Aggregates CVE and security vulnerability intelligence across all cththemes-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Common weakness patterns include vendor risk cross-site scripting, with potential vendor impact session compromise across vendor surface software deployment and vendor surface production workloads use cases.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2023-36502 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cththemes Balkon plugin <= 1.3.2 versions. | [email protected] | 7.1 | 0.10% | 2023-07-25 | 2024-11-21 |
| CVE-2023-29430 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CTHthemes TheRoof theme <= 1.0.3 versions. | [email protected] | 7.1 | 0.08% | 2023-06-26 | 2024-11-21 |
| CVE-2023-29236 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cththemes Outdoor theme <= 3.9.6 versions. | [email protected] | 7.1 | 0.20% | 2023-04-07 | 2024-11-21 |
| CVE-2023-25041 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cththemes Monolit theme <= 2.0.6 versions. | [email protected] | 7.1 | 0.20% | 2023-04-07 | 2024-11-21 |
| CVE-2019-20212 | The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form. | [email protected] | 6.1 | 0.64% | 2020-01-13 | 2024-11-21 |
| CVE-2019-20211 | The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, Description, Name, Job or Position, Description, Service Name, Address, Latitude, Longitude, Phone Number, or Website. | [email protected] | 6.1 | 0.75% | 2020-01-13 | 2024-11-21 |
| CVE-2019-20210 | The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query. | [email protected] | 6.1 | 0.38% | 2020-01-13 | 2024-11-21 |
| CVE-2019-20209 | The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php to delete any page/post/listing. | [email protected] | 7.5 | 0.99% | 2020-01-13 | 2024-11-21 |