2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-52712MEDIUM4.2Path Traversal: '.../...//' vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Pat...
CVE-2025-50040MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moshensky CF7 Spre...
CVE-2025-50031MEDIUM6.5Missing Authorization vulnerability in syedamirhussain91 DB Backup db-backup allows Exploiting Incorrectly Configured Ac...
CVE-2025-50029MEDIUM6.5Missing Authorization vulnerability in Ashish AI Tools artificial-intelligence-auto-content-generator allows Exploiting ...
CVE-2025-49437MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in worstguy WP LOL Ro...
CVE-2025-49433MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThanhD Supermalink...
CVE-2025-49061MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in perteus Porn Video...
CVE-2025-49053MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kadesthemes WP Air...
CVE-2025-49052MEDIUM4.3Missing Authorization vulnerability in Dariolee Netease Music netease-music allows Exploiting Incorrectly Configured Acc...
CVE-2025-49051MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in biscia7 Hide Text ...
CVE-2025-49048MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in inspectlet Inspect...
CVE-2025-49047MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in keeross DigitalOce...
CVE-2025-47610MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wetail WooCommerce...
CVE-2025-39483MEDIUM6.5Improper Control of Generation of Code ('Code Injection') vulnerability in imithemes Eventer eventer allows Code Injecti...
CVE-2025-30993MEDIUM6.5Missing Authorization vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customize...
CVE-2025-28987MEDIUM6.4Server-Side Request Forgery (SSRF) vulnerability in PressForward PressForward pressforward allows Server Side Request Fo...
CVE-2025-28962MEDIUM6.5Missing Authorization vulnerability in stefanoai Advanced Google Universal Analytics advanced-google-universal-analytics...
CVE-2025-7761MEDIUM5.1Lepszy BIP is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in index.php form in one of ...
CVE-2025-5998MEDIUM6.5The PPWP – Password Protect Pages WordPress plugin before version 1.9.11 allows to put the site content behind a passwor...
CVE-2025-48861MEDIUM5.3A vulnerability in the Task API endpoint of the ctrlX OS setup mechanism allowed a remote, unauthenticated attacker to a...
CVE-2025-8046MEDIUM6.1The Injection Guard WordPress plugin before 1.2.8 does not escape the $_SERVER['REQUEST_URI'] parameter before outputtin...
CVE-2025-7808MEDIUM6.1The WP Shopify WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2025-6790MEDIUM4.3The Quiz and Survey Master (QSM) WordPress plugin before 10.2.3 does not have CSRF check in place when updating its set...
CVE-2025-3414MEDIUM5.4The Structured Content (JSON-LD) #wpsc WordPress plugin before 1.7.0 does not validate and escape some of its block opti...
CVE-2025-8938MEDIUM6.3A vulnerability was found in TOTOLINK N350R 1.2.3-B20130826. This issue affects the function formSysTel of the file /boa...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now