2025 CVE Vulnerabilities
45,213 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-32266 | MEDIUM | 4.3 | 0.2% | Apr 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in wp-buy 404 Image Redirection (Replace Broken Images) broken-images-re... |
| CVE-2025-32265 | MEDIUM | 4.3 | 0.1% | Apr 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak JobWP jobwp allows Cross Site Request Forgery.This iss... |
| CVE-2025-32264 | MEDIUM | 4.3 | 0.1% | Apr 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Saiful Islam UltraAddons Elementor Lite ultraaddons-elementor-lite al... |
| CVE-2025-32263 | MEDIUM | 4.3 | 0.1% | Apr 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in BeRocket Sequential Order Numbers for WooCommerce sequential-order-nu... |
| CVE-2025-32262 | MEDIUM | 4.3 | 0.1% | Apr 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Robert D Payne RDP Wiki Embed rdp-wiki-embed allows Cross Site Reques... |
| CVE-2025-32261 | MEDIUM | 4.3 | 0.1% | Apr 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Kuppuraj Advanced All in One Admin Search by WP Spotlight wp-spotligh... |
| CVE-2025-32258 | MEDIUM | 5.3 | 0.3% | Apr 4, 2025 | Missing Authorization vulnerability in InfoGiants Simple Website Logo simple-website-logo allows Exploiting Incorrectly ... |
| CVE-2025-32257 | MEDIUM | 5.3 | 0.8% | Apr 4, 2025 | Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click Wor... |
| CVE-2025-32256 | MEDIUM | 5.3 | 0.3% | Apr 4, 2025 | Missing Authorization vulnerability in devsoftbaltic SurveyJS surveyjs allows Accessing Functionality Not Properly Const... |
| CVE-2025-32255 | MEDIUM | 5.3 | 0.5% | Apr 4, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ERA404 StaffList stafflist a... |
| CVE-2025-32254 | MEDIUM | 5.3 | 0.4% | Apr 4, 2025 | Missing Authorization vulnerability in Iqonic Design WPBookit wpbookit allows Accessing Functionality Not Properly Const... |
| CVE-2025-32253 | MEDIUM | 5.3 | 0.6% | Apr 4, 2025 | Missing Authorization vulnerability in ComMotion Course Booking System course-booking-system allows Accessing Functional... |
| CVE-2025-32252 | MEDIUM | 5.3 | 0.5% | Apr 4, 2025 | Missing Authorization vulnerability in Black and White WP Genealogy – Your Family History Website wpgenealogy allows Exp... |
| CVE-2025-32251 | MEDIUM | 5.3 | 0.5% | Apr 4, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in J. Tyler Wiest Jetpack Feedb... |
| CVE-2025-32250 | MEDIUM | 5.4 | 0.2% | Apr 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in rollbar Rollbar rollbar allows Cross Site Request Forgery.This issue ... |
| CVE-2025-32249 | MEDIUM | 5.4 | 0.2% | Apr 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Designinvento DirectoryPress directorypress allows Cross Site Request... |
| CVE-2025-32248 | MEDIUM | 5.4 | 0.2% | Apr 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in SwiftXR SwiftXR (3D/AR/VR) Viewer swiftxr-3darvr-viewer allows Cross ... |
| CVE-2025-32247 | MEDIUM | 5.4 | 0.2% | Apr 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ABCdatos AI Content Creator ai-content-creator allows Cross Site Requ... |
| CVE-2025-32246 | MEDIUM | 5.4 | 0.4% | Apr 4, 2025 | Missing Authorization vulnerability in Tim Nguyen 1-Click Backup & Restore Database 1-click-backup-restore-database-by-s... |
| CVE-2025-32241 | MEDIUM | 6.5 | 0.3% | Apr 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in CleverReach® Official CleverReach Plugin for WooCommerce cleverreach-... |
| CVE-2025-32239 | MEDIUM | 4.3 | 0.4% | Apr 4, 2025 | Missing Authorization vulnerability in Joao Romao Social Share Buttons & Analytics Plugin – GetSocial.io wp-share-button... |
| CVE-2025-32238 | MEDIUM | 4.3 | 0.4% | Apr 4, 2025 | Generation of Error Message Containing Sensitive Information vulnerability in vcita Online Booking & Scheduling Calendar... |
| CVE-2025-32237 | MEDIUM | 4.3 | 0.4% | Apr 4, 2025 | Missing Authorization vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Exploi... |
| CVE-2025-32235 | MEDIUM | 4.3 | 0.3% | Apr 4, 2025 | Missing Authorization vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-... |
| CVE-2025-32234 | MEDIUM | 4.3 | 0.4% | Apr 4, 2025 | Missing Authorization vulnerability in aleswebs AdMail – Multilingual Back in-Stock Notifier for WooCommerce admail allo... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now