2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-8397MEDIUM6.4The Save as PDF Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's restpackpdfbut...
CVE-2025-12015MEDIUM4.3The Convert WebP & AVIF | Quicq | Best image optimizer and compression plugin | Improve your Google Pagespeed plugin for...
CVE-2025-11769MEDIUM6.4The WordPress Content Flipper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bgcolor' shortc...
CVE-2025-11260MEDIUM5.3The WP Headless CMS Framework plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, a...
CVE-2025-10295MEDIUM6.4The Angel – Fashion Model Agency WordPress CMS Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting th...
CVE-2025-12844HIGH7.1The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to,...
CVE-2025-12681MEDIUM5.3The Comment Edit Core – Simple Comment Editing plugin for WordPress is vulnerable to Sensitive Information Exposure in a...
CVE-2025-12620MEDIUM4.9The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection ...
CVE-2025-12891MEDIUM5.3The Survey Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on ...
CVE-2025-12979MEDIUM5.3The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability che...
CVE-2025-12892MEDIUM5.3The Survey Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che...
CVE-2025-12733HIGH8.8The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Exe...
CVE-2025-12536MEDIUM5.3The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2025-12366MEDIUM4.3The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Insecure Direct Object...
CVE-2025-12089MEDIUM6.5The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient...
CVE-2025-11923HIGH8.8The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escalati...
CVE-2025-64716MEDIUM5.1Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scrap...
CVE-2025-64711MEDIUM5.4PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior...
CVE-2025-64710MEDIUM5.3Bitplatform Boilerplate is a Visual studio and .NET project template. Versions prior to 9.11.3 are affected by a cross-s...
CVE-2025-59367CRITICAL9.8An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to ...
CVE-2025-64707MEDIUM5.4Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to ve...
CVE-2025-64705MEDIUM4.3Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to ve...
CVE-2025-64523HIGH8.8File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2025-13076CRITICAL9.8A flaw has been found in code-projects Responsive Hotel Site 1.0. The affected element is an unknown function of the fil...
CVE-2025-13075CRITICAL9.8A vulnerability was detected in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /ad...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now