Vulnerability index

Browse CVEs

27 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2024-13319 The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping… Themify Builder 7.6.6+ Fix from $1,6002025-01-22 MEDIUM 6.5 CVE-2024-56216 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themifyme Themify Builder th… Builder after 7.6.3 Fix from $1,6002024-12-31 MEDIUM 5.4 CVE-2024-52423 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Builder themify-builder allow… Builder after 7.6.3 Fix from $1,6002024-11-18 MEDIUM 6.1 CVE-2024-9385 The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping… Builder 7.6.3+ Fix from $1,6002024-10-05 MEDIUM 5.4 CVE-2024-43133 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themify Themify Shortcodes allows Stored… Themify Shortcodes 2.1.2+ Fix from $1,6002024-08-12 HIGH 7.5 CVE-2024-6027 The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to time-based SQL Injection via the ‘conditions’ parameter in all version… Product Filter 1.5.0+ Fix from $1,9502024-06-21 HIGH 8.8 CVE-2023-46148 Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5. Ultra 7.3.5+ Fix from $1,9502024-06-19 HIGH 8.8 CVE-2023-46146 Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5. Ultra 7.3.6+ Fix from $1,9502024-06-19 MEDIUM 6.1 CVE-2024-3032 Themify Builder WordPress plugin before 7.5.8 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect iss… Builder 7.5.8+ Fix from $1,6002024-06-13 HIGH 8.8 CVE-2023-46145 Improper Privilege Management vulnerability in Themify Themify Ultra allows Privilege Escalation.This issue affects Themify Ultra: from n/a through 7… Ultra 7.3.6+ Fix from $1,9502024-05-17 MEDIUM 5.4 CVE-2024-4567 The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's themify_button shortcode in all versions up… Themify Shortcodes 2.1.0+ Fix from $1,6002024-05-14 MEDIUM 6.1 CVE-2024-2278 Themify WordPress plugin before 1.4.4 does not sanitise and escape some of its Filters settings, which could allow high privilege users such as admi… Woocommerce Product Filter 1.4.4+ Fix from $1,6002024-04-01 MEDIUM 5.4 CVE-2024-2732 The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'themify_post_slider shortcode in all versi… Themify Shortcodes 2.0.9+ Fix from $1,6002024-03-26 HIGH 8.8 CVE-2024-24872 Cross-Site Request Forgery (CSRF) vulnerability in Themify Themify Builder.This issue affects Themify Builder: from n/a through 7.0.5. Builder 7.0.6+ Fix from $1,9502024-02-21 MEDIUM 5.4 CVE-2023-51693 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Icons allows Stored XSS.This issue affe… Icons after 2.0.1 Fix from $1,6002024-02-01 HIGH 8.8 CVE-2023-46149 Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5. Ultra after 7.3.5 Fix from $1,9502023-12-20 HIGH 8.8 CVE-2023-46147 Deserialization of Untrusted Data vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5. Ultra 7.3.6+ Fix from $1,9502023-12-20 MEDIUM 6.1 CVE-2023-2654 The Conditional Menus WordPress plugin before 1.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cro… Conditional Menus 1.2.1+ Fix from $1,6002023-06-19 MEDIUM 5.4 CVE-2022-32970 Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Themify Themify Portfolio Post plugin <= 1.2.4 versions. Portfolio Post after 1.2.4 Fix from $1,6002023-05-10 MEDIUM 5.4 CVE-2023-0362 Themify Portfolio Post WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a p… Portfolio Post 1.2.2+ Fix from $1,6002023-02-13 MEDIUM 5.4 CVE-2022-4787 Themify Shortcodes WordPress plugin before 2.0.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as… Shortcodes 2.0.8+ Fix from $1,6002023-01-30 MEDIUM 5.4 CVE-2022-4464 Themify Portfolio Post WordPress plugin before 1.2.1 does not validate and escapes some of its shortcode attributes before outputting them back in th… Portfolio Post 1.2.1+ Fix from $1,6002023-01-16 MEDIUM 6.1 CVE-2022-1532 Themify WordPress plugin before 1.3.8 does not sanitise and escape the page parameter before outputting it back in an attribute in an admin page, lea… Woocommerce Product Filter 1.3.8+ Fix from $1,6002022-06-13 MEDIUM 6.1 CVE-2022-1047 The Themify Post Type Builder Search Addon WordPress plugin before 1.4.0 does not properly escape the current page URL before reusing it in a HTML at… Post Type Builder Search Addon 1.4.0+ Fix from $1,6002022-05-09 MEDIUM 5.4 CVE-2022-0200 Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outputting it back the response o… Portfolio Post 1.1.7+ Fix from $1,6002022-02-14 CRITICAL 9.8 CVE-2013-20002 Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/the… Framework 1.2.2+ Fix from $2,3002021-06-17 MEDIUM 5.4 CVE-2021-24129 Unvalidated input and lack of output encoding in the Themify Portfolio Post WordPress plugin, versions before 1.1.6, lead to Stored Cross-Site Script… Portfolio Post 1.1.6+ Fix from $1,6002021-03-18