2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67986 | MEDIUM | 5.9 | 0.2% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Barn2 Plugins Docu... |
| CVE-2025-67985 | MEDIUM | 5.3 | 0.3% | Dec 16, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Barn2 Plugins Document Library Lite document-library-l... |
| CVE-2025-67983 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visit... |
| CVE-2025-67976 | MEDIUM | 6.5 | 0.3% | Dec 16, 2025 | Missing Authorization vulnerability in Bob Watu Quiz watu allows Exploiting Incorrectly Configured Access Control Securi... |
| CVE-2025-67965 | MEDIUM | 5.3 | 0.3% | Dec 16, 2025 | Missing Authorization vulnerability in favethemes Homey Core homey-core allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-67962 | HIGH | 7.6 | 0.3% | Dec 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AIOSEO Plugin Team... |
| CVE-2025-67951 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Addo... |
| CVE-2025-67950 | HIGH | 8.5 | 0.3% | Dec 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi All In... |
| CVE-2025-67948 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in SendPulse SendPulse Email Ma... |
| CVE-2025-67929 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Exploitin... |
| CVE-2025-67912 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premio Stars Testi... |
| CVE-2025-66167 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Lottier lottier-gutenberg allows Exploiting Incorrectly Configured Acce... |
| CVE-2025-66166 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Lottier for Elementor lottier-elementor allows Exploiting Incorrectly C... |
| CVE-2025-66165 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Lottier for WPBakery lottier-wpbakery allows Exploiting Incorrectly Con... |
| CVE-2025-66164 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Laser laser allows Exploiting Incorrectly Configured Access Control Sec... |
| CVE-2025-66163 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Masker for Elementor masker-elementor allows Exploiting Incorrectly Con... |
| CVE-2025-66162 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Spoter for Elementor spoter-elementor allows Exploiting Incorrectly Con... |
| CVE-2025-66161 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Grider for Elementor grider-elementor allows Exploiting Incorrectly Con... |
| CVE-2025-66147 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Coder for Elementor coder-elementor allows Exploiting Incorrectly Confi... |
| CVE-2025-66134 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in NinjaTeam FileBird Pro filebird-pro allows Exploiting Incorrectly Configured Acce... |
| CVE-2025-66133 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-con... |
| CVE-2025-66132 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in FAPI Business s.r.o. FAPI Member fapi-member allows Ex... |
| CVE-2025-66131 | MEDIUM | 5.3 | 0.3% | Dec 16, 2025 | Missing Authorization vulnerability in yaadsarig Yaad Sarig Payment Gateway For WC yaad-sarig-payment-gateway-for-wc all... |
| CVE-2025-66130 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in etruel WP Views Counter wpecounter allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-66129 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in wppochipp Pochipp pochipp allows Exploiting Incorrectly Configured Access Control... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now