2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9993HIGH8.1The Bei Fen – WordPress Backup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, ...
CVE-2025-9991HIGH8.1The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and ...
CVE-2025-9948MEDIUM4.3The Chat by Chatwee plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin...
CVE-2025-9946MEDIUM6.1The LockerPress – WordPress Security Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers...
CVE-2025-9852MEDIUM6.4The Yoga Schedule Momoyoga plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'momoyoga-...
CVE-2025-9762CRITICAL9.8The Post By Email plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th...
CVE-2025-8877HIGH7.5The AffiliateWP plugin for WordPress is vulnerable to SQL Injection via the ajax_get_affiliate_id_from_login function in...
CVE-2025-8777MEDIUM6.4The planetcalc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘language’ parameter in all ver...
CVE-2025-8625CRITICAL9.8The Copypress Rest API plugin for WordPress is vulnerable to Remote Code Execution via copyreap_handle_image() Function ...
CVE-2025-8624MEDIUM6.4The Nexa Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Google Maps widget in...
CVE-2025-8623MEDIUM6.4The WeedMaps Menu for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's weedm...
CVE-2025-8608MEDIUM6.4The Mihdan: Elementor Yandex Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blo...
CVE-2025-8566MEDIUM6.4The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via parameters in the ...
CVE-2025-8560MEDIUM6.4The FancyTabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all version...
CVE-2025-8559MEDIUM6.5The All in One Music Player plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1...
CVE-2025-8214MEDIUM6.4The The Pack Elementor addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typing L...
CVE-2025-8122HIGH8.8Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQ...
CVE-2025-8121HIGH8.8Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQ...
CVE-2025-8120CRITICAL9.8Due to client-controlled permission check parameter, PAD CMS's upload photo functionality allows an unauthenticated remo...
CVE-2025-8119MEDIUM4.3PAD CMS is vulnerable to Cross-Site Request Forgery in reset password's functionality. Malicious attacker can craft spec...
CVE-2025-8118MEDIUM6.5PAD CMS implements weak client-side brute-force protection by utilizing two cookies:  login_count and login_timeout. Inf...
CVE-2025-8117HIGH7.5PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that d...
CVE-2025-8116MEDIUM6.1PAD CMS is vulnerable to Reflected XSS in printing and save to PDF functionality. Malicious attacker can craft special U...
CVE-2025-7065CRITICAL9.8Due to client-controlled permission check parameter, PAD CMS's photo upload functionality allows an unauthenticated remo...
CVE-2025-7063CRITICAL9.8Due to client-controlled permission check parameter, PAD CMS's file upload functionality allows an unauthenticated remot...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now