2025 CVE Vulnerabilities
45,280 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47683 | HIGH | 7.2 | 0.5% | May 7, 2025 | Deserialization of Untrusted Data vulnerability in Florent Maillefaud WP Maintenance wp-maintenance allows Object Inject... |
| CVE-2025-47681 | MEDIUM | 4.3 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Ability, Inc Web Accessibility with Max Access accessibility-toolbar ... |
| CVE-2025-47679 | MEDIUM | 6.5 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RS WP THEMES RS WP... |
| CVE-2025-47677 | MEDIUM | 6.5 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Ga... |
| CVE-2025-47676 | MEDIUM | 6.5 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Faiyaz Alam User L... |
| CVE-2025-47675 | MEDIUM | 6.5 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woobox Woobox woob... |
| CVE-2025-47674 | MEDIUM | 4.3 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Credova Financial Credova_Financial credova-financial allows Cross Si... |
| CVE-2025-47669 | MEDIUM | 6.5 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sabuj Kundu CBX Ma... |
| CVE-2025-47668 | MEDIUM | 5.9 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cookiecode CookieC... |
| CVE-2025-47667 | MEDIUM | 5.4 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in qusupport LiveAgent liveagent allows Cross Site Request Forgery.This ... |
| CVE-2025-47665 | MEDIUM | 5.9 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bistromatic N360 |... |
| CVE-2025-47664 | MEDIUM | 6.5 | 0.2% | May 7, 2025 | Server-Side Request Forgery (SSRF) vulnerability in ThimPress WP Pipes allows Server Side Request Forgery. This issue af... |
| CVE-2025-47662 | MEDIUM | 6.5 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woobox Woobox woob... |
| CVE-2025-47661 | MEDIUM | 5.4 | 0.2% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in codemstory 워드프레스 결제 심플페이 pgall-for-woocommerce allows Cross Site Requ... |
| CVE-2025-47659 | MEDIUM | 6.5 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidcoders WPBaker... |
| CVE-2025-47657 | CRITICAL | 9.3 | 0.3% | May 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Productive Minds P... |
| CVE-2025-47656 | MEDIUM | 6.5 | 0.2% | May 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiracle Themes Sp... |
| CVE-2025-47655 | HIGH | 7.1 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in themarketer2023 theMarketer themarketer allows Stored XSS.This issue ... |
| CVE-2025-47653 | HIGH | 7.5 | 0.5% | May 7, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47649 | HIGH | 8.8 | 0.4% | May 7, 2025 | Path Traversal: '.../...//' vulnerability in StackWC Open Close WooCommerce Store woc-open-close allows PHP Local File I... |
| CVE-2025-47648 | HIGH | 7.1 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in axima Pays – WooCommerce Payment Gateway axima-payment-gateway allows... |
| CVE-2025-47647 | MEDIUM | 4.3 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Sidebar Manager Light sidebar-manager-light allows Cross Si... |
| CVE-2025-47644 | MEDIUM | 4.7 | 0.3% | May 7, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in formsintegrations Integrations of Zoho CRM with Ele... |
| CVE-2025-47643 | HIGH | 7.6 | 0.4% | May 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX ... |
| CVE-2025-47639 | HIGH | 7.1 | 0.1% | May 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Supertext Supertext Translation and Proofreading polylang-supertext a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now