2025 CVE Vulnerabilities
45,152 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9630 | MEDIUM | 4.3 | 0.1% | Oct 3, 2025 | The WP SinoType plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1... |
| CVE-2025-9372 | MEDIUM | 5.5 | 0.2% | Oct 3, 2025 | The Ultimate Multi Design Video Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versio... |
| CVE-2025-9333 | MEDIUM | 5.5 | 0.2% | Oct 3, 2025 | The Smart Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t... |
| CVE-2025-9332 | MEDIUM | 5.5 | 0.2% | Oct 3, 2025 | The Interactive Human Anatomy with Clickable Body Parts plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2025-9206 | MEDIUM | 6.4 | 0.2% | Oct 3, 2025 | The Meks Easy Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title field in all ver... |
| CVE-2025-9204 | MEDIUM | 6.4 | 0.2% | Oct 3, 2025 | The X Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Youtube Video ID fi... |
| CVE-2025-9199 | MEDIUM | 6.5 | 0.3% | Oct 3, 2025 | The Woo superb slideshow transition gallery with random effect plugin for WordPress is vulnerable to SQL Injection via t... |
| CVE-2025-9198 | MEDIUM | 6.5 | 0.3% | Oct 3, 2025 | The Wp cycle text announcement plugin for WordPress is vulnerable to SQL Injection via the 'cycle-text' shortcode in all... |
| CVE-2025-9194 | MEDIUM | 4.3 | 0.2% | Oct 3, 2025 | The Constructor theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check... |
| CVE-2025-9130 | MEDIUM | 6.4 | 0.3% | Oct 3, 2025 | The Unify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin for WordPress's unify_checkou... |
| CVE-2025-9129 | MEDIUM | 6.4 | 0.2% | Oct 3, 2025 | The Flexi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin for WordPress's flexi-form-ta... |
| CVE-2025-9080 | MEDIUM | 6.4 | 0.3% | Oct 3, 2025 | The Generic Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widget fields in ver... |
| CVE-2025-9077 | MEDIUM | 6.4 | 0.3% | Oct 3, 2025 | The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Animated ... |
| CVE-2025-9045 | MEDIUM | 6.4 | 0.3% | Oct 3, 2025 | The Easy Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget parameter... |
| CVE-2025-8776 | MEDIUM | 6.4 | 0.2% | Oct 3, 2025 | The Epic Bootstrap Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘icol’ parameter in... |
| CVE-2025-8669 | MEDIUM | 4.3 | 0.2% | Oct 3, 2025 | The Customify theme for WordPress is vulnerable to Cross-Site Request Forgery in version 0.4.11. This is due to missing ... |
| CVE-2025-7825 | MEDIUM | 6.3 | 0.2% | Oct 3, 2025 | The Schema Plugin For Divi, Gutenberg & Shortcodes plugin for WordPress is vulnerable to Object Instantiation in all ver... |
| CVE-2025-49641 | MEDIUM | 4.3 | 0.3% | Oct 3, 2025 | A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refre... |
| CVE-2025-27236 | MEDIUM | 6.5 | 0.3% | Oct 3, 2025 | A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have ... |
| CVE-2025-27231 | MEDIUM | 4.9 | 0.4% | Oct 3, 2025 | The LDAP 'Bind password' value cannot be read after saving, but a Super Admin account can leak it by changing LDAP 'Host... |
| CVE-2025-10311 | MEDIUM | 4.3 | 0.1% | Oct 3, 2025 | The Comment Info Detector plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-10309 | MEDIUM | 4.3 | 0.1% | Oct 3, 2025 | The PayPal Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2025-10302 | MEDIUM | 4.3 | 0.1% | Oct 3, 2025 | The Ultimate Viral Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2025-10212 | MEDIUM | 5.3 | 0.3% | Oct 3, 2025 | The SiteAlert (Formerly WP Health) plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca... |
| CVE-2025-10192 | MEDIUM | 6.4 | 0.3% | Oct 3, 2025 | The WP Photo Effects plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wppe_effect' sh... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now