Themify records
32 published records for vendor themify.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')19
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-862 Missing Authorization2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-269 Improper Privilege Management1
The weakness classes this vendor ships most often: where to look.
CWEAll records
32 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2013-20002No exploit | Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/ththemify · framework · CWE-434 | Critical9.8 | — | 3.9% | Jun 17, 2021 |
35Monitor | CVE-2023-46149No exploit | WordPress Themify Ultra Theme <= 7.3.5 is vulnerable to Arbitrary File Uploadthemify · ultra · CWE-434 | High8.8 | — | 0.6% | Dec 20, 2023 |
35Monitor | CVE-2023-46145No exploit | WordPress Themify Ultra theme <= 7.3.5 - Authenticated Privilege Escalation vulnerabilitythemify · ultra · CWE-269 | High8.8 | — | 0.6% | May 17, 2024 |
35Monitor | CVE-2023-46147No exploit | WordPress Themify Ultra Theme <= 7.3.5 is vulnerable to PHP Object Injectionthemify · ultra · CWE-502 | High8.8 | — | 0.5% | Dec 20, 2023 |
35Monitor | CVE-2023-46148No exploit | WordPress Themify Ultra theme <= 7.3.5 - Authenticated Arbitrary Settings Change vulnerabilitythemify · ultra · CWE-862 | High8.8 | — | 0.4% | Jun 19, 2024 |
35Monitor | CVE-2023-46146No exploit | WordPress Themify Ultra theme <= 7.3.5 - Multiple Broken Access Control vulnerabilitythemify · ultra · CWE-862 | High8.8 | — | 0.4% | Jun 19, 2024 |
35Monitor | CVE-2024-24872No exploit | WordPress Themify Builder Plugin <= 7.0.5 is vulnerable to Cross Site Request Forgery (CSRF)themify · builder · CWE-352 | High8.8 | — | 0.2% | Feb 21, 2024 |
30Monitor | CVE-2024-6027No exploit | Themify - WooCommerce Product Filter <= 1.4.9 - Unauthenticated SQL Injection via conditions Parameterthemify · product filter · CWE-89 | High7.5 | — | 0.8% | Jun 21, 2024 |
26Monitor | CVE-2024-56216No exploit | WordPress Themify Builder plugin <= 7.6.3 - Local File Inclusion vulnerabilitythemify · builder · CWE-98 | Medium6.5 | — | 0.5% | Dec 31, 2024 |
24Monitor | CVE-2022-1532No exploit | Themify - WooCommerce Product Filter < 1.3.8 - Reflected Cross-Site Scriptingthemify · woocommerce product filter · CWE-79 | Medium6.1 | — | 0.8% | Jun 13, 2022 |
24Monitor | CVE-2024-3032Proof of concept | Themify Builder < 7.5.8 - Open Redirectthemify · builder · CWE-601 | Medium6.1 | — | 0.8% | Jun 13, 2024 |
24Monitor | CVE-2022-1047No exploit | Themify - Post Type Builder Search Addon < 1.4.0 - Reflected Cross-Site Scriptingthemify · post type builder search addon · CWE-79 | Medium6.1 | — | 0.8% | May 9, 2022 |
24Monitor | CVE-2023-2654No exploit | Conditional Menus < 1.2.1 - Reflected XSSthemify · conditional menus · CWE-79 | Medium6.1 | — | 0.5% | Jun 19, 2023 |
24Monitor | CVE-2024-2278No exploit | WooCommerce Product Filter < 1.4.4 - Admin+ Stored XSSthemify · woocommerce product filter · CWE-79 | Medium6.1 | — | 0.4% | Apr 1, 2024 |
24Monitor | CVE-2024-9385No exploit | Themify Builder <= 7.6.2 - Reflected Cross-Site Scriptingthemify · builder · CWE-79 | Medium6.1 | — | 0.4% | Oct 4, 2024 |
24Monitor | CVE-2024-13319No exploit | Themify Builder <= 7.6.5 - Reflected Cross-Site Scriptingthemify · themify builder · CWE-79 | Medium6.1 | — | 0.3% | Jan 22, 2025 |
21Monitor | CVE-2021-24129No exploit | Themify Portfolio Post < 1.1.6 - Authenticated Stored Cross-Site Scriptingthemify · portfolio post · CWE-79 | Medium5.4 | — | 0.7% | Mar 18, 2021 |
21Monitor | CVE-2022-0200No exploit | Themify Portfolio Post < 1.1.7 - Reflected Cross-Site Scriptingthemify · portfolio post · CWE-79 | Medium5.4 | — | 0.6% | Feb 14, 2022 |
21Monitor | CVE-2022-4464No exploit | Themify Portfolio Post < 1.2.1 - Contributor+ Stored XSSthemify · portfolio post · CWE-79 | Medium5.4 | — | 0.5% | Jan 16, 2023 |
21Monitor | CVE-2023-0362No exploit | Themify Portfolio Post < 1.2.2 - Contributor+ Stored XSSthemify · portfolio post · CWE-79 | Medium5.4 | — | 0.5% | Feb 13, 2023 |
21Monitor | CVE-2022-4787No exploit | Themify Shortcodes < 2.0.8 - Contributor+ Stored XSS via Shortcodethemify · shortcodes · CWE-79 | Medium5.4 | — | 0.5% | Jan 30, 2023 |
21Monitor | CVE-2024-4567No exploit | Themify Shortcodes <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via themify_button Shortcodethemify · themify shortcodes · CWE-79 | Medium5.4 | — | 0.4% | May 14, 2024 |
