2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9993 | HIGH | 8.1 | 0.7% | Sep 30, 2025 | The Bei Fen – WordPress Backup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, ... |
| CVE-2025-9991 | HIGH | 8.1 | 0.6% | Sep 30, 2025 | The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and ... |
| CVE-2025-9948 | MEDIUM | 4.3 | 0.2% | Sep 30, 2025 | The Chat by Chatwee plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2025-9946 | MEDIUM | 6.1 | 0.1% | Sep 30, 2025 | The LockerPress – WordPress Security Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers... |
| CVE-2025-9852 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The Yoga Schedule Momoyoga plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'momoyoga-... |
| CVE-2025-9762 | CRITICAL | 9.8 | 0.7% | Sep 30, 2025 | The Post By Email plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th... |
| CVE-2025-8877 | HIGH | 7.5 | 0.3% | Sep 30, 2025 | The AffiliateWP plugin for WordPress is vulnerable to SQL Injection via the ajax_get_affiliate_id_from_login function in... |
| CVE-2025-8777 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The planetcalc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘language’ parameter in all ver... |
| CVE-2025-8625 | CRITICAL | 9.8 | 0.6% | Sep 30, 2025 | The Copypress Rest API plugin for WordPress is vulnerable to Remote Code Execution via copyreap_handle_image() Function ... |
| CVE-2025-8624 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The Nexa Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Google Maps widget in... |
| CVE-2025-8623 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The WeedMaps Menu for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's weedm... |
| CVE-2025-8608 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The Mihdan: Elementor Yandex Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blo... |
| CVE-2025-8566 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via parameters in the ... |
| CVE-2025-8560 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The FancyTabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all version... |
| CVE-2025-8559 | MEDIUM | 6.5 | 0.4% | Sep 30, 2025 | The All in One Music Player plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1... |
| CVE-2025-8214 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The The Pack Elementor addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typing L... |
| CVE-2025-8122 | HIGH | 8.8 | 0.3% | Sep 30, 2025 | Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQ... |
| CVE-2025-8121 | HIGH | 8.8 | 0.3% | Sep 30, 2025 | Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQ... |
| CVE-2025-8120 | CRITICAL | 9.8 | 0.5% | Sep 30, 2025 | Due to client-controlled permission check parameter, PAD CMS's upload photo functionality allows an unauthenticated remo... |
| CVE-2025-8119 | MEDIUM | 4.3 | 0.1% | Sep 30, 2025 | PAD CMS is vulnerable to Cross-Site Request Forgery in reset password's functionality. Malicious attacker can craft spec... |
| CVE-2025-8118 | MEDIUM | 6.5 | 0.2% | Sep 30, 2025 | PAD CMS implements weak client-side brute-force protection by utilizing two cookies: login_count and login_timeout. Inf... |
| CVE-2025-8117 | HIGH | 7.5 | 0.3% | Sep 30, 2025 | PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that d... |
| CVE-2025-8116 | MEDIUM | 6.1 | 0.2% | Sep 30, 2025 | PAD CMS is vulnerable to Reflected XSS in printing and save to PDF functionality. Malicious attacker can craft special U... |
| CVE-2025-7065 | CRITICAL | 9.8 | 0.6% | Sep 30, 2025 | Due to client-controlled permission check parameter, PAD CMS's photo upload functionality allows an unauthenticated remo... |
| CVE-2025-7063 | CRITICAL | 9.8 | 0.6% | Sep 30, 2025 | Due to client-controlled permission check parameter, PAD CMS's file upload functionality allows an unauthenticated remot... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now