Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Betheme MEDIUM 5.4
CVE-2025-3077

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button shortcode and Custom CSS field in all versions u…

Fix: 28.0.4+
Fix from $1,600 2025-04-16
Betheme MEDIUM 5.4
CVE-2025-0450

The Betheme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom JS functionality in all versions up to, and inc…

Fix: 27.6.2+
Fix from $1,600 2025-01-21
Betheme MEDIUM 5.4
CVE-2024-5567

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 27.5.5 due to…

Fix: 27.5.5+
Fix from $1,600 2024-09-13
Betheme HIGH 8.8
CVE-2024-2694

The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via deserialization of untrusted i…

Fix: after 27.5.6
Fix from $1,950 2024-08-30
Betheme MEDIUM 5.4
CVE-2024-3998

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and includ…

Fix: after 27.5.6
Fix from $1,600 2024-08-30
Betheme HIGH 7.2
CVE-2023-39998

Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 27.1.1.

Fix: 27.1.2+
Fix from $1,950 2024-06-19
Betheme HIGH 7.6
CVE-2023-47770

Missing Authorization vulnerability in Muffin Group Betheme.This issue affects Betheme: from n/a through 27.1.1.

Fix: 27.1.2+
Fix from $1,950 2024-06-19
Betheme HIGH 8.8
CVE-2022-45356

Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1.

Fix: 26.6.3+
Fix from $1,950 2024-03-25
Betheme MEDIUM 5.4
CVE-2022-45351

Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1.

Fix: after 26.6.1
Fix from $1,600 2024-03-25
Betheme MEDIUM 6.1
CVE-2023-29101

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Muffingroup Betheme theme <= 26.7.5 versions.

Fix: after 26.7.5
Fix from $1,600 2023-05-10
Betheme HIGH 8.1
CVE-2022-45353

Broken Access Control in Betheme theme <= 26.6.1 on WordPress.

Fix: after 26.6.1
Fix from $1,950 2023-01-14
Becustom MEDIUM 6.5
CVE-2022-3747

The Becustom plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5.2. This is due to missing nonce…

Fix: after 1.0.5.2
Fix from $1,600 2022-11-29
Betheme MEDIUM 5.4
CVE-2022-45363

Auth. (subscriber+) Stored Cross-Site Scripting (XSS) in Muffingroup Betheme theme <= 26.6.1 on WordPress.

Fix: after 26.6.1
Fix from $1,600 2022-11-22
Betheme HIGH 8.8
CVE-2022-3861

The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via deserialization of untrusted inp…

Fix: 26.6+
Fix from $1,950 2022-11-21
Betheme HIGH 8.8
CVE-2022-45077

Auth. (subscriber+) PHP Object Injection vulnerability in Betheme theme <= 26.5.1.4 on WordPress.

Fix: 26.6+
Fix from $1,950 2022-11-17