2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12913CRITICAL9.8A flaw has been found in code-projects Responsive Hotel Site 1.0. This affects an unknown part of the file /admin/roomde...
CVE-2025-12837MEDIUM6.4The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Call To Actio...
CVE-2025-12643MEDIUM6.4The Saphali LiqPay for donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'saphali_liqpay'...
CVE-2025-12399HIGH7.2The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to miss...
CVE-2025-12092MEDIUM6.5The CYAN Backup plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation i...
CVE-2025-11980MEDIUM4.9The Quick Featured Images plugin for WordPress is vulnerable to SQL Injection via the 'delete_orphaned' function in all ...
CVE-2025-11967HIGH7.2The Mail Mint plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pr...
CVE-2025-11448MEDIUM4.3The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification ...
CVE-2025-12099HIGH7.2The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to PHP Object ...
CVE-2025-12098MEDIUM5.3The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Sensitive I...
CVE-2025-12621MEDIUM5.3The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of ...
CVE-2025-12498MEDIUM4.3The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized booking note c...
CVE-2025-9334HIGH8.8The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in all...
CVE-2025-7663MEDIUM6.5The Ovatheme Events Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check ...
CVE-2025-12353MEDIUM5.3The WPFunnels – The Easiest Funnel Builder For WordPress And WooCommerce To Collect Leads And Increase Sales plugin for ...
CVE-2025-12193MEDIUM6.1The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mp' parameter in all ver...
CVE-2025-12177MEDIUM5.3The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the d...
CVE-2025-12167MEDIUM4.3The Contact Form 7 AWeber Extension plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2025-12161HIGH8.8The Smart Auto Upload Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid...
CVE-2025-12125MEDIUM4.4The HTML Forms – Simple WordPress Forms Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm...
CVE-2025-12112MEDIUM6.4The Insert Headers and Footers Code – HT Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ad...
CVE-2025-12064MEDIUM6.1The WP2Social Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all v...
CVE-2025-12042MEDIUM5.3The Course Booking System plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ...
CVE-2025-12000MEDIUM6.5The WPFunnels plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in ...
CVE-2025-11972MEDIUM4.9The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to SQL Injection ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now