Skip to content
Noroxi

Themify records

32 published records for vendor themify.

All records

32 records
  • Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/th

    CriticalCVSS 9.8No exploitEPSS 4%

    themify · frameworkJun 17, 2021

  • WordPress Themify Ultra Theme <= 7.3.5 is vulnerable to Arbitrary File Upload

    HighCVSS 8.8No exploitEPSS 1%

    themify · ultraDec 20, 2023

  • WordPress Themify Ultra theme <= 7.3.5 - Authenticated Privilege Escalation vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    themify · ultraMay 17, 2024

  • WordPress Themify Ultra Theme <= 7.3.5 is vulnerable to PHP Object Injection

    HighCVSS 8.8No exploitEPSS 0%

    themify · ultraDec 20, 2023

  • WordPress Themify Ultra theme <= 7.3.5 - Authenticated Arbitrary Settings Change vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    themify · ultraJun 19, 2024

  • WordPress Themify Ultra theme <= 7.3.5 - Multiple Broken Access Control vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    themify · ultraJun 19, 2024

  • WordPress Themify Builder Plugin <= 7.0.5 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    themify · builderFeb 21, 2024

  • CVE-2024-6027
    30Monitor

    Themify - WooCommerce Product Filter <= 1.4.9 - Unauthenticated SQL Injection via conditions Parameter

    HighCVSS 7.5No exploitEPSS 1%

    themify · product filterJun 21, 2024

  • WordPress Themify Builder plugin <= 7.6.3 - Local File Inclusion vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    themify · builderDec 31, 2024

  • CVE-2022-1532
    24Monitor

    Themify - WooCommerce Product Filter < 1.3.8 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 1%

    themify · woocommerce product filterJun 13, 2022

  • CVE-2024-3032
    24Monitor

    Themify Builder < 7.5.8 - Open Redirect

    MediumCVSS 6.1Proof of conceptEPSS 1%

    themify · builderJun 13, 2024

  • CVE-2022-1047
    24Monitor

    Themify - Post Type Builder Search Addon < 1.4.0 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 1%

    themify · post type builder search addonMay 9, 2022

  • CVE-2023-2654
    24Monitor

    Conditional Menus < 1.2.1 - Reflected XSS

    MediumCVSS 6.1No exploitEPSS 0%

    themify · conditional menusJun 19, 2023

  • CVE-2024-2278
    24Monitor

    WooCommerce Product Filter < 1.4.4 - Admin+ Stored XSS

    MediumCVSS 6.1No exploitEPSS 0%

    themify · woocommerce product filterApr 1, 2024

  • CVE-2024-9385
    24Monitor

    Themify Builder <= 7.6.2 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 0%

    themify · builderOct 4, 2024

  • Themify Builder <= 7.6.5 - Reflected Cross-Site Scripting

    MediumCVSS 6.1No exploitEPSS 0%

    themify · themify builderJan 22, 2025

  • Themify Portfolio Post < 1.1.6 - Authenticated Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 1%

    themify · portfolio postMar 18, 2021

  • CVE-2022-0200
    21Monitor

    Themify Portfolio Post < 1.1.7 - Reflected Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 1%

    themify · portfolio postFeb 14, 2022

  • CVE-2022-4464
    21Monitor

    Themify Portfolio Post < 1.2.1 - Contributor+ Stored XSS

    MediumCVSS 5.4No exploitEPSS 1%

    themify · portfolio postJan 16, 2023

  • CVE-2023-0362
    21Monitor

    Themify Portfolio Post < 1.2.2 - Contributor+ Stored XSS

    MediumCVSS 5.4No exploitEPSS 1%

    themify · portfolio postFeb 13, 2023

  • CVE-2022-4787
    21Monitor

    Themify Shortcodes < 2.0.8 - Contributor+ Stored XSS via Shortcode

    MediumCVSS 5.4No exploitEPSS 0%

    themify · shortcodesJan 30, 2023

  • CVE-2024-4567
    21Monitor

    Themify Shortcodes <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via themify_button Shortcode

    MediumCVSS 5.4No exploitEPSS 0%

    themify · themify shortcodesMay 14, 2024

  • WordPress Themify Portfolio Post Plugin <= 1.2.4 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    themify · portfolio postMay 10, 2023

  • CVE-2024-2732
    21Monitor

    Themify Shortcodes <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 0%

    themify · themify shortcodesMar 25, 2024

  • WordPress Themify Icons Plugin <= 2.0.1 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    themify · iconsFeb 1, 2024