2025 CVE Vulnerabilities

45,251 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9493MEDIUM6.4The Admin Menu Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ parameter ...
CVE-2025-9442MEDIUM6.4The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vodsChanne...
CVE-2025-9126MEDIUM6.4The Smart Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all ...
CVE-2025-8722MEDIUM6.4The Content Views plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid and List widge...
CVE-2025-8564MEDIUM6.4The SKT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in a...
CVE-2025-8149MEDIUM6.4The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Coun...
CVE-2025-7045MEDIUM6.5The Cloud SAML SSO plugin for WordPress is vulnerable to Identity Provider Deletion due to a missing capability check on...
CVE-2025-7040HIGH8.2The Cloud SAML SSO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c...
CVE-2025-9853MEDIUM6.4The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' ...
CVE-2025-9515HIGH7.2The Multi Step Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via...
CVE-2025-9085MEDIUM4.9The User Registration & Membership plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in version ...
CVE-2025-8360MEDIUM6.4The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of...
CVE-2025-8359CRITICAL9.8The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. Thi...
CVE-2025-58912Rejected reason: Not used
CVE-2025-58911Rejected reason: Not used
CVE-2025-58910Rejected reason: Not used
CVE-2025-58909Rejected reason: Not used
CVE-2025-58908Rejected reason: Not used
CVE-2025-58907Rejected reason: Not used
CVE-2025-58906Rejected reason: Not used
CVE-2025-58905Rejected reason: Not used
CVE-2025-58904Rejected reason: Not used
CVE-2025-58437HIGH8.1Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3...
CVE-2025-58374HIGH7.8Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a def...
CVE-2025-10003MEDIUM6.5The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now