2025 CVE Vulnerabilities
45,207 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62937 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johnny Post List F... |
| CVE-2025-62936 | MEDIUM | 4.3 | 0.2% | Oct 27, 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Jthemes xSmart xsmart all... |
| CVE-2025-62935 | MEDIUM | 4.3 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in StackWC Open Close WooCommerce Store woc-open-close allows Exploiting Incorrectly... |
| CVE-2025-62934 | HIGH | 7.1 | 0.1% | Oct 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Mejar WP Business Hours wp-business-hours allows Stored XSS.This issu... |
| CVE-2025-62933 | HIGH | 7.1 | 0.1% | Oct 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Prakash Awesome Testimonials awesome-testimonials allows Stored XSS.T... |
| CVE-2025-62932 | MEDIUM | 4.3 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in wprio Table Block by RioVizual riovizual allows Exploiting Incorrectly Configured... |
| CVE-2025-62931 | MEDIUM | 4.3 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in microsoftstart MSN Partner Hub microsoft-start allows Exploiting Incorrectly Conf... |
| CVE-2025-62930 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RomanCode MapSVG m... |
| CVE-2025-62929 | MEDIUM | 6.5 | 0.3% | Oct 27, 2025 | Missing Authorization vulnerability in PickPlugins Testimonial Slider testimonial allows Exploiting Incorrectly Configur... |
| CVE-2025-62928 | MEDIUM | 4.3 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in Joby Joseph SEO Meta Description Updater seo-meta-description-updater allows Expl... |
| CVE-2025-62927 | MEDIUM | 6.5 | 0.3% | Oct 27, 2025 | Missing Authorization vulnerability in Nelio Software Nelio Content nelio-content allows Exploiting Incorrectly Configur... |
| CVE-2025-62925 | MEDIUM | 5.4 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in Conversios Conversios.io enhanced-e-commerce-for-woocommerce-store allows Exploit... |
| CVE-2025-62924 | MEDIUM | 6.5 | 0.3% | Oct 27, 2025 | Missing Authorization vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectl... |
| CVE-2025-62923 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debuggers Studio M... |
| CVE-2025-62922 | MEDIUM | 5.3 | 0.3% | Oct 27, 2025 | Missing Authorization vulnerability in Shambhu Patnaik Export Categories export-categories allows Accessing Functionalit... |
| CVE-2025-62921 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pagup Bulk Auto Im... |
| CVE-2025-62920 | MEDIUM | 5.9 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webnique USERCENTR... |
| CVE-2025-62919 | MEDIUM | 5.4 | 0.3% | Oct 27, 2025 | Missing Authorization vulnerability in themeshopy TS Demo Importer ts-demo-importer allows Exploiting Incorrectly Config... |
| CVE-2025-62918 | MEDIUM | 5.4 | 0.3% | Oct 27, 2025 | Missing Authorization vulnerability in ignitionwp IgnitionDeck ignitiondeck allows Exploiting Incorrectly Configured Acc... |
| CVE-2025-62917 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jamel.Z Tooltipy b... |
| CVE-2025-62916 | MEDIUM | 5.4 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in Travon WP Flights & Hotels Booking WP Plugin adiaha-hotel allows Exploiting Incor... |
| CVE-2025-62915 | MEDIUM | 4.3 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in clicksend SMS Contact Form 7 Notifications by ClickSend clicksend-contactform7 al... |
| CVE-2025-62913 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpopal Opal Servic... |
| CVE-2025-62912 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SiteGround SiteGro... |
| CVE-2025-62911 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rock Content Rock ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now