2025 CVE Vulnerabilities
45,344 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48347 | MEDIUM | 6.5 | 0.2% | Aug 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vincent Mimoun-Pra... |
| CVE-2025-48327 | MEDIUM | 5.3 | 0.3% | Aug 28, 2025 | Missing Authorization vulnerability in inkthemes WP Mailgun SMTP wp-mailgun-smtp allows Accessing Functionality Not Prop... |
| CVE-2025-48324 | MEDIUM | 5.9 | 0.2% | Aug 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in khashabawy tli.tl ... |
| CVE-2025-48323 | MEDIUM | 5.9 | 0.2% | Aug 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md Abunaser Khan A... |
| CVE-2025-48322 | MEDIUM | 6.5 | 0.2% | Aug 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Finn Dohrn Statify... |
| CVE-2025-48319 | MEDIUM | 5.9 | 0.2% | Aug 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gslauraspeck Mesa ... |
| CVE-2025-48318 | MEDIUM | 4.3 | 0.1% | Aug 28, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in shen2 多说社会化评论框 duoshuo allows Cross Site Request Forgery.This issue a... |
| CVE-2025-48316 | MEDIUM | 6.5 | 0.2% | Aug 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ItayXD Responsive ... |
| CVE-2025-48315 | MEDIUM | 6.5 | 0.2% | Aug 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stanton119 WordPre... |
| CVE-2025-48314 | MEDIUM | 5.9 | 0.2% | Aug 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in salubrio Add Code ... |
| CVE-2025-48313 | MEDIUM | 5.9 | 0.2% | Aug 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kevin heath Tripad... |
| CVE-2025-48312 | MEDIUM | 6.5 | 0.2% | Aug 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 文派翻译(WP Chinese Tr... |
| CVE-2025-48310 | MEDIUM | 4.3 | 0.1% | Aug 28, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in wptableeditor Table Editor wp-table-editor allows Cross Site Request ... |
| CVE-2025-48305 | MEDIUM | 5.9 | 0.2% | Aug 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vikingjs Goal Trac... |
| CVE-2025-48110 | MEDIUM | 6.5 | 0.2% | Aug 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mibuthu Link View ... |
| CVE-2025-9376 | MEDIUM | 6.5 | 0.3% | Aug 28, 2025 | The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to... |
| CVE-2025-55175 | MEDIUM | 6.1 | 0.2% | Aug 28, 2025 | QuickCMS is vulnerable to Reflected XSS via sLangEdit parameter in admin's panel functionality. A malicious attacker can... |
| CVE-2025-54544 | MEDIUM | 4.8 | 0.2% | Aug 28, 2025 | QuickCMS is vulnerable to Stored XSS via aDirFilesDescriptions parameter in files editor functionality. Malicious attack... |
| CVE-2025-54543 | MEDIUM | 4.8 | 0.2% | Aug 28, 2025 | QuickCMS is vulnerable to Stored XSS via sDescriptionMeta parameter in page editor SEO functionality. Malicious attacker... |
| CVE-2025-54542 | MEDIUM | 5.5 | 0.1% | Aug 28, 2025 | QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser hist... |
| CVE-2025-54541 | MEDIUM | 4.3 | 0.1% | Aug 28, 2025 | QuickCMS is vulnerable to Cross-Site Request Forgery in page deletion functionality. Malicious attacker can craft specia... |
| CVE-2025-54540 | MEDIUM | 6.1 | 0.2% | Aug 28, 2025 | QuickCMS is vulnerable to Reflected XSS via sSort parameter in admin's panel functionality. A malicious attacker can cra... |
| CVE-2025-52460 | MEDIUM | 6.9 | 0.3% | Aug 28, 2025 | Files or directories accessible to external parties issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a... |
| CVE-2025-8073 | MEDIUM | 6.4 | 0.2% | Aug 28, 2025 | The Dynamic AJAX Product Filters for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2025-6255 | MEDIUM | 6.4 | 0.2% | Aug 28, 2025 | The Dynamic AJAX Product Filters for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now