2025 CVE Vulnerabilities
45,168 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9627 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The Run Log plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1... |
| CVE-2025-9623 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The Admin in English with Switch plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2025-9620 | MEDIUM | 6.1 | 0.1% | Sep 11, 2025 | The Seo Monster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3... |
| CVE-2025-9617 | MEDIUM | 5.3 | 0.1% | Sep 11, 2025 | The Publish approval plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi... |
| CVE-2025-9451 | MEDIUM | 6.5 | 0.3% | Sep 11, 2025 | The Smartcat Translator for WPML plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parame... |
| CVE-2025-9128 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The eID Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up... |
| CVE-2025-9123 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The CBX Map for Google Map & OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pop... |
| CVE-2025-8721 | MEDIUM | 6.4 | 0.3% | Sep 11, 2025 | The Workable Api plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's workable_jobs shortc... |
| CVE-2025-8692 | MEDIUM | 4.9 | 0.4% | Sep 11, 2025 | The Coupon API plugin for WordPress is vulnerable to SQL Injection via the ‘log_duration’ parameter in all versions up t... |
| CVE-2025-8691 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The WP Scriptcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' parameter in all versi... |
| CVE-2025-8689 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The Elements Plus! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Comparison, ... |
| CVE-2025-8686 | MEDIUM | 6.4 | 0.3% | Sep 11, 2025 | The WP Easy FAQs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's WP_EASY_FAQ shortcod... |
| CVE-2025-8492 | MEDIUM | 5.3 | 0.3% | Sep 11, 2025 | The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable ... |
| CVE-2025-8481 | MEDIUM | 4.3 | 0.1% | Sep 11, 2025 | The Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid plugin for WordPress is vulnerable to Cross-Site... |
| CVE-2025-8445 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The Countdown Timer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'countdown_l... |
| CVE-2025-8423 | MEDIUM | 5.4 | 0.3% | Sep 11, 2025 | The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ... |
| CVE-2025-8398 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The azurecurve BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode... |
| CVE-2025-8392 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The Mitfahrgelegenheit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘date’ parameter in all... |
| CVE-2025-8318 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The Jobify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘keyword’ parameter in all versions... |
| CVE-2025-8316 | MEDIUM | 6.4 | 0.3% | Sep 11, 2025 | The Certifica WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘evento’ parameter in all ver... |
| CVE-2025-8215 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The Responsive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widge... |
| CVE-2025-5801 | MEDIUM | 6.4 | 0.3% | Sep 11, 2025 | The Digital Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘column’ parameter... |
| CVE-2025-0763 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The Ultimate Classified Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missin... |
| CVE-2025-8479 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The Zoho Flow plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.14.1.... |
| CVE-2025-9034 | MEDIUM | 6.1 | 0.2% | Sep 11, 2025 | The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now