Vulnerabilities > Themeum > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-12-28 CVE-2023-50859 Cross-site Scripting vulnerability in Themeum WP Crowdfunding
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum WP Crowdfunding allows Stored XSS.This issue affects WP Crowdfunding: from n/a through 2.1.6.
network
low complexity
themeum CWE-79
5.4
2023-12-15 CVE-2023-49829 Unspecified vulnerability in Themeum Tutor LMS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS – eLearning and online course solution allows Stored XSS.This issue affects Tutor LMS – eLearning and online course solution: from n/a through 2.2.4.
network
low complexity
themeum
4.8
2023-12-11 CVE-2023-5757 Cross-site Scripting vulnerability in Themeum WP Crowdfunding
The WP Crowdfunding WordPress plugin before 2.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
network
low complexity
themeum CWE-79
4.8
2023-11-14 CVE-2023-47532 Cross-site Scripting vulnerability in Themeum WP Crowdfunding
Unauth.
network
low complexity
themeum CWE-79
6.1
2023-10-16 CVE-2023-4805 Unspecified vulnerability in Themeum Tutor LMS
The Tutor LMS WordPress plugin before 2.3.0 does not sanitise and escape some of its settings, which could allow users such as subscriber to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
network
low complexity
themeum
5.4
2023-02-06 CVE-2023-0236 Unspecified vulnerability in Themeum Tutor LMS
The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
network
low complexity
themeum
6.1
2022-12-05 CVE-2022-3830 Unspecified vulnerability in Themeum WP Page Builder
The WP Page Builder WordPress plugin through 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
network
low complexity
themeum
4.8
2022-11-18 CVE-2022-40963 Cross-site Scripting vulnerability in Themeum WP Page Builder
Multiple Auth.
network
low complexity
themeum CWE-79
5.4
2022-10-17 CVE-2022-2563 Unspecified vulnerability in Themeum Tutor LMS
The Tutor LMS WordPress plugin before 2.0.10 does not escape some course parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
network
low complexity
themeum
4.8
2022-01-24 CVE-2021-25013 Cross-Site Request Forgery (CSRF) vulnerability in Themeum Qubely
The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any authenticated users, such as subscriber can delete arbitrary posts
network
low complexity
themeum CWE-352
6.5