Vulnerabilities > Themify
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-11-18 | CVE-2024-52423 | Cross-site Scripting vulnerability in Themify Builder Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themify Themify Builder allows Stored XSS.This issue affects Themify Builder: from n/a through 7.6.3. | 5.4 |
2024-08-22 | CVE-2024-7836 | Incorrect Authorization vulnerability in Themify Builder The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to missing checks on the duplicate_page_ajaxify function in all versions up to, and including, 7.6.1. | 4.3 |
2024-06-21 | CVE-2024-6027 | SQL Injection vulnerability in Themify Product Filter The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to time-based SQL Injection via the ‘conditions’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |
2024-06-19 | CVE-2023-46146 | Missing Authorization vulnerability in Themify Ultra Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5. | 8.8 |
2024-06-19 | CVE-2023-46148 | Missing Authorization vulnerability in Themify Ultra Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5. | 8.8 |
2024-06-13 | CVE-2024-3032 | Open Redirect vulnerability in Themify Builder Themify Builder WordPress plugin before 7.5.8 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue | 6.1 |
2024-02-01 | CVE-2023-51693 | Cross-site Scripting vulnerability in Themify Icons Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Icons allows Stored XSS.This issue affects Themify Icons: from n/a through 2.0.1. | 5.4 |
2023-12-20 | CVE-2023-46149 | Unrestricted Upload of File with Dangerous Type vulnerability in Themify Ultra Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5. | 8.8 |
2023-12-20 | CVE-2023-46147 | Deserialization of Untrusted Data vulnerability in Themify Ultra Deserialization of Untrusted Data vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5. | 8.8 |
2023-06-19 | CVE-2023-2654 | Unspecified vulnerability in Themify Conditional Menus The Conditional Menus WordPress plugin before 1.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | 6.1 |