Codexthemes

Thegem

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 23.07.2026 11:18:51
  • Zuletzt bearbeitet 14.08.2026 11:16:57

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem allows DOM-Based XSS. This issue affects TheGem: from n/a before 5.12.1.1.

  • EPSS 0.37%
  • Veröffentlicht 13.07.2026 08:41:25
  • Zuletzt bearbeitet 14.08.2026 11:16:57

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows PHP Local File Inclusion. This issue affects TheGem Theme Elements (for...

  • EPSS 0.13%
  • Veröffentlicht 27.04.2026 10:41:03
  • Zuletzt bearbeitet 27.04.2026 18:37:59

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows DOM-Based XSS.This issue affects TheGem Theme Elements (for Elementor): from n/a before 5.1...

  • EPSS 0.34%
  • Veröffentlicht 06.01.2026 16:36:41
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor allows PHP Local File Inclusion.This issue affects Th...

  • EPSS 0.16%
  • Veröffentlicht 23.12.2025 11:37:35
  • Zuletzt bearbeitet 23.04.2026 15:36:01

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor.This issue affects TheGem Theme Elements (for Elementor): from n/a throu...

  • EPSS 0.37%
  • Veröffentlicht 23.12.2025 11:36:26
  • Zuletzt bearbeitet 23.04.2026 15:36:01

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor.This issue affects TheGem Theme Elements (for Element...

  • EPSS 0.2%
  • Veröffentlicht 06.11.2025 15:55:22
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem thegem.This issue affects TheGem: from n/a through <= 5.10.5.

  • EPSS 0.25%
  • Veröffentlicht 26.09.2025 09:15:34
  • Zuletzt bearbeitet 23.04.2026 15:34:12

Missing Authorization vulnerability in CodexThemes TheGem (Elementor) thegem-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TheGem (Elementor): from n/a through <= 5.10.5.

  • EPSS 0.25%
  • Veröffentlicht 26.09.2025 09:15:34
  • Zuletzt bearbeitet 23.04.2026 15:34:12

Missing Authorization vulnerability in CodexThemes TheGem thegem allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TheGem: from n/a through <= 5.10.5.

Medienbericht
  • EPSS 0.42%
  • Veröffentlicht 13.05.2025 06:40:56
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The TheGem theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajaxApi() function in all versions up to, and including, 5.10.3. This makes it possible for authenticated attackers, with Subsc...