2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66061 | MEDIUM | 4.3 | 0.1% | Nov 21, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting ... |
| CVE-2025-66060 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Explo... |
| CVE-2025-66059 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Craig Hewitt Seriously Simpl... |
| CVE-2025-66057 | MEDIUM | 6.5 | 0.2% | Nov 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Pa... |
| CVE-2025-66056 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Uncanny Owl Uncanny Automato... |
| CVE-2025-66053 | MEDIUM | 6.5 | 0.2% | Nov 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold enfo... |
| CVE-2025-12935 | MEDIUM | 6.4 | 0.3% | Nov 21, 2025 | The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin f... |
| CVE-2025-10054 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification ... |
| CVE-2025-10039 | MEDIUM | 4.3 | 0.3% | Nov 21, 2025 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Insecure Direct Object Ref... |
| CVE-2025-12964 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The Magical Products Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mpdpr_title_tag'... |
| CVE-2025-12750 | MEDIUM | 4.9 | 0.3% | Nov 21, 2025 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to SQL Injection via the ... |
| CVE-2025-12066 | MEDIUM | 4.4 | 0.2% | Nov 21, 2025 | The WP Delete Post Copies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve... |
| CVE-2025-13149 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin fo... |
| CVE-2025-13141 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2025-12039 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to IP Address Spoofing in all versi... |
| CVE-2025-11973 | MEDIUM | 4.9 | 0.3% | Nov 21, 2025 | The 简数采集器 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.6.3 via the ... |
| CVE-2025-11826 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The WP Company Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the '... |
| CVE-2025-11808 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The Shortcode for Google Street View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'streetvi... |
| CVE-2025-11803 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The WPSite Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'format' shortcode attrib... |
| CVE-2025-13142 | MEDIUM | 4.3 | 0.1% | Nov 21, 2025 | The Custom Post Type plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi... |
| CVE-2025-13135 | MEDIUM | 6.4 | 0.2% | Nov 21, 2025 | The HotelRunner Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hotel... |
| CVE-2025-13134 | MEDIUM | 6.1 | 0.1% | Nov 21, 2025 | The AuthorSure plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.... |
| CVE-2025-12894 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Informa... |
| CVE-2025-12881 | MEDIUM | 5.4 | 0.1% | Nov 21, 2025 | The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in... |
| CVE-2025-12746 | MEDIUM | 6.1 | 0.2% | Nov 21, 2025 | The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all vers... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now