CodexThemes / TheGem
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-65480 | WordPress TheGem theme < 5.12.1.1 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | Jul 23, 2026 |
| CVE-2025-62011 | WordPress TheGem theme <= 5.10.5 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | Nov 6, 2025 |
| CVE-2025-60097 | WordPress TheGem Theme <= 5.10.5 - Broken Access Control Vulnerability | MEDIUM | 5.4 | Sep 26, 2025 |
| CVE-2025-4339 | TheGem <= 5.10.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Theme Options Update | MEDIUM | 4.3 | May 13, 2025 |
| CVE-2025-4317 | TheGem <= 5.10.3 - Authenticated (Subscriber+) Arbitrary File Upload | HIGH | 8.8 | May 13, 2025 |
| CVE-2023-50892 | WordPress TheGem Theme <= 5.9.1 is vulnerable to Cross Site Scripting (XSS) | HIGH | 7.1 | Dec 29, 2023 |
Showing 1 to 5 of 5 CVEs