ThemeGrill records
13 published records for vendor themegrill.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 30.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-862 Missing Authorization2
- CWE-284 Improper Access Control2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-266 Incorrect Privilege Assignment1
- CWE-863 Incorrect Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2024-24882Proof of concept | WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerabilitythemegrill · masteriyo · CWE-266 | Critical9.8 | — | 2.1% | May 17, 2024 |
39Monitor | CVE-2020-36837No exploit | ThemeGrill Demo Importer 1.3.4 - 1.6.1 - Authorization Bypass to Site Resetthemegrill · themegrill demo importer · CWE-862 | Critical9.9 | — | 0.6% | Oct 16, 2024 |
37Monitor | CVE-2020-36333Proof of concept | themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.themegrill · themegrill demo importer · CWE-306 | Critical9.1 | — | 4.1% | May 5, 2021 |
35Monitor | CVE-2020-36334No exploit | themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database.themegrill · themegrill demo importer · CWE-352 | High8.8 | — | 0.6% | May 5, 2021 |
27Monitor | CVE-2023-3345Proof of concept | LMS by Masteriyo < 1.6.8 - Information Exposurethemegrill · masteriyo · CWE-863 | Medium6.5 | — | 2.0% | Jul 31, 2023 |
26Monitor | CVE-2024-0679Proof of concept | ColorMag <= 3.1.2 - Missing Authorization to Arbitrary Plugin Installationthemegrill · colormag · CWE-862 | Medium6.5 | — | 1.3% | Jan 20, 2024 |
26Monitor | CVE-2024-33540No exploit | WordPress ColorNews theme <= 1.2.6 - Cross Site Scripting (XSS) vulnerabilitythemegrill · colornews · CWE-79 | Medium6.5 | — | 0.3% | Apr 29, 2024 |
24Monitor | CVE-2024-9218No exploit | Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid <= 1.3.14 - Reflected Cross-Site Scriptingthemegrill · magazine blocks · CWE-79 | Medium6.1 | — | 0.4% | Oct 2, 2024 |
24Monitor | CVE-2024-37432No exploit | WordPress Esteem theme <= 1.5.0 - Cross Site Scripting (XSS) vulnerabilitythemegrill · esteem · CWE-79 | Medium6.1 | — | 0.3% | Jul 22, 2024 |
21Monitor | CVE-2024-33939Proof of concept | WordPress LMS by Masteriyo plugin <= 1.7.3 - Broken Authentication vulnerabilitythemegrill · masteriyo · CWE-288 | Medium5.3 | — | 0.9% | May 19, 2025 |
21Monitor | CVE-2024-1462No exploit | Maintenance Page <= 1.0.8 - Security Mechanism Bypass via REST APIthemegrill · maintenance page · CWE-284 | Medium5.3 | — | 0.5% | Mar 13, 2024 |
19Monitor | CVE-2024-39629No exploit | WordPress Himalayas theme <= 1.3.2 - Cross Site Scripting (XSS) vulnerabilitythemegrill · himalayas · CWE-79 | Medium4.8 | — | 0.3% | Aug 1, 2024 |
17Monitor | CVE-2024-1370No exploit | Maintenance Page <= 1.0.8 - Missing Authorization to Sensitive Information Exposurethemegrill · maintenance page · CWE-284 | Medium4.3 | — | 0.4% | Mar 13, 2024 |
- CVE-2024-2488240Plan
WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 2%themegrill · masteriyoMay 17, 2024
- CVE-2020-3683739Monitor
ThemeGrill Demo Importer 1.3.4 - 1.6.1 - Authorization Bypass to Site Reset
CriticalCVSS 9.9No exploitEPSS 1%themegrill · themegrill demo importerOct 16, 2024
- CVE-2020-3633337Monitor
themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.
CriticalCVSS 9.1Proof of conceptEPSS 4%themegrill · themegrill demo importerMay 5, 2021
- CVE-2020-3633435Monitor
themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database.
HighCVSS 8.8No exploitEPSS 1%themegrill · themegrill demo importerMay 5, 2021
- CVE-2023-334527Monitor
LMS by Masteriyo < 1.6.8 - Information Exposure
MediumCVSS 6.5Proof of conceptEPSS 2%themegrill · masteriyoJul 31, 2023
- CVE-2024-067926Monitor
ColorMag <= 3.1.2 - Missing Authorization to Arbitrary Plugin Installation
MediumCVSS 6.5Proof of conceptEPSS 1%themegrill · colormagJan 20, 2024
- CVE-2024-3354026Monitor
WordPress ColorNews theme <= 1.2.6 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.5No exploitEPSS 0%themegrill · colornewsApr 29, 2024
- CVE-2024-921824Monitor
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid <= 1.3.14 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 0%themegrill · magazine blocksOct 2, 2024
- CVE-2024-3743224Monitor
WordPress Esteem theme <= 1.5.0 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 0%themegrill · esteemJul 22, 2024
- CVE-2024-3393921Monitor
WordPress LMS by Masteriyo plugin <= 1.7.3 - Broken Authentication vulnerability
MediumCVSS 5.3Proof of conceptEPSS 1%themegrill · masteriyoMay 19, 2025
- CVE-2024-146221Monitor
Maintenance Page <= 1.0.8 - Security Mechanism Bypass via REST API
MediumCVSS 5.3No exploitEPSS 1%themegrill · maintenance pageMar 13, 2024
- CVE-2024-3962919Monitor
WordPress Himalayas theme <= 1.3.2 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 4.8No exploitEPSS 0%themegrill · himalayasAug 1, 2024
- CVE-2024-137017Monitor
Maintenance Page <= 1.0.8 - Missing Authorization to Sensitive Information Exposure
MediumCVSS 4.3No exploitEPSS 0%themegrill · maintenance pageMar 13, 2024