2025 CVE Vulnerabilities
45,266 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-28947 | HIGH | 8.1 | 0.5% | Jun 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-28946 | HIGH | 8.1 | 0.5% | Jun 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-27361 | HIGH | 7.1 | 0.2% | Jun 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thhake Photo Expre... |
| CVE-2025-25173 | HIGH | 7.1 | 0.2% | Jun 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FasterThemes FastB... |
| CVE-2025-25171 | HIGH | 8.8 | 0.4% | Jun 27, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Convers Lab WP SmartPay smartpay allows Authen... |
| CVE-2025-24774 | HIGH | 7.1 | 0.2% | Jun 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla WPCRM - C... |
| CVE-2025-24769 | HIGH | 8.1 | 0.5% | Jun 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-24765 | HIGH | 7.7 | 0.4% | Jun 27, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RobMarsh Image Shadow im... |
| CVE-2025-24760 | HIGH | 8.1 | 0.5% | Jun 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-23973 | HIGH | 7.1 | 0.2% | Jun 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dugudlabs SpecFit-... |
| CVE-2025-23967 | CRITICAL | 9.3 | 0.3% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpopal GG Bought T... |
| CVE-2025-6761 | HIGH | 7.3 | 0.4% | Jun 27, 2025 | A vulnerability was found in Kingdee Cloud-Starry-Sky Enterprise Edition 6.x/7.x/8.x/9.0. It has been rated as critical.... |
| CVE-2025-5398 | MEDIUM | 5.4 | 0.2% | Jun 27, 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2025-2940 | HIGH | 7.2 | 0.3% | Jun 27, 2025 | The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all vers... |
| CVE-2025-6689 | MEDIUM | 5.4 | 0.2% | Jun 27, 2025 | The FL3R Accessibility Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fl3racce... |
| CVE-2025-6688 | CRITICAL | 9.8 | 0.5% | Jun 27, 2025 | The Simple Payment plugin for WordPress is vulnerable to Authentication Bypass in versions 1.3.6 to 2.3.8. This is due t... |
| CVE-2025-6550 | MEDIUM | 5.4 | 0.2% | Jun 27, 2025 | The The Pack Elementor addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slider_options’ ... |
| CVE-2025-5940 | MEDIUM | 5.4 | 0.2% | Jun 27, 2025 | The Osom Blocks – Custom Post Type listing block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2025-5936 | MEDIUM | 4.3 | 0.1% | Jun 27, 2025 | The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2... |
| CVE-2025-5306 | CRITICAL | 9.8 | 19.9% | Jun 27, 2025 | Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue af... |
| CVE-2025-4587 | MEDIUM | 6.4 | 0.2% | Jun 27, 2025 | The A/B Testing for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ab-tes... |
| CVE-2025-5526 | MEDIUM | 4.3 | 0.2% | Jun 27, 2025 | The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and d... |
| CVE-2025-5194 | MEDIUM | 4.8 | 0.2% | Jun 27, 2025 | The WP Map Block WordPress plugin before 2.0.3 does not validate and escape some of its block options before outputting... |
| CVE-2025-5093 | MEDIUM | 5.4 | 0.2% | Jun 27, 2025 | The Responsive Lightbox & Gallery WordPress plugin before 2.5.2 use the Swipebox library which does not validate and esc... |
| CVE-2025-5035 | MEDIUM | 5.4 | 0.2% | Jun 27, 2025 | The Firelight Lightbox WordPress plugin before 2.3.16 does not sanitise and escape title attributes before outputting th... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now