2025 CVE Vulnerabilities

45,322 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13660MEDIUM5.3The Guest Support plugin for WordPress is vulnerable to User Email Disclosure in versions up to, and including, 1.2.3. T...
CVE-2025-12655MEDIUM5.3The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write via a missing authoriza...
CVE-2025-67724MEDIUM6.1Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason ...
CVE-2025-10684MEDIUM4.3The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX ac...
CVE-2025-66492MEDIUM6.1Masa CMS is an open source Enterprise Content Management platform. Versions 7.2.8 and below, 7.3.1 through 7.3.13, 7.4.0...
CVE-2025-66284MEDIUM5.4Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud p...
CVE-2025-65120MEDIUM6.1Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud...
CVE-2025-64781MEDIUM5.1In GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to v...
CVE-2025-62192MEDIUM5.4SQL Injection vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3....
CVE-2025-61987MEDIUM6.9GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5...
CVE-2025-61950MEDIUM5.3In GroupSession, a Circular notice can be created with its memo field non-editable, but the authorization check is impro...
CVE-2025-58576MEDIUM5.1Cross-site request forgery vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud pri...
CVE-2025-57883MEDIUM5.1Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud...
CVE-2025-54407MEDIUM5.1Stored cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud pr...
CVE-2025-53523MEDIUM5.4Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud p...
CVE-2025-14467MEDIUM4.4The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including...
CVE-2025-14393MEDIUM6.4The Wpik WordPress Basic Ajax Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dname' par...
CVE-2025-14392MEDIUM4.3The Simple Theme Changer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2025-14391MEDIUM4.3The Simple Theme Changer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi...
CVE-2025-14354MEDIUM4.3The Resource Library for Logged In Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2025-14170MEDIUM4.3The Vimeo SimpleGallery plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including...
CVE-2025-14166MEDIUM5.3The WPMasterToolKit plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.13....
CVE-2025-14165MEDIUM4.3The Kirim.Email WooCommerce Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
CVE-2025-14162MEDIUM4.3The BMLT WordPress Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2025-14161MEDIUM4.3The Truefy Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now