themegoods CVE Vulnerabilities & CVE List (14)

Products (CPE): — CVEs: 14

themegoods vulnerability overview

Aggregates CVE and security vulnerability intelligence across all themegoods-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk cross-site scripting, vendor risk csrf, and vendor risk path handling and related problems; some flaws may lead to vendor impact session compromise and vendor impact file overwrite.

Vulnerability distribution trend (last 24 months)

Showing 114 of 14 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-67922 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Reflected XSS.This issue affects Grand Restaurant: from n/a through < 7.0.9. [email protected] 7.1 0.18% 2026-01-08 2026-06-17
CVE-2025-64217 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Photography photography allows Reflected XSS.This issue affects Photography: from n/a through <= 7.7.2. [email protected] 7.1 0.18% 2025-12-18 2026-06-17
CVE-2025-64224 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Conference Theme Custom Post Type grandconference-custom-post allows Reflected XSS.This issue affects Grand Conference Theme Custom Post Type: from n/a through < 2.6.4. [email protected] 7.1 0.15% 2025-11-06 2026-06-17
CVE-2025-60116 Missing Authorization vulnerability in ThemeGoods Grand Conference Theme Custom Post Type grandconference-custom-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Conference Theme Custom Post Type: from n/a through < 2.6.4. [email protected] 5.4 0.27% 2025-09-26 2026-06-17
CVE-2025-47579 Deserialization of Untrusted Data vulnerability in ThemeGoods Photography photography allows Object Injection.This issue affects Photography: from n/a through <= 7.7.2. [email protected] 9.0 0.30% 2025-09-09 2026-06-17
CVE-2025-47584 Deserialization of Untrusted Data vulnerability in ThemeGoods Photography.This issue affects Photography: from n/a through 7.5.2. [email protected] 8.5 0.25% 2025-06-06 2026-06-17
CVE-2025-39485 Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour grandtour allows Object Injection.This issue affects Grand Tour: from n/a through <= 5.6. [email protected] 9.8 0.50% 2025-05-23 2026-06-17
CVE-2025-39354 Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Conference grandconference allows Object Injection.This issue affects Grand Conference: from n/a through <= 5.3. [email protected] 9.8 0.37% 2025-05-19 2026-06-17
CVE-2025-39352 Missing Authorization vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant: from n/a through <= 7.0. [email protected] 8.2 0.26% 2025-05-19 2026-06-17
CVE-2025-39348 Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Restaurant: from n/a through <= 7.0. [email protected] 9.8 0.40% 2025-05-19 2026-06-17
CVE-2025-32928 Deserialization of Untrusted Data vulnerability in ThemeGoods Altair altair allows Object Injection.This issue affects Altair: from n/a through <= 5.2.2. [email protected] 9.8 0.40% 2025-05-19 2026-06-17
CVE-2025-32926 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Path Traversal.This issue affects Grand Restaurant: from n/a through <= 7.0. [email protected] 9.8 0.47% 2025-05-19 2026-06-17
CVE-2025-39353 Missing Authorization vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant: from n/a through <= 7.0. [email protected] 5.3 0.22% 2025-05-19 2026-06-17
CVE-2025-39351 Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Cross Site Request Forgery.This issue affects Grand Restaurant: from n/a through <= 7.0. [email protected] 4.3 0.13% 2025-05-19 2026-06-17
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence