ThemeBoy records
5 published records for vendor themeboy.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 40%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-862 Missing Authorization2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
25Monitor | CVE-2024-34824No exploit | WordPress SportsPress – Sports Club & League Manager plugin <= 2.7.20 - Broken Access Control vulnerabilitythemeboy · sportspress · CWE-862 | Medium6.3 | — | 0.2% | Jun 11, 2024 |
24Monitor | CVE-2021-24578No exploit | SportsPress < 2.7.9 - Reflected Cross-Site Scriptingthemeboy · sportspress · CWE-79 | Medium6.1 | — | 0.8% | Dec 21, 2021 |
21Monitor | CVE-2020-13892No exploit | The SportsPress plugin before 2.7.2 for WordPress allows XSS.themeboy · sportspress · CWE-79 | Medium5.4 | — | 0.7% | Jun 9, 2020 |
21Monitor | CVE-2024-1178No exploit | SportsPress – Sports Club & League Manager <= 2.7.17 - Missing Authorization to Unauthenticated Event Permalink Updatethemeboy · sportspress · CWE-862 | Medium5.3 | — | 0.4% | Mar 4, 2024 |
19Monitor | CVE-2024-3986No exploit | SportsPress < 2.7.22 - Admin+ Stored XSSthemeboy · sportspress · CWE-79 | Medium4.8 | — | 0.4% | Jul 30, 2024 |
- CVE-2024-3482425Monitor
WordPress SportsPress – Sports Club & League Manager plugin <= 2.7.20 - Broken Access Control vulnerability
MediumCVSS 6.3No exploitEPSS 0%themeboy · sportspressJun 11, 2024
- CVE-2021-2457824Monitor
SportsPress < 2.7.9 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%themeboy · sportspressDec 21, 2021
- CVE-2020-1389221Monitor
The SportsPress plugin before 2.7.2 for WordPress allows XSS.
MediumCVSS 5.4No exploitEPSS 1%themeboy · sportspressJun 9, 2020
- CVE-2024-117821Monitor
SportsPress – Sports Club & League Manager <= 2.7.17 - Missing Authorization to Unauthenticated Event Permalink Update
MediumCVSS 5.3No exploitEPSS 0%themeboy · sportspressMar 4, 2024
- CVE-2024-398619Monitor
SportsPress < 2.7.22 - Admin+ Stored XSS
MediumCVSS 4.8No exploitEPSS 0%themeboy · sportspressJul 30, 2024