2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12655MEDIUM5.3The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write via a missing authoriza...
CVE-2025-12570HIGH7.2The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all...
CVE-2025-67725HIGH7.5Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously...
CVE-2025-67724MEDIUM6.1Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason ...
CVE-2025-67508HIGH8.4gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools. Wh...
CVE-2025-10684MEDIUM4.3The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX ac...
CVE-2025-66492MEDIUM6.1Masa CMS is an open source Enterprise Content Management platform. Versions 7.2.8 and below, 7.3.1 through 7.3.13, 7.4.0...
CVE-2025-66284MEDIUM5.4Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud p...
CVE-2025-65120MEDIUM6.1Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud...
CVE-2025-64781MEDIUM5.1In GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to v...
CVE-2025-62192MEDIUM5.4SQL Injection vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3....
CVE-2025-61987MEDIUM6.9GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5...
CVE-2025-61950MEDIUM5.3In GroupSession, a Circular notice can be created with its memo field non-editable, but the authorization check is impro...
CVE-2025-58576MEDIUM5.1Cross-site request forgery vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud pri...
CVE-2025-57883MEDIUM6.1Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud...
CVE-2025-54407MEDIUM6.1Stored cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud pr...
CVE-2025-53523MEDIUM5.4Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud p...
CVE-2025-14467MEDIUM4.4The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including...
CVE-2025-14393MEDIUM6.4The Wpik WordPress Basic Ajax Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dname' par...
CVE-2025-14392MEDIUM4.3The Simple Theme Changer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2025-14391MEDIUM4.3The Simple Theme Changer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi...
CVE-2025-14354MEDIUM4.3The Resource Library for Logged In Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2025-14344CRITICAL9.8The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient f...
CVE-2025-14170MEDIUM4.3The Vimeo SimpleGallery plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including...
CVE-2025-14166MEDIUM5.3The WPMasterToolKit plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.13....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now