2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-11876MEDIUM6.4The Mailgun Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mailgun_su...
CVE-2025-10583LOW3.5The WP Fastest Cache Premium plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an...
CVE-2025-67737LOW3.7AzuraCast is a self-hosted, all-in-one web radio management suite. Versions 0.23.1 mistakenly include an API endpoint th...
CVE-2025-67728CRITICAL9.8Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unau...
CVE-2025-67727CRITICAL9.8Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior t...
CVE-2025-67726HIGH7.5Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algor...
CVE-2025-14356MEDIUM4.3The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing c...
CVE-2025-14068HIGH7.5The WPNakama plugin for WordPress is vulnerable to time-based SQL Injection via the 'order_by' parameter in all versions...
CVE-2025-13660MEDIUM5.3The Guest Support plugin for WordPress is vulnerable to User Email Disclosure in versions up to, and including, 1.2.3. T...
CVE-2025-12655MEDIUM5.3The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write via a missing authoriza...
CVE-2025-12570HIGH7.2The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all...
CVE-2025-67725HIGH7.5Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously...
CVE-2025-67724MEDIUM6.1Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason ...
CVE-2025-67508HIGH8.4gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools. Wh...
CVE-2025-10684MEDIUM4.3The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX ac...
CVE-2025-66492MEDIUM6.1Masa CMS is an open source Enterprise Content Management platform. Versions 7.2.8 and below, 7.3.1 through 7.3.13, 7.4.0...
CVE-2025-66284MEDIUM5.4Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud p...
CVE-2025-65120MEDIUM6.1Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud...
CVE-2025-64781MEDIUM5.1In GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to v...
CVE-2025-62192MEDIUM5.4SQL Injection vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3....
CVE-2025-61987MEDIUM6.9GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5...
CVE-2025-61950MEDIUM5.3In GroupSession, a Circular notice can be created with its memo field non-editable, but the authorization check is impro...
CVE-2025-58576MEDIUM5.1Cross-site request forgery vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud pri...
CVE-2025-57883MEDIUM5.1Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud...
CVE-2025-54407MEDIUM5.1Stored cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud pr...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now