2025 CVE Vulnerabilities
45,213 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11703 | MEDIUM | 5.3 | 0.2% | Oct 18, 2025 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, an... |
| CVE-2025-11691 | HIGH | 7.5 | 0.4% | Oct 18, 2025 | The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the PP... |
| CVE-2025-11519 | MEDIUM | 4.3 | 0.3% | Oct 18, 2025 | The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vuln... |
| CVE-2025-11517 | HIGH | 7.5 | 0.4% | Oct 18, 2025 | The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and inclu... |
| CVE-2025-11510 | MEDIUM | 4.3 | 0.2% | Oct 18, 2025 | The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized modific... |
| CVE-2025-11391 | CRITICAL | 9.8 | 0.9% | Oct 18, 2025 | The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads d... |
| CVE-2025-11372 | MEDIUM | 6.5 | 0.4% | Oct 18, 2025 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to modification of data in all versions up to, ... |
| CVE-2025-11270 | MEDIUM | 6.4 | 0.2% | Oct 18, 2025 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stor... |
| CVE-2025-10187 | MEDIUM | 4.9 | 0.4% | Oct 18, 2025 | The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' pa... |
| CVE-2025-10006 | MEDIUM | 5.4 | 0.2% | Oct 18, 2025 | The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rev_slider... |
| CVE-2025-11937 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-11857 | MEDIUM | 6.4 | 0.3% | Oct 18, 2025 | The XX2WP Integration Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mxp_fb2wp_display... |
| CVE-2025-11742 | MEDIUM | 4.3 | 0.3% | Oct 18, 2025 | The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missin... |
| CVE-2025-11738 | MEDIUM | 5.3 | 0.4% | Oct 18, 2025 | The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and includ... |
| CVE-2025-62671 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62670 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62669 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Central... |
| CVE-2025-62668 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows R... |
| CVE-2025-62667 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62666 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in The Wikimedia Foundation Mediawiki - CirrusSearch ... |
| CVE-2025-62664 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62663 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62662 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-11361 | MEDIUM | 6.4 | 0.3% | Oct 18, 2025 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Serv... |
| CVE-2025-62665 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now