2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12913 | CRITICAL | 9.8 | 0.3% | Nov 8, 2025 | A flaw has been found in code-projects Responsive Hotel Site 1.0. This affects an unknown part of the file /admin/roomde... |
| CVE-2025-12837 | MEDIUM | 6.4 | 0.2% | Nov 8, 2025 | The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Call To Actio... |
| CVE-2025-12643 | MEDIUM | 6.4 | 0.2% | Nov 8, 2025 | The Saphali LiqPay for donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'saphali_liqpay'... |
| CVE-2025-12399 | HIGH | 7.2 | 0.6% | Nov 8, 2025 | The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to miss... |
| CVE-2025-12092 | MEDIUM | 6.5 | 0.6% | Nov 8, 2025 | The CYAN Backup plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation i... |
| CVE-2025-11980 | MEDIUM | 4.9 | 0.3% | Nov 8, 2025 | The Quick Featured Images plugin for WordPress is vulnerable to SQL Injection via the 'delete_orphaned' function in all ... |
| CVE-2025-11967 | HIGH | 7.2 | 0.5% | Nov 8, 2025 | The Mail Mint plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pr... |
| CVE-2025-11448 | MEDIUM | 4.3 | 0.2% | Nov 8, 2025 | The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification ... |
| CVE-2025-12099 | HIGH | 7.2 | 0.5% | Nov 8, 2025 | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to PHP Object ... |
| CVE-2025-12098 | MEDIUM | 5.3 | 0.2% | Nov 8, 2025 | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Sensitive I... |
| CVE-2025-12621 | MEDIUM | 5.3 | 0.2% | Nov 8, 2025 | The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of ... |
| CVE-2025-12498 | MEDIUM | 4.3 | 0.2% | Nov 8, 2025 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized booking note c... |
| CVE-2025-9334 | HIGH | 8.8 | 0.4% | Nov 8, 2025 | The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in all... |
| CVE-2025-7663 | MEDIUM | 6.5 | 0.2% | Nov 8, 2025 | The Ovatheme Events Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check ... |
| CVE-2025-12353 | MEDIUM | 5.3 | 0.2% | Nov 8, 2025 | The WPFunnels – The Easiest Funnel Builder For WordPress And WooCommerce To Collect Leads And Increase Sales plugin for ... |
| CVE-2025-12193 | MEDIUM | 6.1 | 0.2% | Nov 8, 2025 | The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mp' parameter in all ver... |
| CVE-2025-12177 | MEDIUM | 5.3 | 0.2% | Nov 8, 2025 | The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the d... |
| CVE-2025-12167 | MEDIUM | 4.3 | 0.2% | Nov 8, 2025 | The Contact Form 7 AWeber Extension plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2025-12161 | HIGH | 8.8 | 0.5% | Nov 8, 2025 | The Smart Auto Upload Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid... |
| CVE-2025-12125 | MEDIUM | 4.4 | 0.2% | Nov 8, 2025 | The HTML Forms – Simple WordPress Forms Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm... |
| CVE-2025-12112 | MEDIUM | 6.4 | 0.2% | Nov 8, 2025 | The Insert Headers and Footers Code – HT Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ad... |
| CVE-2025-12064 | MEDIUM | 6.1 | 0.2% | Nov 8, 2025 | The WP2Social Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all v... |
| CVE-2025-12042 | MEDIUM | 5.3 | 0.2% | Nov 8, 2025 | The Course Booking System plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ... |
| CVE-2025-12000 | MEDIUM | 6.5 | 0.7% | Nov 8, 2025 | The WPFunnels plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in ... |
| CVE-2025-11972 | MEDIUM | 4.9 | 0.3% | Nov 8, 2025 | The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to SQL Injection ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now