2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13133 | MEDIUM | 6.6 | 0.2% | Nov 18, 2025 | The Simple User Import Export plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, ... |
| CVE-2025-13069 | HIGH | 8.8 | 0.6% | Nov 18, 2025 | The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, ... |
| CVE-2025-12955 | HIGH | 7.5 | 0.3% | Nov 18, 2025 | The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions ... |
| CVE-2025-12691 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin for WordPress is vulnerable to Stored Cross-Site Scr... |
| CVE-2025-12639 | MEDIUM | 4.3 | 0.2% | Nov 18, 2025 | The wModes – Catalog Mode, Product Pricing, Enquiry Forms & Promotions plugin for WordPress is vulnerable to authorizati... |
| CVE-2025-12481 | MEDIUM | 4.3 | 0.2% | Nov 18, 2025 | The WP Duplicate Page plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, ... |
| CVE-2025-12457 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo... |
| CVE-2025-12392 | MEDIUM | 5.3 | 0.2% | Nov 18, 2025 | The Cryptocurrency Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of da... |
| CVE-2025-12391 | MEDIUM | 5.3 | 0.2% | Nov 18, 2025 | The Restrictions for BuddyPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing... |
| CVE-2025-12088 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The Meta Display Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Meta Display Block in a... |
| CVE-2025-12079 | MEDIUM | 6.1 | 0.2% | Nov 18, 2025 | The WP Twitter Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all ... |
| CVE-2025-11734 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | The Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable to... |
| CVE-2025-9625 | MEDIUM | 4.3 | 0.1% | Nov 18, 2025 | The Coil Web Monetization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-8609 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accor... |
| CVE-2025-8605 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The Gutenify – Visual Site Builder Blocks & Site Templates. plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2025-40549 | CRITICAL | 9.1 | 1.0% | Nov 18, 2025 | A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to a... |
| CVE-2025-40548 | CRITICAL | 9.1 | 0.6% | Nov 18, 2025 | A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges ... |
| CVE-2025-40547 | CRITICAL | 9.1 | 0.8% | Nov 18, 2025 | A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privile... |
| CVE-2025-40545 | MEDIUM | 4.4 | 0.2% | Nov 18, 2025 | SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly saniti... |
| CVE-2025-26391 | MEDIUM | 5.4 | 0.4% | Nov 18, 2025 | SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability t... |
| CVE-2025-13088 | HIGH | 8.8 | 0.3% | Nov 18, 2025 | The Category and Product Woocommerce Tabs plugin for WordPress is vulnerable to Local File Inclusion in all versions up ... |
| CVE-2025-12962 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The Local Syndication plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu... |
| CVE-2025-12961 | MEDIUM | 4.3 | 0.2% | Nov 18, 2025 | The Download Panel plugin for WordPress is vulnerable to unauthorized settings modification due to a missing capability ... |
| CVE-2025-12937 | MEDIUM | 6.5 | 0.2% | Nov 18, 2025 | The ACF Flexible Layouts Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missin... |
| CVE-2025-12827 | MEDIUM | 4.3 | 0.1% | Nov 18, 2025 | The Top Friends plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now