2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60102 | MEDIUM | 6.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syam Mohan WPFront... |
| CVE-2025-60101 | MEDIUM | 5.9 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in duongancol Woostif... |
| CVE-2025-60100 | MEDIUM | 5.3 | 0.3% | Sep 26, 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore xstore allo... |
| CVE-2025-60099 | MEDIUM | 6.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awsm.in Embed Any ... |
| CVE-2025-60098 | MEDIUM | 6.5 | 0.3% | Sep 26, 2025 | Missing Authorization vulnerability in Jeff Farthing Theme My Login theme-my-login allows Exploiting Incorrectly Configu... |
| CVE-2025-60097 | MEDIUM | 5.4 | 0.2% | Sep 26, 2025 | Missing Authorization vulnerability in CodexThemes TheGem thegem allows Exploiting Incorrectly Configured Access Control... |
| CVE-2025-60096 | MEDIUM | 5.4 | 0.2% | Sep 26, 2025 | Missing Authorization vulnerability in CodexThemes TheGem (Elementor) thegem-elementor allows Exploiting Incorrectly Con... |
| CVE-2025-60095 | MEDIUM | 4.3 | 0.3% | Sep 26, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Benjamin Intal Stackable stackable-ultimate-gutenberg... |
| CVE-2025-60094 | MEDIUM | 4.3 | 0.2% | Sep 26, 2025 | Missing Authorization vulnerability in Benjamin Intal Stackable stackable-ultimate-gutenberg-blocks allows Exploiting In... |
| CVE-2025-60093 | MEDIUM | 4.3 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Shahjada Download Manager download-manager allows Cross Site Request ... |
| CVE-2025-60092 | MEDIUM | 5.3 | 0.3% | Sep 26, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager do... |
| CVE-2025-60040 | MEDIUM | 6.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fkrauthan wp-mpdf ... |
| CVE-2025-59012 | HIGH | 7.1 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shinetheme Travele... |
| CVE-2025-59011 | HIGH | 7.5 | 0.4% | Sep 26, 2025 | Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2025-59010 | HIGH | 7.5 | 0.4% | Sep 26, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Maciej Bis Permalink Manager Lite permalink-manager a... |
| CVE-2025-59002 | HIGH | 7.7 | 0.4% | Sep 26, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SeaTheme BM Content Buil... |
| CVE-2025-58919 | MEDIUM | 5.3 | 0.2% | Sep 26, 2025 | Missing Authorization vulnerability in guihom Wide Banner wide-banner allows Exploiting Incorrectly Configured Access Co... |
| CVE-2025-58917 | MEDIUM | 6.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nick Verwymeren Qu... |
| CVE-2025-58914 | MEDIUM | 4.3 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Di Themes Di Themes Demo Site Importer di-themes-demo-site-importer a... |
| CVE-2025-4957 | HIGH | 7.1 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss ProfileG... |
| CVE-2025-48326 | MEDIUM | 6.5 | 0.3% | Sep 26, 2025 | Missing Authorization vulnerability in Acclectic Media Acclectic Media Organizer acclectic-media-organizer allows Exploi... |
| CVE-2025-48107 | HIGH | 7.1 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in undsgn Uncode unco... |
| CVE-2025-27006 | MEDIUM | 6.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeplugs Authors... |
| CVE-2025-1862 | HIGH | 7.2 | 0.5% | Sep 26, 2025 | An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied file... |
| CVE-2025-11021 | HIGH | 7.5 | 0.6% | Sep 26, 2025 | A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applicati... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now