Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Moody HIGH 8.1
CVE-2025-22707

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Moody tm-moody all…

Fix: after 2.7.3
Fix from $1,950 2026-01-08
Mitech HIGH 8.1
CVE-2025-22708

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Mitech mitech allo…

Fix: after 2.3.4
Fix from $1,950 2026-01-08
Aeroland HIGH 8.1
CVE-2025-14429

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove AeroLand aeroland …

Fix: after 1.6.6
Fix from $1,950 2026-01-08
Brook HIGH 8.1
CVE-2025-14430

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Brook brook allows…

Fix: after 2.9.0
Fix from $1,950 2026-01-08
Minimogwp HIGH 8.1
CVE-2025-60069

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MinimogWP minimog …

Fix: after 3.9.6
Fix from $1,950 2025-12-18
Edumall HIGH 7.5
CVE-2025-68061

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove EduMall edumall al…

Fix: 4.4.7+
Fix from $1,950 2025-12-16
Minimogwp HIGH 7.5
CVE-2025-68062

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MinimogWP minimog …

Fix: after 3.9.6
Fix from $1,950 2025-12-16
Billey HIGH 8.1
CVE-2025-59558

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allo…

Fix: 2.1.6+
Fix from $1,950 2025-10-22
Edumall HIGH 8.1
CVE-2025-59564

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove EduMall edumall al…

Fix: 4.4.5+
Fix from $1,950 2025-10-22
Businext HIGH 8.1
CVE-2025-58967

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Businext businext …

Fix: 2.4.4+
Fix from $1,950 2025-10-22
Medizin HIGH 8.1
CVE-2025-59555

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Medizin medizin al…

Fix: 1.9.7+
Fix from $1,950 2025-10-22
Smilepure HIGH 8.1
CVE-2025-58958

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove SmilePure smilepur…

Fix: 1.8.5+
Fix from $1,950 2025-10-22
Maxcoach CRITICAL 9.8
CVE-2025-58206

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MaxCoach maxcoach …

Fix: after 3.2.5
Fix from $2,300 2025-09-05
Makeaholic CRITICAL 9.8
CVE-2025-58210

Missing Authorization vulnerability in ThemeMove Makeaholic makeaholic allows Exploiting Incorrectly Configured Access Control Security Levels.This i…

Fix: 1.8.7+
Fix from $2,300 2025-09-03
Unicamp CRITICAL 9.8
CVE-2025-54701

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Unicamp unicamp al…

Fix: 2.6.4+
Fix from $2,300 2025-08-14
Makeaholic CRITICAL 9.8
CVE-2025-54700

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Makeaholic makeaho…

Fix: 1.8.5+
Fix from $2,300 2025-08-14
Amely CRITICAL 9.8
CVE-2025-39474

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeMove Amely amely allows SQL Injection.This…

Fix: 3.2.0+
Fix from $2,300 2025-06-27
Healsoul HIGH 8.1
CVE-2025-32309

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Healsoul healsoul …

Fix: 2.2.4+
Fix from $1,950 2025-05-23
Insight Core MEDIUM 5.4
CVE-2021-24950

The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_options_import (available to …

No fix yet
Fix from $1,600 2022-03-14