CreativeThemes records
16 published records for vendor creativethemes.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 43.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-20 Improper Input Validation2
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2024-31382No exploit | WordPress Blocksy theme <= 2.0.22 - Cross Site Request Forgery (CSRF) vulnerabilitycreativethemes · blocksy · CWE-352 | High8.8 | — | 0.2% | Apr 15, 2024 |
35Monitor | CVE-2024-31932No exploit | WordPress Blocksy Companion plugin <= 2.0.28 - Cross Site Request Forgery (CSRF) vulnerabilitycreativethemes · blocksy companion · CWE-352 | High8.8 | — | 0.2% | Apr 11, 2024 |
35Monitor | CVE-2024-37469No exploit | WordPress Blocksy theme <= 1.9.5 - Cross Site Request Forgery (CSRF) vulnerabilitycreativethemes · blocksy · CWE-352 | High8.8 | — | 0.2% | Jan 2, 2025 |
25Monitor | CVE-2024-2392No exploit | Blocksy Companion <= 2.0.31 - Authenticated (Contributor+) Stored Cross-Site Scriptingcreativethemes · blocksy companion · CWE-79 | Medium6.4 | — | 0.3% | Mar 21, 2024 |
21Monitor | CVE-2024-4487No exploit | Blocksy Companion <= 2.0.45 - Authenticated (Contributor+) Stored Cross-Site Scripting via SVG Uploadscreativethemes · blocksy companion · CWE-79 | Medium5.4 | — | 0.4% | May 14, 2024 |
21Monitor | CVE-2024-3747No exploit | Blocksy <= 2.0.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via About Me blockcreativethemes · blocksy · CWE-20 | Medium5.4 | — | 0.4% | May 2, 2024 |
21Monitor | CVE-2023-23898No exploit | WordPress Blocksy Companion Plugin <= 1.8.67 is vulnerable to Cross Site Scripting (XSS)creativethemes · blocksy companion · CWE-79 | Medium5.4 | — | 0.3% | Apr 6, 2023 |
21Monitor | CVE-2024-4158No exploit | Blocksy <= 2.0.42 - Authenticated (Contributor+) Stored Cross-Site Scriptingcreativethemes · blocksy · CWE-79 | Medium5.4 | — | 0.3% | May 14, 2024 |
21Monitor | CVE-2024-24871No exploit | WordPress Blocksy theme <= 2.0.19 - Cross Site Scripting (XSS) vulnerabilitycreativethemes · blocksy · CWE-79 | Medium5.4 | — | 0.3% | Feb 8, 2024 |
21Monitor | CVE-2024-1767No exploit | Blocksy <= 2.0.26 - Authenticated (Contributor+) Stored Cross-Site Scriptingcreativethemes · blocksy · CWE-79 | Medium5.4 | — | 0.3% | Mar 9, 2024 |
21Monitor | CVE-2024-32961No exploit | WordPress Blocksy theme <= 2.0.33 - Cross Site Scripting (XSS) vulnerabilitycreativethemes · blocksy · CWE-79 | Medium5.4 | — | 0.3% | Apr 25, 2024 |
21Monitor | CVE-2024-5439No exploit | Blocksy <= 2.0.50 - Authenticated (Contributor+) Stored Cross-Site Scriptingcreativethemes · blocksy · CWE-20 | Medium5.4 | — | 0.3% | Jun 5, 2024 |
21Monitor | CVE-2024-4943No exploit | Blocksy <= 2.0.46 - Authenticated (Contributor+) Stored Cross-Site Scriptingcreativethemes · blocksy · CWE-79 | Medium5.4 | — | 0.3% | May 20, 2024 |
21Monitor | CVE-2024-11420No exploit | Blocksy <= 2.0.77 - Authenticated (Contributor+) Stored Cross-Site Scriptingcreativethemes · blocksy · CWE-79 | Medium5.4 | — | 0.3% | Dec 5, 2024 |
19Monitor | CVE-2024-35633No exploit | WordPress Blocksy Companion plugin <= 2.0.42 - Server Side Request Forgery (SSRF) vulnerabilitycreativethemes · blocksy companion · CWE-918 | Medium4.9 | — | 0.3% | Jun 3, 2024 |
17Monitor | CVE-2023-1911No exploit | Blocksy Companion < 1.8.82 - Subscriber+ Draft Post Accesscreativethemes · blocksy companion · CWE-639 | Medium4.3 | — | 0.6% | May 2, 2023 |
- CVE-2024-3138235Monitor
WordPress Blocksy theme <= 2.0.22 - Cross Site Request Forgery (CSRF) vulnerability
HighCVSS 8.8No exploitEPSS 0%creativethemes · blocksyApr 15, 2024
- CVE-2024-3193235Monitor
WordPress Blocksy Companion plugin <= 2.0.28 - Cross Site Request Forgery (CSRF) vulnerability
HighCVSS 8.8No exploitEPSS 0%creativethemes · blocksy companionApr 11, 2024
- CVE-2024-3746935Monitor
WordPress Blocksy theme <= 1.9.5 - Cross Site Request Forgery (CSRF) vulnerability
HighCVSS 8.8No exploitEPSS 0%creativethemes · blocksyJan 2, 2025
- CVE-2024-239225Monitor
Blocksy Companion <= 2.0.31 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 6.4No exploitEPSS 0%creativethemes · blocksy companionMar 21, 2024
- CVE-2024-448721Monitor
Blocksy Companion <= 2.0.45 - Authenticated (Contributor+) Stored Cross-Site Scripting via SVG Uploads
MediumCVSS 5.4No exploitEPSS 0%creativethemes · blocksy companionMay 14, 2024
- CVE-2024-374721Monitor
Blocksy <= 2.0.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via About Me block
MediumCVSS 5.4No exploitEPSS 0%creativethemes · blocksyMay 2, 2024
- CVE-2023-2389821Monitor
WordPress Blocksy Companion Plugin <= 1.8.67 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%creativethemes · blocksy companionApr 6, 2023
- CVE-2024-415821Monitor
Blocksy <= 2.0.42 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%creativethemes · blocksyMay 14, 2024
- CVE-2024-2487121Monitor
WordPress Blocksy theme <= 2.0.19 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%creativethemes · blocksyFeb 8, 2024
- CVE-2024-176721Monitor
Blocksy <= 2.0.26 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%creativethemes · blocksyMar 9, 2024
- CVE-2024-3296121Monitor
WordPress Blocksy theme <= 2.0.33 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%creativethemes · blocksyApr 25, 2024
- CVE-2024-543921Monitor
Blocksy <= 2.0.50 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%creativethemes · blocksyJun 5, 2024
- CVE-2024-494321Monitor
Blocksy <= 2.0.46 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%creativethemes · blocksyMay 20, 2024
- CVE-2024-1142021Monitor
Blocksy <= 2.0.77 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%creativethemes · blocksyDec 5, 2024
- CVE-2024-3563319Monitor
WordPress Blocksy Companion plugin <= 2.0.42 - Server Side Request Forgery (SSRF) vulnerability
MediumCVSS 4.9No exploitEPSS 0%creativethemes · blocksy companionJun 3, 2024
- CVE-2023-191117Monitor
Blocksy Companion < 1.8.82 - Subscriber+ Draft Post Access
MediumCVSS 4.3No exploitEPSS 1%creativethemes · blocksy companionMay 2, 2023