2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-63710MEDIUM6.5The send_message.php endpoint in SourceCodester Simple Public Chat Room 1.0 is vulnerable to Cross-Site Request Forgery ...
CVE-2025-63709MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Simple To-Do List System 1.0 in the "Add Tasks" text...
CVE-2025-41001MEDIUM5.4Cross Site Scripting (XSS) vulnerability stored in SOPlanning v1.53.02, which consist of a stored XSS due to a lack of p...
CVE-2025-41107MEDIUM5.4Stored Cross Site Scripting (XSS) vulnerability in Smart School 7.0 due to lack of proper validation of user input when ...
CVE-2025-12924MEDIUM6.5A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. This issue affects the fu...
CVE-2025-12923MEDIUM4.9A vulnerability was determined in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function resourceDownl...
CVE-2025-12920MEDIUM4.8A flaw has been found in qianfox FoxCMS up to 1.2.16. Affected by this vulnerability is the function add/edit of the fil...
CVE-2025-12918MEDIUM5.3A security flaw has been discovered in yungifez Skuul School Management System up to 2.6.5. The impacted element is an u...
CVE-2025-12917MEDIUM4.3A vulnerability was identified in TOZED ZLT T10 T10PLUS_3.04.15. The affected element is an unknown function of the file...
CVE-2025-12915MEDIUM6.4A vulnerability was found in 70mai X200 up to 20251019. This issue affects some unknown processing of the component Init...
CVE-2025-12914MEDIUM4.7A vulnerability has been found in aaPanel BaoTa up to 11.2.x. This vulnerability affects unknown code of the file /datab...
CVE-2025-12837MEDIUM6.4The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Call To Actio...
CVE-2025-12643MEDIUM6.4The Saphali LiqPay for donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'saphali_liqpay'...
CVE-2025-12092MEDIUM6.5The CYAN Backup plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation i...
CVE-2025-11980MEDIUM4.9The Quick Featured Images plugin for WordPress is vulnerable to SQL Injection via the 'delete_orphaned' function in all ...
CVE-2025-11448MEDIUM4.3The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification ...
CVE-2025-12098MEDIUM5.3The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Sensitive I...
CVE-2025-12621MEDIUM5.3The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of ...
CVE-2025-12498MEDIUM4.3The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized booking note c...
CVE-2025-7663MEDIUM6.5The Ovatheme Events Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check ...
CVE-2025-12353MEDIUM5.3The WPFunnels – The Easiest Funnel Builder For WordPress And WooCommerce To Collect Leads And Increase Sales plugin for ...
CVE-2025-12193MEDIUM6.1The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mp' parameter in all ver...
CVE-2025-12177MEDIUM5.3The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the d...
CVE-2025-12167MEDIUM4.3The Contact Form 7 AWeber Extension plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2025-12125MEDIUM4.4The HTML Forms – Simple WordPress Forms Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now