2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66492 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | Masa CMS is an open source Enterprise Content Management platform. Versions 7.2.8 and below, 7.3.1 through 7.3.13, 7.4.0... |
| CVE-2025-66284 | MEDIUM | 5.4 | 0.1% | Dec 12, 2025 | Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud p... |
| CVE-2025-65120 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud... |
| CVE-2025-64781 | MEDIUM | 5.1 | 0.2% | Dec 12, 2025 | In GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to v... |
| CVE-2025-62192 | MEDIUM | 5.4 | 0.2% | Dec 12, 2025 | SQL Injection vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.... |
| CVE-2025-61987 | MEDIUM | 6.9 | 0.1% | Dec 12, 2025 | GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5... |
| CVE-2025-61950 | MEDIUM | 5.3 | 0.2% | Dec 12, 2025 | In GroupSession, a Circular notice can be created with its memo field non-editable, but the authorization check is impro... |
| CVE-2025-58576 | MEDIUM | 5.1 | 0.1% | Dec 12, 2025 | Cross-site request forgery vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud pri... |
| CVE-2025-57883 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud... |
| CVE-2025-54407 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | Stored cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud pr... |
| CVE-2025-53523 | MEDIUM | 5.4 | 0.1% | Dec 12, 2025 | Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud p... |
| CVE-2025-14467 | MEDIUM | 4.4 | 0.2% | Dec 12, 2025 | The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including... |
| CVE-2025-14393 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Wpik WordPress Basic Ajax Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dname' par... |
| CVE-2025-14392 | MEDIUM | 4.3 | 0.2% | Dec 12, 2025 | The Simple Theme Changer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi... |
| CVE-2025-14391 | MEDIUM | 4.3 | 0.1% | Dec 12, 2025 | The Simple Theme Changer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi... |
| CVE-2025-14354 | MEDIUM | 4.3 | 0.1% | Dec 12, 2025 | The Resource Library for Logged In Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version... |
| CVE-2025-14170 | MEDIUM | 4.3 | 0.2% | Dec 12, 2025 | The Vimeo SimpleGallery plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including... |
| CVE-2025-14166 | MEDIUM | 5.3 | 0.4% | Dec 12, 2025 | The WPMasterToolKit plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.13.... |
| CVE-2025-14165 | MEDIUM | 4.3 | 0.1% | Dec 12, 2025 | The Kirim.Email WooCommerce Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions... |
| CVE-2025-14162 | MEDIUM | 4.3 | 0.1% | Dec 12, 2025 | The BMLT WordPress Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2025-14161 | MEDIUM | 4.3 | 0.1% | Dec 12, 2025 | The Truefy Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2025-14160 | MEDIUM | 4.3 | 0.1% | Dec 12, 2025 | The Upcoming for Calendly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-14158 | MEDIUM | 4.3 | 0.1% | Dec 12, 2025 | The Coding Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-14143 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Ayo Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' parameter of the ay... |
| CVE-2025-14138 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | The WPLG Default Mail From plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_S... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now