« Back to list

8theme

8theme Xstore Core: vulnerabilities and CVEs

8theme Xstore Core has 12 published vulnerabilities, 4 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.

CVEs12
Last 12 months4
Critical4
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-25306High (7.1)0.18%—Mar 25, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows Reflected XSS.This issue affects XStore Core: from n/a through <= 5.6.4.
CVE-2026-25307Medium (6.5)0.17%—Feb 19, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows DOM-Based XSS.This issue affects XStore Core: from n/a through < 5.7.
CVE-2025-64190Medium (6.5)0.16%—Dec 30, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows DOM-Based XSS.This issue affects XStore Core: from n/a through < 5.6.
CVE-2025-64189High (7.1)0.22%—Dec 18, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows Reflected XSS.This issue affects XStore Core: from n/a through < 5.6.
CVE-2024-33555High (8.8)0.42%—Jun 9, 2024
Missing Authorization vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8.
CVE-2024-33557High (8.8)0.56%—Jun 4, 2024
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore Core allows PHP Local File Inclusion.This issue affects XStore Core: from n/a through 5.3.8.
CVE-2024-33552Critical (9.8)0.57%—May 17, 2024
Improper Privilege Management vulnerability in 8theme XStore Core allows Privilege Escalation.This issue affects XStore Core: from n/a through 5.3.8.
CVE-2024-33556Critical (9.8)0.58%—May 17, 2024
Unrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8.
CVE-2024-33558Medium (6.5)0.43%—Apr 29, 2024
Missing Authorization vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.
CVE-2024-33553Critical (9.8)0.58%—Apr 29, 2024
Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.
CVE-2024-33554Medium (6.1)0.42%—Apr 29, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core allows Reflected XSS.This issue affects XStore Core: from n/a through 5.3.5.
CVE-2024-33551Critical (9.8)0.61%—Apr 29, 2024
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core allows SQL Injection.This issue affects XStore Core: from n/a through 5.3.5.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059.007 JavaScript2
  2. T1189 Drive-by Compromise2

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by 8theme