21Monitor | CVE-2022-32970No exploit | WordPress Themify Portfolio Post Plugin <= 1.2.4 is vulnerable to Cross Site Scripting (XSS)themify · portfolio post · CWE-79 | Medium5.4 | — | 0.4% | May 10, 2023 |
21Monitor | CVE-2024-2732No exploit | Themify Shortcodes <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scriptingthemify · themify shortcodes · CWE-79 | Medium5.4 | — | 0.3% | Mar 25, 2024 |
21Monitor | CVE-2023-51693No exploit | WordPress Themify Icons Plugin <= 2.0.1 is vulnerable to Cross Site Scripting (XSS)themify · icons · CWE-79 | Medium5.4 | — | 0.3% | Feb 1, 2024 |
- CVE-2013-2000240Plan
Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/th
CriticalCVSS 9.8No exploitEPSS 4%themify · frameworkJun 17, 2021
- CVE-2023-4614935Monitor
WordPress Themify Ultra Theme <= 7.3.5 is vulnerable to Arbitrary File Upload
HighCVSS 8.8No exploitEPSS 1%themify · ultraDec 20, 2023
- CVE-2023-4614535Monitor
WordPress Themify Ultra theme <= 7.3.5 - Authenticated Privilege Escalation vulnerability
HighCVSS 8.8No exploitEPSS 1%themify · ultraMay 17, 2024
- CVE-2023-4614735Monitor
WordPress Themify Ultra Theme <= 7.3.5 is vulnerable to PHP Object Injection
HighCVSS 8.8No exploitEPSS 0%themify · ultraDec 20, 2023
- CVE-2023-4614835Monitor
WordPress Themify Ultra theme <= 7.3.5 - Authenticated Arbitrary Settings Change vulnerability
HighCVSS 8.8No exploitEPSS 0%themify · ultraJun 19, 2024
- CVE-2023-4614635Monitor
WordPress Themify Ultra theme <= 7.3.5 - Multiple Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%themify · ultraJun 19, 2024
- CVE-2024-2487235Monitor
WordPress Themify Builder Plugin <= 7.0.5 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%themify · builderFeb 21, 2024
- CVE-2024-602730Monitor
Themify - WooCommerce Product Filter <= 1.4.9 - Unauthenticated SQL Injection via conditions Parameter
HighCVSS 7.5No exploitEPSS 1%themify · product filterJun 21, 2024
- CVE-2024-5621626Monitor
WordPress Themify Builder plugin <= 7.6.3 - Local File Inclusion vulnerability
MediumCVSS 6.5No exploitEPSS 0%themify · builderDec 31, 2024
- CVE-2022-153224Monitor
Themify - WooCommerce Product Filter < 1.3.8 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%themify · woocommerce product filterJun 13, 2022
- CVE-2024-303224Monitor
Themify Builder < 7.5.8 - Open Redirect
MediumCVSS 6.1Proof of conceptEPSS 1%themify · builderJun 13, 2024
- CVE-2022-104724Monitor
Themify - Post Type Builder Search Addon < 1.4.0 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%themify · post type builder search addonMay 9, 2022
- CVE-2023-265424Monitor
Conditional Menus < 1.2.1 - Reflected XSS
MediumCVSS 6.1No exploitEPSS 0%themify · conditional menusJun 19, 2023
- CVE-2024-227824Monitor
WooCommerce Product Filter < 1.4.4 - Admin+ Stored XSS
MediumCVSS 6.1No exploitEPSS 0%themify · woocommerce product filterApr 1, 2024
- CVE-2024-938524Monitor
Themify Builder <= 7.6.2 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 0%themify · builderOct 4, 2024
- CVE-2024-1331924Monitor
Themify Builder <= 7.6.5 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 0%themify · themify builderJan 22, 2025
- CVE-2021-2412921Monitor
Themify Portfolio Post < 1.1.6 - Authenticated Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 1%themify · portfolio postMar 18, 2021
- CVE-2022-020021Monitor
Themify Portfolio Post < 1.1.7 - Reflected Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 1%themify · portfolio postFeb 14, 2022
- CVE-2022-446421Monitor
Themify Portfolio Post < 1.2.1 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 1%themify · portfolio postJan 16, 2023
- CVE-2023-036221Monitor
Themify Portfolio Post < 1.2.2 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 1%themify · portfolio postFeb 13, 2023
- CVE-2022-478721Monitor
Themify Shortcodes < 2.0.8 - Contributor+ Stored XSS via Shortcode
MediumCVSS 5.4No exploitEPSS 0%themify · shortcodesJan 30, 2023
- CVE-2024-456721Monitor
Themify Shortcodes <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via themify_button Shortcode
MediumCVSS 5.4No exploitEPSS 0%themify · themify shortcodesMay 14, 2024
- CVE-2022-3297021Monitor
WordPress Themify Portfolio Post Plugin <= 1.2.4 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%themify · portfolio postMay 10, 2023
- CVE-2024-273221Monitor
Themify Shortcodes <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%themify · themify shortcodesMar 25, 2024
- CVE-2023-5169321Monitor
WordPress Themify Icons Plugin <= 2.0.1 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%themify · iconsFeb 1, 2024