2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-6461MEDIUM4.3The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all vers...
CVE-2025-13920MEDIUM5.3The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc...
CVE-2025-15516MEDIUM4.3The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca...
CVE-2025-14907MEDIUM4.3The Moderate Selected Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2025-14630MEDIUM4.3The AdminQuickbar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-13205MEDIUM4.3The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for ...
CVE-2025-13194MEDIUM4.3The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for ...
CVE-2025-13139MEDIUM4.3The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
CVE-2025-14985MEDIUM6.4The Alpha Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alpha_block_css’ parameter i...
CVE-2025-14941MEDIUM6.4The GZSEO plugin for WordPress is vulnerable to authorization bypass leading to Stored Cross-Site Scripting in all versi...
CVE-2025-14906MEDIUM4.3The WP Youtube Video Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and...
CVE-2025-14903MEDIUM4.3The Simple Crypto Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc...
CVE-2025-14843MEDIUM5.3The Wizit Gateway for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Order Cancellation in ...
CVE-2025-14797MEDIUM5.4The Same Category Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget title placehold...
CVE-2025-14629MEDIUM5.3The Alchemist Ajax Upload plugin for WordPress is vulnerable to unauthorized media file deletion due to a missing capabi...
CVE-2025-14609MEDIUM5.3The Wise Analytics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1...
CVE-2025-13676MEDIUM6.1The JustClick registration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, a...
CVE-2025-13374CRITICAL9.8The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ...
CVE-2025-12836MEDIUM6.4The VK Google Job Posting Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Descript...
CVE-2025-13952CRITICAL9.8A web page that contains unusual GPU shader code is loaded from the Internet into the GPU compiler process triggers a wr...
CVE-2025-12780——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-70458MEDIUM5.4A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sou...
CVE-2025-70457CRITICAL9.8A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/up...
CVE-2025-52026HIGH7.5An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend...
CVE-2025-52025CRITICAL9.4An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backen...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now