Skip to content
Noroxi

ThemeGrill records

13 published records for vendor themegrill.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
30.8%
Median publish → KEV
No record has entered KEV

All records

13 records
  • WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    themegrill · masteriyoMay 17, 2024

  • ThemeGrill Demo Importer 1.3.4 - 1.6.1 - Authorization Bypass to Site Reset

    CriticalCVSS 9.9No exploitEPSS 1%

    themegrill · themegrill demo importerOct 16, 2024

  • themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.

    CriticalCVSS 9.1Proof of conceptEPSS 4%

    themegrill · themegrill demo importerMay 5, 2021

  • themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database.

    HighCVSS 8.8No exploitEPSS 1%

    themegrill · themegrill demo importerMay 5, 2021

  • CVE-2023-3345
    27Monitor

    LMS by Masteriyo < 1.6.8 - Information Exposure

    MediumCVSS 6.5Proof of conceptEPSS 2%

    themegrill · masteriyoJul 31, 2023

  • CVE-2024-0679
    26Monitor

    ColorMag <= 3.1.2 - Missing Authorization to Arbitrary Plugin Installation

    MediumCVSS 6.5Proof of conceptEPSS 1%

    themegrill · colormagJan 20, 2024

  • WordPress ColorNews theme <= 1.2.6 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    themegrill · colornewsApr 29, 2024

  • CVE-2024-9218
    24Monitor

    Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid <= 1.3.14 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 0%

    themegrill · magazine blocksOct 2, 2024

  • WordPress Esteem theme <= 1.5.0 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.1No exploitEPSS 0%

    themegrill · esteemJul 22, 2024

  • WordPress LMS by Masteriyo plugin <= 1.7.3 - Broken Authentication vulnerability

    MediumCVSS 5.3Proof of conceptEPSS 1%

    themegrill · masteriyoMay 19, 2025

  • CVE-2024-1462
    21Monitor

    Maintenance Page <= 1.0.8 - Security Mechanism Bypass via REST API

    MediumCVSS 5.3No exploitEPSS 1%

    themegrill · maintenance pageMar 13, 2024

  • WordPress Himalayas theme <= 1.3.2 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 4.8No exploitEPSS 0%

    themegrill · himalayasAug 1, 2024

  • CVE-2024-1370
    17Monitor

    Maintenance Page <= 1.0.8 - Missing Authorization to Sensitive Information Exposure

    MediumCVSS 4.3No exploitEPSS 0%

    themegrill · maintenance pageMar 13, 2024