2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-48149HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-48148CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeepe...
CVE-2025-48142HIGH8.8Incorrect Privilege Assignment vulnerability in Saad Iqbal Bookify bookify allows Privilege Escalation.This issue affect...
CVE-2025-47650MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Infility Infility Global...
CVE-2025-30975HIGH7.5Improper Control of Generation of Code ('Code Injection') vulnerability in SaifuMak Add Custom Codes add-custom-codes al...
CVE-2025-28977MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Pipes...
CVE-2025-9202MEDIUM4.3The ColorMag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2025-8618MEDIUM6.4The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2025-55706MEDIUM5.1URL redirection to untrusted site ('Open Redirect') issue exists in Movable Type. If this vulnerability is exploited, a...
CVE-2025-54551MEDIUM5.3Synapse Mobility 8.0, 8.0.1, 8.0.2, 8.1, and 8.1.1 contain a privilege escalation vulnerability through external control...
CVE-2025-53522MEDIUM6.9Movable Type contains an issue with use of less trusted source. If exploited, tampered email to reset a password may be ...
CVE-2025-57791MEDIUM6.5A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments...
CVE-2025-57790HIGH8.8A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access thr...
CVE-2025-57789MEDIUM5.4During the brief window between installation and the first administrator login, remote attackers may exploit the default...
CVE-2025-57788MEDIUM6.5A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user ...
CVE-2025-57748Rejected reason: Not used
CVE-2025-57747Rejected reason: Not used
CVE-2025-57746Rejected reason: Not used
CVE-2025-57745Rejected reason: Not used
CVE-2025-57744Rejected reason: Not used
CVE-2025-57743Rejected reason: Not used
CVE-2025-57742Rejected reason: Not used
CVE-2025-8289HIGH7.5The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and...
CVE-2025-8145HIGH8.8The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and...
CVE-2025-8141HIGH8.8The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fil...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now