2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48269 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPA... |
| CVE-2025-48268 | MEDIUM | 4.3 | 0.2% | May 19, 2025 | Missing Authorization vulnerability in Guru Team Bot for Telegram on WooCommerce bot-for-telegram-on-woocommerce allows ... |
| CVE-2025-48266 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 Active ... |
| CVE-2025-48265 | MEDIUM | 4.3 | 0.1% | May 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Pektsekye Year Make Model Search for WooCommerce ymm-search allows Cr... |
| CVE-2025-48264 | MEDIUM | 4.3 | 0.1% | May 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in artiosmedia Product Code for WooCommerce product-code-for-woocommerce... |
| CVE-2025-48263 | MEDIUM | 5.4 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MultiVendorX Multi... |
| CVE-2025-48262 | MEDIUM | 4.3 | 0.3% | May 19, 2025 | Missing Authorization vulnerability in M.Code Url Rewrite Analyzer url-rewrite-analyzer allows Exploiting Incorrectly Co... |
| CVE-2025-48260 | MEDIUM | 4.3 | 0.2% | May 19, 2025 | Missing Authorization vulnerability in Ninja Team GDPR CCPA Compliance Support ninja-gdpr-compliance allows Exploiting I... |
| CVE-2025-48259 | MEDIUM | 4.3 | 0.1% | May 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Juan Carlos WP Mapa Politico España wp-mapa-politico-spain allows Cro... |
| CVE-2025-48258 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jetmonsters Mega M... |
| CVE-2025-48257 | MEDIUM | 6.5 | 0.3% | May 19, 2025 | Missing Authorization vulnerability in Projectopia Projectopia projectopia-core allows Exploiting Incorrectly Configured... |
| CVE-2025-48256 | MEDIUM | 5.4 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xylus Themes Impor... |
| CVE-2025-48255 | HIGH | 8.8 | 0.2% | May 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in videowhisper Broadcast Live Video videowhisper-live-streaming-integra... |
| CVE-2025-48254 | MEDIUM | 5.4 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Change A... |
| CVE-2025-48253 | MEDIUM | 5.4 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Free Shi... |
| CVE-2025-48252 | MEDIUM | 5.4 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Back But... |
| CVE-2025-48251 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Addition... |
| CVE-2025-48250 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Coupons ... |
| CVE-2025-48249 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory EAN for ... |
| CVE-2025-48248 | MEDIUM | 6.5 | 0.2% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Sitewide... |
| CVE-2025-48247 | MEDIUM | 4.3 | 0.3% | May 19, 2025 | Missing Authorization vulnerability in Blair Williams Shortlinks by Pretty Links pretty-link allows Exploiting Incorrect... |
| CVE-2025-48246 | MEDIUM | 5.4 | 0.3% | May 19, 2025 | Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly C... |
| CVE-2025-48244 | MEDIUM | 5.9 | 0.3% | May 19, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclu... |
| CVE-2025-48243 | MEDIUM | 4.3 | 0.1% | May 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in sminozzi reCAPTCHA for all recaptcha-for-all allows Cross Site Reques... |
| CVE-2025-48242 | MEDIUM | 6.5 | 0.3% | May 19, 2025 | Missing Authorization vulnerability in wpWax Legal Pages legal-pages allows Exploiting Incorrectly Configured Access Con... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now