2025 CVE Vulnerabilities

45,152 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-9630MEDIUM4.3The WP SinoType plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2025-9372MEDIUM5.5The Ultimate Multi Design Video Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versio...
CVE-2025-9333MEDIUM5.5The Smart Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t...
CVE-2025-9332MEDIUM5.5The Interactive Human Anatomy with Clickable Body Parts plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2025-9206MEDIUM6.4The Meks Easy Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title field in all ver...
CVE-2025-9204MEDIUM6.4The X Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Youtube Video ID fi...
CVE-2025-9199MEDIUM6.5The Woo superb slideshow transition gallery with random effect plugin for WordPress is vulnerable to SQL Injection via t...
CVE-2025-9198MEDIUM6.5The Wp cycle text announcement plugin for WordPress is vulnerable to SQL Injection via the 'cycle-text' shortcode in all...
CVE-2025-9194MEDIUM4.3The Constructor theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2025-9130MEDIUM6.4The Unify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin for WordPress's unify_checkou...
CVE-2025-9129MEDIUM6.4The Flexi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin for WordPress's flexi-form-ta...
CVE-2025-9080MEDIUM6.4The Generic Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widget fields in ver...
CVE-2025-9077MEDIUM6.4The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Animated ...
CVE-2025-9045MEDIUM6.4The Easy Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget parameter...
CVE-2025-8776MEDIUM6.4The Epic Bootstrap Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘icol’ parameter in...
CVE-2025-8669MEDIUM4.3The Customify theme for WordPress is vulnerable to Cross-Site Request Forgery in version 0.4.11. This is due to missing ...
CVE-2025-7825MEDIUM6.3The Schema Plugin For Divi, Gutenberg & Shortcodes plugin for WordPress is vulnerable to Object Instantiation in all ver...
CVE-2025-49641MEDIUM4.3A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refre...
CVE-2025-27236MEDIUM6.5A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have ...
CVE-2025-27231MEDIUM4.9The LDAP 'Bind password' value cannot be read after saving, but a Super Admin account can leak it by changing LDAP 'Host...
CVE-2025-10311MEDIUM4.3The Comment Info Detector plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-10309MEDIUM4.3The PayPal Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2025-10302MEDIUM4.3The Ultimate Viral Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2025-10212MEDIUM5.3The SiteAlert (Formerly WP Health) plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca...
CVE-2025-10192MEDIUM6.4The WP Photo Effects plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wppe_effect' sh...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now