CVE-2025-69356
- EPSS 0.15%
- Veröffentlicht 06.01.2026 16:36:41
- Zuletzt bearbeitet 20.01.2026 15:20:04
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor allows PHP Local File Inclusion.This issue affects Th...
CVE-2025-68559
- EPSS 0.05%
- Veröffentlicht 23.12.2025 11:37:35
- Zuletzt bearbeitet 20.01.2026 15:19:45
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elementor).This issue affects TheGem Theme Elements (for Elementor): from n/a through 5.10.5.1.
CVE-2025-68560
- EPSS 0.17%
- Veröffentlicht 23.12.2025 11:36:26
- Zuletzt bearbeitet 20.01.2026 15:19:46
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor).This issue affects TheGem Theme Elements (for Elementor): from n/a through 5.10...
CVE-2025-62011
- EPSS 0.05%
- Veröffentlicht 06.11.2025 15:55:22
- Zuletzt bearbeitet 20.01.2026 15:17:38
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem thegem.This issue affects TheGem: from n/a through <= 5.10.5.
CVE-2025-60096
- EPSS 0.04%
- Veröffentlicht 26.09.2025 09:15:34
- Zuletzt bearbeitet 26.09.2025 14:32:19
Missing Authorization vulnerability in CodexThemes TheGem (Elementor) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects TheGem (Elementor): from n/a through 5.10.5.
CVE-2025-60097
- EPSS 0.04%
- Veröffentlicht 26.09.2025 09:15:34
- Zuletzt bearbeitet 26.09.2025 14:32:19
Missing Authorization vulnerability in CodexThemes TheGem allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects TheGem: from n/a through 5.10.5.
CVE-2025-4339
- EPSS 0.06%
- Veröffentlicht 13.05.2025 06:40:56
- Zuletzt bearbeitet 13.05.2025 19:35:18
The TheGem theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajaxApi() function in all versions up to, and including, 5.10.3. This makes it possible for authenticated attackers, with Subsc...
CVE-2025-4317
- EPSS 0.43%
- Veröffentlicht 13.05.2025 06:40:55
- Zuletzt bearbeitet 13.05.2025 19:35:18
The TheGem theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the thegem_get_logo_url() function in all versions up to, and including, 5.10.3. This makes it possible for authenticated attackers, with Su...