2025 CVE Vulnerabilities
45,269 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-30994 | MEDIUM | 4.3 | 0.1% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Cross Site Request Forge... |
| CVE-2025-30991 | MEDIUM | 6.5 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada WPDM – Pr... |
| CVE-2025-30990 | MEDIUM | 5.4 | 0.2% | Jun 6, 2025 | Missing Authorization vulnerability in ThemeHunk ThemeHunk themehunk-megamenu-plus allows Exploiting Incorrectly Configu... |
| CVE-2025-30989 | HIGH | 7.6 | 0.4% | Jun 6, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Renzo Tejada Libro... |
| CVE-2025-30986 | MEDIUM | 5.4 | 0.1% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in _CreativeMedia_ Elite Video Player elite-video-player allows Cross Si... |
| CVE-2025-30981 | MEDIUM | 6.3 | 0.1% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in tggfref WP-Recall allows Privilege Escalation. This issue affects WP-... |
| CVE-2025-30980 | MEDIUM | 4.3 | 0.1% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Simple Keyword to Link simple-keyword-to-link allow... |
| CVE-2025-30978 | MEDIUM | 4.3 | 0.3% | Jun 6, 2025 | Missing Authorization vulnerability in Dor Zuberi Slack Notifications by dorzki dorzki-notifications-to-slack allows Exp... |
| CVE-2025-30977 | MEDIUM | 5.9 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chaport Live Chat ... |
| CVE-2025-30976 | MEDIUM | 4.9 | 0.2% | Jun 6, 2025 | Server-Side Request Forgery (SSRF) vulnerability in wpdive Nexa Blocks nexa-blocks allows Server Side Request Forgery.Th... |
| CVE-2025-30974 | HIGH | 8.8 | 0.3% | Jun 6, 2025 | Missing Authorization vulnerability in Akhtarujjaman Shuvo Post Grid Master ajax-filter-posts allows Exploiting Incorrec... |
| CVE-2025-30968 | MEDIUM | 5.4 | 0.1% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in jokerbr313 Advanced Post List advanced-post-list allows Cross Site Re... |
| CVE-2025-30958 | MEDIUM | 5.4 | 0.3% | Jun 6, 2025 | Missing Authorization vulnerability in onOffice GmbH onOffice for WP-Websites onoffice-for-wp-websites allows Exploiting... |
| CVE-2025-30957 | MEDIUM | 5.4 | 0.3% | Jun 6, 2025 | Missing Authorization vulnerability in BuddyDev Activity Plus Reloaded for BuddyPress bp-activity-plus-reloaded allows E... |
| CVE-2025-30956 | MEDIUM | 4.3 | 0.1% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Booqable Rental Software Booqable Rental booqable-rental-reservations... |
| CVE-2025-30954 | MEDIUM | 4.7 | 0.3% | Jun 6, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin ... |
| CVE-2025-30953 | MEDIUM | 4.7 | 0.3% | Jun 6, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce... |
| CVE-2025-30952 | MEDIUM | 6.5 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdive Nexa Blocks... |
| CVE-2025-30951 | MEDIUM | 6.5 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stiofan BlockStrap... |
| CVE-2025-30950 | MEDIUM | 6.5 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Wham All Curren... |
| CVE-2025-30948 | MEDIUM | 4.3 | 0.1% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Giraphix Creative Layouts for Elementor layouts-for-elementor allows ... |
| CVE-2025-30946 | MEDIUM | 4.3 | 0.1% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Michael Cannon Custom Bulk/Quick Edit custom-bulkquick-edit allows Cr... |
| CVE-2025-30945 | MEDIUM | 5.3 | 0.3% | Jun 6, 2025 | Missing Authorization vulnerability in taskbuilder Taskbuilder taskbuilder allows Accessing Functionality Not Properly C... |
| CVE-2025-30942 | MEDIUM | 5.9 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Post Cu... |
| CVE-2025-30941 | MEDIUM | 5.9 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marvie Pons Pinter... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now