2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12457MEDIUM6.4The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo...
CVE-2025-12392MEDIUM5.3The Cryptocurrency Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of da...
CVE-2025-12391MEDIUM5.3The Restrictions for BuddyPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
CVE-2025-12088MEDIUM6.4The Meta Display Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Meta Display Block in a...
CVE-2025-12079MEDIUM6.1The WP Twitter Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all ...
CVE-2025-11734MEDIUM5.4The Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable to...
CVE-2025-9625MEDIUM4.3The Coil Web Monetization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-8609MEDIUM6.4The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accor...
CVE-2025-8605MEDIUM6.4The Gutenify – Visual Site Builder Blocks & Site Templates. plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2025-40545MEDIUM4.4SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly saniti...
CVE-2025-26391MEDIUM5.4SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability t...
CVE-2025-12962MEDIUM6.4The Local Syndication plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu...
CVE-2025-12961MEDIUM4.3The Download Panel plugin for WordPress is vulnerable to unauthorized settings modification due to a missing capability ...
CVE-2025-12937MEDIUM6.5The ACF Flexible Layouts Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missin...
CVE-2025-12827MEDIUM4.3The Top Friends plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0...
CVE-2025-12823MEDIUM6.4The CSV to SortTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csv' shortcode in all ve...
CVE-2025-12406MEDIUM6.1The Project Honey Pot Spam Trap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ...
CVE-2025-12404MEDIUM6.1The Like-it plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. ...
CVE-2025-12372MEDIUM4.3The Permalinks Cascade plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,...
CVE-2025-12173MEDIUM4.3The WP Admin Microblog plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2025-12078MEDIUM6.1The ArtiBot Free Chat Bot for WebSites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMess...
CVE-2025-11868MEDIUM6.4The everviz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `everviz` shortcode attributes in ...
CVE-2025-8404MEDIUM5.5Stack buffer overflow vulnerability exists in the Supermicro BMC Shared library. An authenticated attacker with access t...
CVE-2025-11267MEDIUM6.4The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_veu_custom_...
CVE-2025-11265MEDIUM6.4The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_cta...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now