2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8566 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via parameters in the ... |
| CVE-2025-8560 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The FancyTabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all version... |
| CVE-2025-8559 | MEDIUM | 6.5 | 0.4% | Sep 30, 2025 | The All in One Music Player plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1... |
| CVE-2025-8214 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The The Pack Elementor addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typing L... |
| CVE-2025-8119 | MEDIUM | 4.3 | 0.1% | Sep 30, 2025 | PAD CMS is vulnerable to Cross-Site Request Forgery in reset password's functionality. Malicious attacker can craft spec... |
| CVE-2025-8118 | MEDIUM | 6.5 | 0.2% | Sep 30, 2025 | PAD CMS implements weak client-side brute-force protection by utilizing two cookies: login_count and login_timeout. Inf... |
| CVE-2025-8116 | MEDIUM | 6.1 | 0.2% | Sep 30, 2025 | PAD CMS is vulnerable to Reflected XSS in printing and save to PDF functionality. Malicious attacker can craft special U... |
| CVE-2025-6941 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2025-6815 | MEDIUM | 5.5 | 0.2% | Sep 30, 2025 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2025-59956 | MEDIUM | 6.5 | 0.4% | Sep 30, 2025 | AgentAPI is an HTTP API for Claude Code, Goose, Aider, Gemini, Amp, and Codex. Versions 0.3.3 and below are susceptible ... |
| CVE-2025-41099 | MEDIUM | 6.5 | 0.3% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con... |
| CVE-2025-41097 | MEDIUM | 4.3 | 0.2% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con... |
| CVE-2025-41096 | MEDIUM | 4.3 | 0.2% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con... |
| CVE-2025-41095 | MEDIUM | 4.3 | 0.2% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con... |
| CVE-2025-41094 | MEDIUM | 4.3 | 0.2% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con... |
| CVE-2025-41093 | MEDIUM | 4.3 | 0.2% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con... |
| CVE-2025-41092 | MEDIUM | 4.3 | 0.2% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con... |
| CVE-2025-41091 | MEDIUM | 4.3 | 0.2% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con... |
| CVE-2025-11163 | MEDIUM | 4.3 | 0.2% | Sep 30, 2025 | The SmartCrawl SEO checker, analyzer & optimizer plugin for WordPress is vulnerable to unauthorized modification of data... |
| CVE-2025-10196 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The Survey Anyplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'surveyanyplace_e... |
| CVE-2025-10191 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The Big Post Shipping for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's... |
| CVE-2025-10189 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The BP Direct Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bpdm_login' shor... |
| CVE-2025-10182 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The dbview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dbview' shortcode in all ... |
| CVE-2025-10179 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The My AskAI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'myaskai' shortcode in a... |
| CVE-2025-10168 | MEDIUM | 6.4 | 0.3% | Sep 30, 2025 | The Any News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'any-ticker' shor... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now