ThemeGoods records
14 published records for vendor themegoods.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 28.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-502 Deserialization of Untrusted Data6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-862 Missing Authorization3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-39485No exploit | WordPress GrandTour theme <= 5.6 - PHP Object Injection vulnerabilitythemegoods · grand tour · CWE-502 | Critical9.8 | — | 0.6% | May 23, 2025 |
39Monitor | CVE-2025-32926No exploit | WordPress Grand Restaurant WordPress theme <= 7.0 - Path Traversal to PHP Object Injection vulnerabilitythemegoods · grand restaurant · CWE-22 | Critical9.8 | — | 0.6% | May 19, 2025 |
39Monitor | CVE-2025-39354No exploit | WordPress Grand Conference theme <= 5.3 - PHP Object Injection vulnerabilitythemegoods · grand conference · CWE-502 | Critical9.8 | — | 0.5% | May 19, 2025 |
39Monitor | CVE-2025-39348No exploit | WordPress Grand Restaurant WordPress theme <= 7.0 - PHP Object Injection vulnerabilitythemegoods · grand restaurant · CWE-502 | Critical9.8 | — | 0.5% | May 19, 2025 |
39Monitor | CVE-2025-32928No exploit | WordPress Altair theme <= 5.2.2 - PHP Object Injection vulnerabilitythemegoods · altair · CWE-502 | Critical9.8 | — | 0.5% | May 19, 2025 |
35Monitor | CVE-2025-60116No exploit | WordPress Grand Conference Theme Custom Post Type plugin < 2.6.4 - Broken Access Control vulnerabilitythemegoods · grand conference · CWE-862 | High8.8 | — | 0.3% | Sep 26, 2025 |
32Monitor | CVE-2025-47579No exploit | WordPress Photography Theme <= 7.7.2 - PHP Object Injection Vulnerabilitythemegoods · photography · CWE-502 | High8.1 | — | 0.3% | Sep 9, 2025 |
32Monitor | CVE-2025-39352No exploit | WordPress Grand Restaurant WordPress theme <= 7.0 - Arbitrary Options Deletion vulnerabilitythemegoods · grand restaurant · CWE-862 | High8.2 | — | 0.3% | May 19, 2025 |
30Monitor | CVE-2025-47584No exploit | WordPress Photography theme <= 7.5.2 - PHP Object Injection vulnerabilitythemegoods · photography · CWE-502 | High7.5 | — | 0.4% | Jun 6, 2025 |
28Monitor | CVE-2025-67922No exploit | WordPress Grand Restaurant theme < 7.0.9 - Cross Site Scripting (XSS) vulnerabilitythemegoods · grand restaurant · CWE-79 | High7.1 | — | 0.2% | Jan 8, 2026 |
28Monitor | CVE-2025-64217No exploit | WordPress Photography theme <= 7.7.2 - Cross Site Scripting (XSS) vulnerabilitythemegoods · photography · CWE-79 | High7.1 | — | 0.2% | Dec 18, 2025 |
28Monitor | CVE-2025-64224No exploit | WordPress Grand Conference Theme Custom Post Type plugin < 2.6.4 - Cross Site Scripting (XSS) vulnerabilitythemegoods · grand conference · CWE-79 | High7.1 | — | 0.2% | Nov 6, 2025 |
21Monitor | CVE-2025-39353No exploit | WordPress Grand Restaurant WordPress theme <= 7.0 - Broken Access Control vulnerabilitythemegoods · grand restaurant · CWE-862 | Medium5.3 | — | 0.3% | May 19, 2025 |
17Monitor | CVE-2025-39351No exploit | WordPress Grand Restaurant WordPress theme <= 7.0 - Cross Site Request Forgery (CSRF) vulnerabilitythemegoods · grand restaurant · CWE-352 | Medium4.3 | — | 0.1% | May 19, 2025 |
- CVE-2025-3948539Monitor
WordPress GrandTour theme <= 5.6 - PHP Object Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 1%themegoods · grand tourMay 23, 2025
- CVE-2025-3292639Monitor
WordPress Grand Restaurant WordPress theme <= 7.0 - Path Traversal to PHP Object Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 1%themegoods · grand restaurantMay 19, 2025
- CVE-2025-3935439Monitor
WordPress Grand Conference theme <= 5.3 - PHP Object Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 0%themegoods · grand conferenceMay 19, 2025
- CVE-2025-3934839Monitor
WordPress Grand Restaurant WordPress theme <= 7.0 - PHP Object Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 0%themegoods · grand restaurantMay 19, 2025
- CVE-2025-3292839Monitor
WordPress Altair theme <= 5.2.2 - PHP Object Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 0%themegoods · altairMay 19, 2025
- CVE-2025-6011635Monitor
WordPress Grand Conference Theme Custom Post Type plugin < 2.6.4 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%themegoods · grand conferenceSep 26, 2025
- CVE-2025-4757932Monitor
WordPress Photography Theme <= 7.7.2 - PHP Object Injection Vulnerability
HighCVSS 8.1No exploitEPSS 0%themegoods · photographySep 9, 2025
- CVE-2025-3935232Monitor
WordPress Grand Restaurant WordPress theme <= 7.0 - Arbitrary Options Deletion vulnerability
HighCVSS 8.2No exploitEPSS 0%themegoods · grand restaurantMay 19, 2025
- CVE-2025-4758430Monitor
WordPress Photography theme <= 7.5.2 - PHP Object Injection vulnerability
HighCVSS 7.5No exploitEPSS 0%themegoods · photographyJun 6, 2025
- CVE-2025-6792228Monitor
WordPress Grand Restaurant theme < 7.0.9 - Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1No exploitEPSS 0%themegoods · grand restaurantJan 8, 2026
- CVE-2025-6421728Monitor
WordPress Photography theme <= 7.7.2 - Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1No exploitEPSS 0%themegoods · photographyDec 18, 2025
- CVE-2025-6422428Monitor
WordPress Grand Conference Theme Custom Post Type plugin < 2.6.4 - Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1No exploitEPSS 0%themegoods · grand conferenceNov 6, 2025
- CVE-2025-3935321Monitor
WordPress Grand Restaurant WordPress theme <= 7.0 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%themegoods · grand restaurantMay 19, 2025
- CVE-2025-3935117Monitor
WordPress Grand Restaurant WordPress theme <= 7.0 - Cross Site Request Forgery (CSRF) vulnerability
MediumCVSS 4.3No exploitEPSS 0%themegoods · grand restaurantMay 19, 2025