CVE-2025-5940MEDIUM5.4The Osom Blocks – Custom Post Type listing block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2025-5936MEDIUM4.3The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2...
CVE-2025-5306CRITICAL9.8Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue af...
CVE-2025-4587MEDIUM6.4The A/B Testing for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ab-tes...
CVE-2025-5526MEDIUM4.3The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and d...
CVE-2025-5194MEDIUM4.8The WP Map Block WordPress plugin before 2.0.3 does not validate and escape some of its block options before outputting...
CVE-2025-5093MEDIUM5.4The Responsive Lightbox & Gallery WordPress plugin before 2.5.2 use the Swipebox library which does not validate and esc...
CVE-2025-5035MEDIUM5.4The Firelight Lightbox WordPress plugin before 2.3.16 does not sanitise and escape title attributes before outputting th...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now