2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12452MEDIUM6.1The Visit Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missin...
CVE-2025-12416MEDIUM6.1The Pagerank Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Request Forgery in a...
CVE-2025-12415MEDIUM6.1The MapMap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. T...
CVE-2025-12413MEDIUM5.4The Social Media WPCF7 Stop Words plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to...
CVE-2025-12412MEDIUM6.1The Top Bar Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2025-12410MEDIUM6.1The SH Contextual Help plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2025-12403MEDIUM6.1The Associados Amazon Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and...
CVE-2025-12402MEDIUM6.1The LinkedIn Resume plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin...
CVE-2025-12400MEDIUM6.1The LMB^Box Smileys plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin...
CVE-2025-12396MEDIUM4.4The clubmember plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t...
CVE-2025-12393MEDIUM4.4The Free Quotation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions ...
CVE-2025-12389MEDIUM4.3The Import Export For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2025-12371MEDIUM4.4The Nari Accountant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via account settings in all versio...
CVE-2025-12369MEDIUM6.4The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `geojsonmarker`...
CVE-2025-12350MEDIUM5.3The DominoKit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax...
CVE-2025-12188MEDIUM4.3The Posts Navigation Links for Sections and Headings – Free by WP Masters plugin for WordPress is vulnerable to Cross-Si...
CVE-2025-12157MEDIUM5.3The Simple User Capabilities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca...
CVE-2025-12156MEDIUM4.3The Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One plugin for WordPress is vulnerable to un...
CVE-2025-12065MEDIUM4.4The WP Carticon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carticon_js_script' parameter...
CVE-2025-11812MEDIUM6.4The Reuse Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'reuse_builder_single_post_t...
CVE-2025-11758MEDIUM6.5The All in One Time Clock Lite plugin for WordPress is vulnerable to unauthorized access due to a missing authorization ...
CVE-2025-11753MEDIUM4.4The Bootstrap Multi-language Responsive Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2025-47370MEDIUM6.5Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.
CVE-2025-47362MEDIUM6.1Information disclosure while processing message from client with invalid payload.
CVE-2025-27064MEDIUM6.1Information disclosure while registering commands from clients with diag through diagHal.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now