2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13133MEDIUM6.6The Simple User Import Export plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, ...
CVE-2025-13069HIGH8.8The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, ...
CVE-2025-12955HIGH7.5The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions ...
CVE-2025-12691MEDIUM6.4The Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin for WordPress is vulnerable to Stored Cross-Site Scr...
CVE-2025-12639MEDIUM4.3The wModes – Catalog Mode, Product Pricing, Enquiry Forms & Promotions plugin for WordPress is vulnerable to authorizati...
CVE-2025-12481MEDIUM4.3The WP Duplicate Page plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, ...
CVE-2025-12457MEDIUM6.4The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo...
CVE-2025-12392MEDIUM5.3The Cryptocurrency Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of da...
CVE-2025-12391MEDIUM5.3The Restrictions for BuddyPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
CVE-2025-12088MEDIUM6.4The Meta Display Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Meta Display Block in a...
CVE-2025-12079MEDIUM6.1The WP Twitter Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all ...
CVE-2025-11734MEDIUM5.4The Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable to...
CVE-2025-9625MEDIUM4.3The Coil Web Monetization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-8609MEDIUM6.4The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accor...
CVE-2025-8605MEDIUM6.4The Gutenify – Visual Site Builder Blocks & Site Templates. plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2025-40549CRITICAL9.1A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to a...
CVE-2025-40548CRITICAL9.1A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges ...
CVE-2025-40547CRITICAL9.1A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privile...
CVE-2025-40545MEDIUM4.4SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly saniti...
CVE-2025-26391MEDIUM5.4SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability t...
CVE-2025-13088HIGH8.8The Category and Product Woocommerce Tabs plugin for WordPress is vulnerable to Local File Inclusion in all versions up ...
CVE-2025-12962MEDIUM6.4The Local Syndication plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu...
CVE-2025-12961MEDIUM4.3The Download Panel plugin for WordPress is vulnerable to unauthorized settings modification due to a missing capability ...
CVE-2025-12937MEDIUM6.5The ACF Flexible Layouts Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missin...
CVE-2025-12827MEDIUM4.3The Top Friends plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now