Codex-themes
Codex-themes Thegem: vulnerabilidades y CVE
Codex-themes Thegem tiene 9 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses4
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-66609 | Crítica (9.3) | 0.40% | — | 20 ago 2026 | Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. |
| CVE-2026-65480 | Media (6.5) | 0.22% | — | 23 jul 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem allows DOM-Based XSS. This issue affects TheGem: from n/a before 5.12.1.1. |
| CVE-2025-62041 | Alta (7.1) | 0.28% | — | 6 nov 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem (Elementor) thegem-elementor.This issue affects TheGem (Elementor): from n/a through <= 5.10.5.1. |
| CVE-2025-62011 | Media (6.5) | 0.20% | — | 6 nov 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem thegem.This issue affects TheGem: from n/a through <= 5.10.5. |
| CVE-2025-60097 | Media (5.4) | 0.27% | — | 26 sept 2025 | Missing Authorization vulnerability in CodexThemes TheGem thegem allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TheGem: from n/a through <= 5.10.5. |
| CVE-2025-60096 | Media (5.4) | 0.27% | — | 26 sept 2025 | Missing Authorization vulnerability in CodexThemes TheGem (Elementor) thegem-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TheGem (Elementor): from n/a through <=… |
| CVE-2025-4339 | Media (4.3) | 0.42% | — | 13 may 2025 | The TheGem theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajaxApi() function in all versions up to, and including, 5.10.3. This makes it possible for… |
| CVE-2025-4317 | Alta (8.8) | 1.1% | — | 13 may 2025 | The TheGem theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the thegem_get_logo_url() function in all versions up to, and including, 5.10.3. This makes it possible for… |
| CVE-2023-50892 | Media (6.1) | 0.34% | — | 29 dic 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem - Creative Multi-Purpose & WooCommerce WordPress Theme allows Reflected XSS.This issue affects… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.