2025 CVE Vulnerabilities

45,168 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-9627MEDIUM4.3The Run Log plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1...
CVE-2025-9623MEDIUM4.3The Admin in English with Switch plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-9620MEDIUM6.1The Seo Monster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3...
CVE-2025-9617MEDIUM5.3The Publish approval plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi...
CVE-2025-9451MEDIUM6.5The Smartcat Translator for WPML plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parame...
CVE-2025-9128MEDIUM6.4The eID Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up...
CVE-2025-9123MEDIUM6.4The CBX Map for Google Map & OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pop...
CVE-2025-8721MEDIUM6.4The Workable Api plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's workable_jobs shortc...
CVE-2025-8692MEDIUM4.9The Coupon API plugin for WordPress is vulnerable to SQL Injection via the ‘log_duration’ parameter in all versions up t...
CVE-2025-8691MEDIUM6.4The WP Scriptcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' parameter in all versi...
CVE-2025-8689MEDIUM6.4The Elements Plus! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Comparison, ...
CVE-2025-8686MEDIUM6.4The WP Easy FAQs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's WP_EASY_FAQ shortcod...
CVE-2025-8492MEDIUM5.3The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable ...
CVE-2025-8481MEDIUM4.3The Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid plugin for WordPress is vulnerable to Cross-Site...
CVE-2025-8445MEDIUM6.4The Countdown Timer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'countdown_l...
CVE-2025-8423MEDIUM5.4The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2025-8398MEDIUM6.4The azurecurve BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode...
CVE-2025-8392MEDIUM6.4The Mitfahrgelegenheit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘date’ parameter in all...
CVE-2025-8318MEDIUM6.4The Jobify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘keyword’ parameter in all versions...
CVE-2025-8316MEDIUM6.4The Certifica WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘evento’ parameter in all ver...
CVE-2025-8215MEDIUM6.4The Responsive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widge...
CVE-2025-5801MEDIUM6.4The Digital Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘column’ parameter...
CVE-2025-0763MEDIUM4.3The Ultimate Classified Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missin...
CVE-2025-8479MEDIUM4.3The Zoho Flow plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.14.1....
CVE-2025-9034MEDIUM6.1The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now