2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12457 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo... |
| CVE-2025-12392 | MEDIUM | 5.3 | 0.2% | Nov 18, 2025 | The Cryptocurrency Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of da... |
| CVE-2025-12391 | MEDIUM | 5.3 | 0.2% | Nov 18, 2025 | The Restrictions for BuddyPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing... |
| CVE-2025-12088 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The Meta Display Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Meta Display Block in a... |
| CVE-2025-12079 | MEDIUM | 6.1 | 0.2% | Nov 18, 2025 | The WP Twitter Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all ... |
| CVE-2025-11734 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | The Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable to... |
| CVE-2025-9625 | MEDIUM | 4.3 | 0.1% | Nov 18, 2025 | The Coil Web Monetization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-8609 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accor... |
| CVE-2025-8605 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The Gutenify – Visual Site Builder Blocks & Site Templates. plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2025-40545 | MEDIUM | 4.4 | 0.2% | Nov 18, 2025 | SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly saniti... |
| CVE-2025-26391 | MEDIUM | 5.4 | 0.4% | Nov 18, 2025 | SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability t... |
| CVE-2025-12962 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The Local Syndication plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu... |
| CVE-2025-12961 | MEDIUM | 4.3 | 0.2% | Nov 18, 2025 | The Download Panel plugin for WordPress is vulnerable to unauthorized settings modification due to a missing capability ... |
| CVE-2025-12937 | MEDIUM | 6.5 | 0.2% | Nov 18, 2025 | The ACF Flexible Layouts Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missin... |
| CVE-2025-12827 | MEDIUM | 4.3 | 0.1% | Nov 18, 2025 | The Top Friends plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0... |
| CVE-2025-12823 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The CSV to SortTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csv' shortcode in all ve... |
| CVE-2025-12406 | MEDIUM | 6.1 | 0.1% | Nov 18, 2025 | The Project Honey Pot Spam Trap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ... |
| CVE-2025-12404 | MEDIUM | 6.1 | 0.1% | Nov 18, 2025 | The Like-it plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. ... |
| CVE-2025-12372 | MEDIUM | 4.3 | 0.2% | Nov 18, 2025 | The Permalinks Cascade plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,... |
| CVE-2025-12173 | MEDIUM | 4.3 | 0.1% | Nov 18, 2025 | The WP Admin Microblog plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2025-12078 | MEDIUM | 6.1 | 0.2% | Nov 18, 2025 | The ArtiBot Free Chat Bot for WebSites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMess... |
| CVE-2025-11868 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The everviz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `everviz` shortcode attributes in ... |
| CVE-2025-8404 | MEDIUM | 5.5 | 0.3% | Nov 18, 2025 | Stack buffer overflow vulnerability exists in the Supermicro BMC Shared library. An authenticated attacker with access t... |
| CVE-2025-11267 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_veu_custom_... |
| CVE-2025-11265 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_cta... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now