2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62042 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event p... |
| CVE-2025-62027 | MEDIUM | 5.4 | 0.2% | Oct 22, 2025 | Missing Authorization vulnerability in StellarWP Event Tickets event-tickets.This issue affects Event Tickets: from n/a ... |
| CVE-2025-62026 | MEDIUM | 4.3 | 0.3% | Oct 22, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Blockspare Blockspare blockspare allows Retrieve Embe... |
| CVE-2025-62024 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jonathan Jernigan ... |
| CVE-2025-62021 | MEDIUM | 4.3 | 0.2% | Oct 22, 2025 | Missing Authorization vulnerability in Made Neat Acknowledgify acknowledgify.This issue affects Acknowledgify: from n/a ... |
| CVE-2025-62019 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Missing Authorization vulnerability in WPZOOM Recipe Card Blocks for Gutenberg & Elementor recipe-card-blocks-by-wpzoom.... |
| CVE-2025-62013 | MEDIUM | 4.3 | 0.2% | Oct 22, 2025 | Missing Authorization vulnerability in POSIMYTH UiChemy uichemy.This issue affects UiChemy: from n/a through <= 4.0.0. |
| CVE-2025-62009 | MEDIUM | 4.3 | 0.1% | Oct 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") UPC/EAN/GTIN Code Generator upc-ean... |
| CVE-2025-62006 | MEDIUM | 5.4 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in VeronaLabs WP SMS wp-sms.This issue affects WP SMS: from n/a through <= 7.0.1. |
| CVE-2025-60176 | MEDIUM | 5.9 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tattersoftware WP ... |
| CVE-2025-60151 | MEDIUM | 4.7 | 0.2% | Oct 22, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allow... |
| CVE-2025-60135 | MEDIUM | 5.9 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NIKITAS GEORGOPOUL... |
| CVE-2025-60134 | MEDIUM | 4.3 | 0.1% | Oct 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in John James Jacoby WP Media Categories wp-media-categories allows Cros... |
| CVE-2025-60131 | MEDIUM | 5.9 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoefff Werk aan de... |
| CVE-2025-59593 | MEDIUM | 5.9 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Coli... |
| CVE-2025-59578 | MEDIUM | 5.8 | 0.3% | Oct 22, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in wpdesk ShopMagic shopmagic-for-woocommerce allows Ret... |
| CVE-2025-59575 | MEDIUM | 4.9 | 0.3% | Oct 22, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stylemix MasterStudy LMS mas... |
| CVE-2025-58970 | MEDIUM | 6.3 | 0.2% | Oct 22, 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in AmentoTech Doctreat doctr... |
| CVE-2025-53424 | MEDIUM | 6.5 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in vanquish WooCommerce Orders & Customers Exporter woocommerce-orders-ei allows Exp... |
| CVE-2025-53421 | MEDIUM | 6.5 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in PickPlugins Accordion accordions allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-53236 | MEDIUM | 6.3 | 0.2% | Oct 22, 2025 | Missing Authorization vulnerability in AndonDesign UDesign Core u-design-core allows Exploiting Incorrectly Configured A... |
| CVE-2025-53232 | MEDIUM | 5.8 | 0.3% | Oct 22, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in inkthemes WP Gmail SMTP wp-gmail-smtp allows Retrieve... |
| CVE-2025-53218 | MEDIUM | 5.8 | 0.3% | Oct 22, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal AppExperts appexperts allows Retrieve Embe... |
| CVE-2025-52757 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Missing Authorization vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Exploiti... |
| CVE-2025-52752 | MEDIUM | 6.5 | 0.3% | Oct 22, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThemeAtelier IDonatePro idon... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now