2025 CVE Vulnerabilities
45,251 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9493 | MEDIUM | 6.4 | 0.2% | Sep 6, 2025 | The Admin Menu Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ parameter ... |
| CVE-2025-9442 | MEDIUM | 6.4 | 0.2% | Sep 6, 2025 | The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vodsChanne... |
| CVE-2025-9126 | MEDIUM | 6.4 | 0.2% | Sep 6, 2025 | The Smart Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all ... |
| CVE-2025-8722 | MEDIUM | 6.4 | 0.2% | Sep 6, 2025 | The Content Views plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid and List widge... |
| CVE-2025-8564 | MEDIUM | 6.4 | 0.2% | Sep 6, 2025 | The SKT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in a... |
| CVE-2025-8149 | MEDIUM | 6.4 | 0.2% | Sep 6, 2025 | The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Coun... |
| CVE-2025-7045 | MEDIUM | 6.5 | 0.4% | Sep 6, 2025 | The Cloud SAML SSO plugin for WordPress is vulnerable to Identity Provider Deletion due to a missing capability check on... |
| CVE-2025-7040 | HIGH | 8.2 | 0.3% | Sep 6, 2025 | The Cloud SAML SSO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c... |
| CVE-2025-9853 | MEDIUM | 6.4 | 0.2% | Sep 6, 2025 | The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' ... |
| CVE-2025-9515 | HIGH | 7.2 | 0.6% | Sep 6, 2025 | The Multi Step Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via... |
| CVE-2025-9085 | MEDIUM | 4.9 | 0.3% | Sep 6, 2025 | The User Registration & Membership plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in version ... |
| CVE-2025-8360 | MEDIUM | 6.4 | 0.2% | Sep 6, 2025 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of... |
| CVE-2025-8359 | CRITICAL | 9.8 | 0.5% | Sep 6, 2025 | The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. Thi... |
| CVE-2025-58912 | — | — | — | Sep 6, 2025 | Rejected reason: Not used |
| CVE-2025-58911 | — | — | — | Sep 6, 2025 | Rejected reason: Not used |
| CVE-2025-58910 | — | — | — | Sep 6, 2025 | Rejected reason: Not used |
| CVE-2025-58909 | — | — | — | Sep 6, 2025 | Rejected reason: Not used |
| CVE-2025-58908 | — | — | — | Sep 6, 2025 | Rejected reason: Not used |
| CVE-2025-58907 | — | — | — | Sep 6, 2025 | Rejected reason: Not used |
| CVE-2025-58906 | — | — | — | Sep 6, 2025 | Rejected reason: Not used |
| CVE-2025-58905 | — | — | — | Sep 6, 2025 | Rejected reason: Not used |
| CVE-2025-58904 | — | — | — | Sep 6, 2025 | Rejected reason: Not used |
| CVE-2025-58437 | HIGH | 8.1 | 0.3% | Sep 6, 2025 | Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3... |
| CVE-2025-58374 | HIGH | 7.8 | 0.2% | Sep 6, 2025 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a def... |
| CVE-2025-10003 | MEDIUM | 6.5 | 0.3% | Sep 6, 2025 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now