2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8397 | MEDIUM | 6.4 | 0.2% | Nov 13, 2025 | The Save as PDF Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's restpackpdfbut... |
| CVE-2025-12015 | MEDIUM | 4.3 | 0.2% | Nov 13, 2025 | The Convert WebP & AVIF | Quicq | Best image optimizer and compression plugin | Improve your Google Pagespeed plugin for... |
| CVE-2025-11769 | MEDIUM | 6.4 | 0.2% | Nov 13, 2025 | The WordPress Content Flipper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bgcolor' shortc... |
| CVE-2025-11260 | MEDIUM | 5.3 | 0.3% | Nov 13, 2025 | The WP Headless CMS Framework plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, a... |
| CVE-2025-10295 | MEDIUM | 6.4 | 0.2% | Nov 13, 2025 | The Angel – Fashion Model Agency WordPress CMS Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting th... |
| CVE-2025-12844 | HIGH | 7.1 | 0.4% | Nov 13, 2025 | The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to,... |
| CVE-2025-12681 | MEDIUM | 5.3 | 0.3% | Nov 13, 2025 | The Comment Edit Core – Simple Comment Editing plugin for WordPress is vulnerable to Sensitive Information Exposure in a... |
| CVE-2025-12620 | MEDIUM | 4.9 | 0.3% | Nov 13, 2025 | The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection ... |
| CVE-2025-12891 | MEDIUM | 5.3 | 0.2% | Nov 13, 2025 | The Survey Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on ... |
| CVE-2025-12979 | MEDIUM | 5.3 | 0.2% | Nov 13, 2025 | The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability che... |
| CVE-2025-12892 | MEDIUM | 5.3 | 0.2% | Nov 13, 2025 | The Survey Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che... |
| CVE-2025-12733 | HIGH | 8.8 | 0.6% | Nov 13, 2025 | The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Exe... |
| CVE-2025-12536 | MEDIUM | 5.3 | 0.7% | Nov 13, 2025 | The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
| CVE-2025-12366 | MEDIUM | 4.3 | 0.2% | Nov 13, 2025 | The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Insecure Direct Object... |
| CVE-2025-12089 | MEDIUM | 6.5 | 0.5% | Nov 13, 2025 | The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient... |
| CVE-2025-11923 | HIGH | 8.8 | 0.3% | Nov 13, 2025 | The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escalati... |
| CVE-2025-64716 | MEDIUM | 5.1 | 0.5% | Nov 13, 2025 | Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scrap... |
| CVE-2025-64711 | MEDIUM | 5.4 | 0.1% | Nov 13, 2025 | PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior... |
| CVE-2025-64710 | MEDIUM | 5.3 | 0.3% | Nov 13, 2025 | Bitplatform Boilerplate is a Visual studio and .NET project template. Versions prior to 9.11.3 are affected by a cross-s... |
| CVE-2025-59367 | CRITICAL | 9.8 | 0.8% | Nov 13, 2025 | An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to ... |
| CVE-2025-64707 | MEDIUM | 5.4 | 0.1% | Nov 12, 2025 | Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to ve... |
| CVE-2025-64705 | MEDIUM | 4.3 | 0.2% | Nov 12, 2025 | Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to ve... |
| CVE-2025-64523 | HIGH | 8.8 | 0.4% | Nov 12, 2025 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ... |
| CVE-2025-13076 | CRITICAL | 9.8 | 0.3% | Nov 12, 2025 | A flaw has been found in code-projects Responsive Hotel Site 1.0. The affected element is an unknown function of the fil... |
| CVE-2025-13075 | CRITICAL | 9.8 | 0.3% | Nov 12, 2025 | A vulnerability was detected in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /ad... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now