Vulnerabilidades en ThemeGoods

50 resultados
Análisis Vexday

ThemeGoods acumula 48 vulnerabilidades catalogadas, das quais 12 são críticas, mas nenhuma está sob exploração ativa conhecida. A fraqueza dominante é injeção XSS (CWE-79), típica de componentes web, com 4 novos registros nos últimos 90 dias indicando descoberta contínua. O risco atual é moderado devido à ausência de ataques em campo, mas a concentração em falhas de validação exige atenção em controles de sanitização de entrada.

CVE-2025-68524HIGHWordPress Avante theme < 3.0.5 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-67952HIGHWordPress Grand Tour theme < 5.6.2 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-68538HIGHWordPress Craft | Coffee Shop Cafe Restaurant WordPress theme <= 2.3.6 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-69321HIGHWordPress Grand Spa theme <= 3.5.5 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-68518HIGHWordPress Hoteller theme < 6.8.9 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-68520HIGHWordPress DotLife theme < 4.9.5 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-65487MEDIUMWordPress Photography theme <= 7.7.6 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2025-30964MEDIUMWordPress Photography theme < 7.7.6 - Server Side Request Forgery (SSRF) vulnerabilityEPSS 0.2%CVE-2026-27352HIGHWordPress Starto theme < 2.2.5 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-27348HIGHWordPress Photography theme < 7.7.6 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-67922HIGHWordPress Grand Restaurant theme < 7.0.9 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-64217HIGHWordPress Photography theme <= 7.7.2 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-27358HIGHWordPress Architecturer theme < 3.9.5 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-69151HIGHWordPress Grand Car Rental theme <= 3.7 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-27367HIGHWordPress Musico theme < 3.4.5 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-57769HIGHWordPress Grand Photography theme <= 5.7.8 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-27353HIGHWordPress Grand News | Magazine Newspaper WordPress theme <= 3.4.3 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-64224HIGHWordPress Grand Conference Theme Custom Post Type plugin < 2.6.4 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-69152HIGHWordPress Artale | Wedding Photography WordPress theme <= 2.2.2 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-69320HIGHWordPress Grand Magazine theme <= 3.5.7 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%