2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62898 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maarten Links shor... |
| CVE-2025-62897 | MEDIUM | 5.3 | 0.3% | Oct 27, 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Brecht WP Recipe Maker wp... |
| CVE-2025-62895 | MEDIUM | 5.3 | 0.3% | Oct 27, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows ... |
| CVE-2025-62894 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magicoders ACF Rec... |
| CVE-2025-62892 | MEDIUM | 5.3 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Accessing Functi... |
| CVE-2025-62891 | MEDIUM | 4.3 | 0.1% | Oct 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Jory Hogeveen Off-Canvas Sidebars & Menus (Slidebars) off-canvas-side... |
| CVE-2025-62890 | MEDIUM | 4.3 | 0.1% | Oct 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce Brands for WooCommerce premmerce-woocommerce-bran... |
| CVE-2025-62889 | MEDIUM | 6.5 | 0.3% | Oct 27, 2025 | Missing Authorization vulnerability in KingAddons.com King Addons for Elementor king-addons allows Exploiting Incorrectl... |
| CVE-2025-62887 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KingAddons.com Kin... |
| CVE-2025-62885 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RexTheme WP VR wpv... |
| CVE-2025-62884 | MEDIUM | 5.3 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates woo-coupon-usage allows Accessing Func... |
| CVE-2025-62883 | MEDIUM | 4.3 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in Premmerce Premmerce User Roles premmerce-user-roles allows Exploiting Incorrectly... |
| CVE-2025-62882 | MEDIUM | 4.3 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Explo... |
| CVE-2025-62881 | MEDIUM | 4.3 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay allows Exploiting Incorrectly C... |
| CVE-2025-12202 | MEDIUM | 4.3 | 0.3% | Oct 27, 2025 | A security flaw has been discovered in ajayrandhawa User-Management-PHP-MYSQL web up to fedcf58797bf2791591606f7b61fdad9... |
| CVE-2025-6601 | MEDIUM | 6.5 | 0.3% | Oct 27, 2025 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that ... |
| CVE-2025-11974 | MEDIUM | 6.5 | 0.4% | Oct 27, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18.4 before 18.4.3, and 1... |
| CVE-2025-11971 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | GitLab has remediated an issue in GitLab EE affecting all versions from 10.6 before 18.3.5, 18.4 before 18.4.3, and 18.5... |
| CVE-2025-12284 | MEDIUM | 6.1 | 0.2% | Oct 26, 2025 | Lack of Input Validation in the web UI might lead to potential exploitation.This issue affects BLU-IC2: through 1.19.5; ... |
| CVE-2025-12278 | MEDIUM | 6.5 | 0.2% | Oct 26, 2025 | Logout Functionality not Working.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-55757 | MEDIUM | 6.1 | 0.2% | Oct 25, 2025 | A unauthenticated reflected XSS vulnerability in VirtueMart 1.0.0-4.4.10 for Joomla was discovered. |
| CVE-2025-12216 | MEDIUM | 5.5 | 0.2% | Oct 25, 2025 | Malicious / Malformed App can be Installed but not Uninstalled/may lead to unavailability.This issue affects BLU-IC2: th... |
| CVE-2025-11897 | MEDIUM | 6.4 | 0.2% | Oct 25, 2025 | The The7 — Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2025-8483 | MEDIUM | 6.3 | 0.2% | Oct 25, 2025 | The The Discussion Board – WordPress Forum Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in... |
| CVE-2025-12034 | MEDIUM | 4.4 | 0.2% | Oct 25, 2025 | The Fast Velocity Minify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now