2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11876 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Mailgun Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mailgun_su... |
| CVE-2025-10583 | LOW | 3.5 | 0.2% | Dec 12, 2025 | The WP Fastest Cache Premium plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an... |
| CVE-2025-67737 | LOW | 3.7 | 0.2% | Dec 12, 2025 | AzuraCast is a self-hosted, all-in-one web radio management suite. Versions 0.23.1 mistakenly include an API endpoint th... |
| CVE-2025-67728 | CRITICAL | 9.8 | 0.6% | Dec 12, 2025 | Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unau... |
| CVE-2025-67727 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior t... |
| CVE-2025-67726 | HIGH | 7.5 | 0.4% | Dec 12, 2025 | Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algor... |
| CVE-2025-14356 | MEDIUM | 4.3 | 0.3% | Dec 12, 2025 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing c... |
| CVE-2025-14068 | HIGH | 7.5 | 0.3% | Dec 12, 2025 | The WPNakama plugin for WordPress is vulnerable to time-based SQL Injection via the 'order_by' parameter in all versions... |
| CVE-2025-13660 | MEDIUM | 5.3 | 0.3% | Dec 12, 2025 | The Guest Support plugin for WordPress is vulnerable to User Email Disclosure in versions up to, and including, 1.2.3. T... |
| CVE-2025-12655 | MEDIUM | 5.3 | 0.2% | Dec 12, 2025 | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write via a missing authoriza... |
| CVE-2025-12570 | HIGH | 7.2 | 0.2% | Dec 12, 2025 | The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all... |
| CVE-2025-67725 | HIGH | 7.5 | 0.4% | Dec 12, 2025 | Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously... |
| CVE-2025-67724 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason ... |
| CVE-2025-67508 | HIGH | 8.4 | 0.2% | Dec 12, 2025 | gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools. Wh... |
| CVE-2025-10684 | MEDIUM | 4.3 | 0.1% | Dec 12, 2025 | The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX ac... |
| CVE-2025-66492 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | Masa CMS is an open source Enterprise Content Management platform. Versions 7.2.8 and below, 7.3.1 through 7.3.13, 7.4.0... |
| CVE-2025-66284 | MEDIUM | 5.4 | 0.1% | Dec 12, 2025 | Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud p... |
| CVE-2025-65120 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud... |
| CVE-2025-64781 | MEDIUM | 5.1 | 0.2% | Dec 12, 2025 | In GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to v... |
| CVE-2025-62192 | MEDIUM | 5.4 | 0.2% | Dec 12, 2025 | SQL Injection vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.... |
| CVE-2025-61987 | MEDIUM | 6.9 | 0.1% | Dec 12, 2025 | GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5... |
| CVE-2025-61950 | MEDIUM | 5.3 | 0.2% | Dec 12, 2025 | In GroupSession, a Circular notice can be created with its memo field non-editable, but the authorization check is impro... |
| CVE-2025-58576 | MEDIUM | 5.1 | 0.1% | Dec 12, 2025 | Cross-site request forgery vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud pri... |
| CVE-2025-57883 | MEDIUM | 5.1 | 0.2% | Dec 12, 2025 | Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud... |
| CVE-2025-54407 | MEDIUM | 5.1 | 0.2% | Dec 12, 2025 | Stored cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud pr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now