2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11519 | MEDIUM | 4.3 | 0.3% | Oct 18, 2025 | The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vuln... |
| CVE-2025-11510 | MEDIUM | 4.3 | 0.2% | Oct 18, 2025 | The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized modific... |
| CVE-2025-11372 | MEDIUM | 6.5 | 0.4% | Oct 18, 2025 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to modification of data in all versions up to, ... |
| CVE-2025-11270 | MEDIUM | 6.4 | 0.2% | Oct 18, 2025 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stor... |
| CVE-2025-10187 | MEDIUM | 4.9 | 0.4% | Oct 18, 2025 | The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' pa... |
| CVE-2025-10006 | MEDIUM | 5.4 | 0.2% | Oct 18, 2025 | The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rev_slider... |
| CVE-2025-11937 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-11857 | MEDIUM | 6.4 | 0.3% | Oct 18, 2025 | The XX2WP Integration Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mxp_fb2wp_display... |
| CVE-2025-11742 | MEDIUM | 4.3 | 0.3% | Oct 18, 2025 | The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missin... |
| CVE-2025-11738 | MEDIUM | 5.3 | 0.4% | Oct 18, 2025 | The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and includ... |
| CVE-2025-62671 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62670 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62669 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Central... |
| CVE-2025-62668 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows R... |
| CVE-2025-62667 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62666 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in The Wikimedia Foundation Mediawiki - CirrusSearch ... |
| CVE-2025-62664 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62663 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62662 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-11361 | MEDIUM | 6.4 | 0.3% | Oct 18, 2025 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Serv... |
| CVE-2025-62665 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-11378 | MEDIUM | 5.4 | 0.3% | Oct 18, 2025 | The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized... |
| CVE-2025-62652 | MEDIUM | 5.9 | 0.4% | Oct 17, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62651 | MEDIUM | 5.8 | 0.4% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 does not implement access control for th... |
| CVE-2025-62649 | MEDIUM | 5.8 | 0.5% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now