Vulnerabilities in ThemeGoods
50 resultsVexday analysis
ThemeGoods acumula 48 vulnerabilidades catalogadas, das quais 12 são críticas, mas nenhuma está sob exploração ativa conhecida. A fraqueza dominante é injeção XSS (CWE-79), típica de componentes web, com 4 novos registros nos últimos 90 dias indicando descoberta contínua. O risco atual é moderado devido à ausência de ataques em campo, mas a concentração em falhas de validação exige atenção em controles de sanitização de entrada.
CVE-2025-32926CRITICALWordPress Grand Restaurant WordPress theme <= 7.0 - Path Traversal to PHP Object Injection vulnerabilityEPSS 0.5%CVE-2026-22417CRITICALWordPress Grand Wedding theme < 3.1.11 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2025-39485CRITICALWordPress GrandTour theme <= 5.6 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2024-12922CRITICALAltair <= 5.2.4 - Unauthenticated Arbitrary Options Update via pp_import_currentEPSS 0.5%CVE-2025-32928CRITICALWordPress Altair theme <= 5.2.2 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-39348CRITICALWordPress Grand Restaurant WordPress theme <= 7.0 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-39354CRITICALWordPress Grand Conference theme <= 5.3 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-68510HIGHWordPress Photography theme < 7.7.5 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2026-23542CRITICALWordPress Grand Restaurant theme <= 7.0.10 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-69301CRITICALWordPress PhotoMe theme <= 5.6.11 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-69370CRITICALWordPress Capella theme <= 2.5.5 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2026-27043HIGHWordPress Photography theme < 7.7.6 - Arbitrary File Upload vulnerabilityEPSS 0.4%CVE-2025-47579CRITICALWordPress Photography Theme <= 7.7.2 - PHP Object Injection VulnerabilityEPSS 0.3%CVE-2025-47584HIGHWordPress Photography theme <= 7.5.2 - PHP Object Injection vulnerabilityEPSS 0.3%CVE-2026-57770CRITICALWordPress Grand Photography theme <= 5.7.8 - PHP Object Injection vulnerabilityEPSS 0.3%CVE-2025-39352HIGHWordPress Grand Restaurant WordPress theme <= 7.0 - Arbitrary Options Deletion vulnerabilityEPSS 0.3%CVE-2025-22702MEDIUMWordPress Photography Theme <= 7.7.2 - Broken Access Control VulnerabilityEPSS 0.3%CVE-2025-60116MEDIUMWordPress Grand Conference Theme Custom Post Type plugin < 2.6.4 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2025-39353MEDIUMWordPress Grand Restaurant WordPress theme <= 7.0 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2025-63026MEDIUMWordPress Grand Restaurant Theme Elements for Elementor plugin <= 2.1.1 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%