2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53523MEDIUM5.4Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud p...
CVE-2025-14467MEDIUM4.4The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including...
CVE-2025-14393MEDIUM6.4The Wpik WordPress Basic Ajax Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dname' par...
CVE-2025-14392MEDIUM4.3The Simple Theme Changer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2025-14391MEDIUM4.3The Simple Theme Changer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi...
CVE-2025-14354MEDIUM4.3The Resource Library for Logged In Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2025-14344CRITICAL9.8The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient f...
CVE-2025-14170MEDIUM4.3The Vimeo SimpleGallery plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including...
CVE-2025-14166MEDIUM5.3The WPMasterToolKit plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.13....
CVE-2025-14165MEDIUM4.3The Kirim.Email WooCommerce Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
CVE-2025-14162MEDIUM4.3The BMLT WordPress Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2025-14161MEDIUM4.3The Truefy Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2025-14160MEDIUM4.3The Upcoming for Calendly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-14158MEDIUM4.3The Coding Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-14143MEDIUM6.4The Ayo Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' parameter of the ay...
CVE-2025-14138MEDIUM6.1The WPLG Default Mail From plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_S...
CVE-2025-14137MEDIUM6.1The Simple AL Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']`...
CVE-2025-14132MEDIUM6.1The Category Dropdown List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_S...
CVE-2025-14129MEDIUM6.1The Like DisLike Voting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF...
CVE-2025-14125MEDIUM6.1The Complag plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable...
CVE-2025-14119MEDIUM6.4The App Landing Template Blocks for WPBakery (Visual Composer) Page Builder plugin for WordPress is vulnerable to Stored...
CVE-2025-14064MEDIUM5.4The BuddyTask plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capabi...
CVE-2025-14062MEDIUM4.3The Animated Pixel Marquee Creator plugin for WordPress is vulnerable to Cross-Site Request Forgery via the 'marquee' pa...
CVE-2025-14048MEDIUM4.4The SimplyConvert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'simplyconvert_hash' option ...
CVE-2025-14045MEDIUM4.3The URL Media Uploader plugin for WordPress is vulnerable to unauthorized safe file uploads due to a missing capability ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now