2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64292 | MEDIUM | 6.5 | 0.1% | Nov 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PascalBajorat Anal... |
| CVE-2025-64277 | MEDIUM | 5.3 | 0.2% | Nov 13, 2025 | Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2025-64276 | MEDIUM | 6.5 | 0.2% | Nov 13, 2025 | Missing Authorization vulnerability in Ays Pro Survey Maker survey-maker allows Exploiting Incorrectly Configured Access... |
| CVE-2025-64275 | MEDIUM | 6.5 | 0.1% | Nov 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking ... |
| CVE-2025-64274 | MEDIUM | 4.3 | 0.2% | Nov 13, 2025 | Missing Authorization vulnerability in wpkoithemes WPKoi Templates for Elementor wpkoi-templates-for-elementor allows Ex... |
| CVE-2025-64271 | MEDIUM | 6.5 | 0.1% | Nov 13, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in HasThemes WP Plugin Manager wp-plugin-manager allows Cross Site Reque... |
| CVE-2025-64269 | MEDIUM | 4.3 | 0.2% | Nov 13, 2025 | Missing Authorization vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Exploit... |
| CVE-2025-64267 | MEDIUM | 4.3 | 0.2% | Nov 13, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPSwings WooCommerce Ultimat... |
| CVE-2025-64265 | MEDIUM | 4.3 | 0.2% | Nov 13, 2025 | Missing Authorization vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorre... |
| CVE-2025-64264 | MEDIUM | 5.9 | 0.1% | Nov 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman Popup addon f... |
| CVE-2025-64263 | MEDIUM | 5.4 | 0.2% | Nov 13, 2025 | Missing Authorization vulnerability in PluginEver WP Content Pilot wp-content-pilot allows Exploiting Incorrectly Config... |
| CVE-2025-64262 | MEDIUM | 6.5 | 0.1% | Nov 13, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ramon fincken Auto Prune Posts auto-prune-posts allows Cross Site Req... |
| CVE-2025-64261 | MEDIUM | 5.4 | 0.2% | Nov 13, 2025 | Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Explo... |
| CVE-2025-64259 | MEDIUM | 5.3 | 0.2% | Nov 13, 2025 | Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configu... |
| CVE-2025-8397 | MEDIUM | 6.4 | 0.2% | Nov 13, 2025 | The Save as PDF Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's restpackpdfbut... |
| CVE-2025-12015 | MEDIUM | 4.3 | 0.2% | Nov 13, 2025 | The Convert WebP & AVIF | Quicq | Best image optimizer and compression plugin | Improve your Google Pagespeed plugin for... |
| CVE-2025-11769 | MEDIUM | 6.4 | 0.2% | Nov 13, 2025 | The WordPress Content Flipper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bgcolor' shortc... |
| CVE-2025-11260 | MEDIUM | 5.3 | 0.3% | Nov 13, 2025 | The WP Headless CMS Framework plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, a... |
| CVE-2025-10295 | MEDIUM | 6.4 | 0.2% | Nov 13, 2025 | The Angel – Fashion Model Agency WordPress CMS Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting th... |
| CVE-2025-12681 | MEDIUM | 5.3 | 0.3% | Nov 13, 2025 | The Comment Edit Core – Simple Comment Editing plugin for WordPress is vulnerable to Sensitive Information Exposure in a... |
| CVE-2025-12620 | MEDIUM | 4.9 | 0.3% | Nov 13, 2025 | The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection ... |
| CVE-2025-12891 | MEDIUM | 5.3 | 0.2% | Nov 13, 2025 | The Survey Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on ... |
| CVE-2025-12979 | MEDIUM | 5.3 | 0.2% | Nov 13, 2025 | The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability che... |
| CVE-2025-12892 | MEDIUM | 5.3 | 0.2% | Nov 13, 2025 | The Survey Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che... |
| CVE-2025-12536 | MEDIUM | 5.3 | 0.7% | Nov 13, 2025 | The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now