2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-66492MEDIUM6.1Masa CMS is an open source Enterprise Content Management platform. Versions 7.2.8 and below, 7.3.1 through 7.3.13, 7.4.0...
CVE-2025-66284MEDIUM5.4Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud p...
CVE-2025-65120MEDIUM6.1Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud...
CVE-2025-64781MEDIUM5.1In GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to v...
CVE-2025-62192MEDIUM5.4SQL Injection vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3....
CVE-2025-61987MEDIUM6.9GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5...
CVE-2025-61950MEDIUM5.3In GroupSession, a Circular notice can be created with its memo field non-editable, but the authorization check is impro...
CVE-2025-58576MEDIUM5.1Cross-site request forgery vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud pri...
CVE-2025-57883MEDIUM6.1Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud...
CVE-2025-54407MEDIUM6.1Stored cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud pr...
CVE-2025-53523MEDIUM5.4Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud p...
CVE-2025-14467MEDIUM4.4The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including...
CVE-2025-14393MEDIUM6.4The Wpik WordPress Basic Ajax Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dname' par...
CVE-2025-14392MEDIUM4.3The Simple Theme Changer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2025-14391MEDIUM4.3The Simple Theme Changer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi...
CVE-2025-14354MEDIUM4.3The Resource Library for Logged In Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2025-14170MEDIUM4.3The Vimeo SimpleGallery plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including...
CVE-2025-14166MEDIUM5.3The WPMasterToolKit plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.13....
CVE-2025-14165MEDIUM4.3The Kirim.Email WooCommerce Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
CVE-2025-14162MEDIUM4.3The BMLT WordPress Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2025-14161MEDIUM4.3The Truefy Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2025-14160MEDIUM4.3The Upcoming for Calendly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-14158MEDIUM4.3The Coding Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-14143MEDIUM6.4The Ayo Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' parameter of the ay...
CVE-2025-14138MEDIUM6.1The WPLG Default Mail From plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_S...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now