VYPR
Vendor

8theme

Products
2
CVEs
11
Across products
14
Status
Private

Products

2

Recent CVEs

11
  • CVE-2024-33552CriMay 17, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Privilege Management vulnerability in 8theme XStore Core allows Privilege Escalation.This issue affects XStore Core: from n/a through 5.3.8.

  • CVE-2024-33551CriApr 29, 2024
    risk 0.60cvss 9.3epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core allows SQL Injection.This issue affects XStore Core: from n/a through 5.3.5.

  • CVE-2024-33553CriApr 29, 2024
    risk 0.59cvss 9.0epss 0.01

    Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.

  • CVE-2024-33564HigJun 9, 2024
    risk 0.57cvss 8.8epss 0.00

    Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8.

  • CVE-2024-33557HigJun 4, 2024
    risk 0.55cvss 8.5epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore Core allows PHP Local File Inclusion.This issue affects XStore Core: from n/a through 5.3.8.

  • CVE-2024-33555HigJun 9, 2024
    risk 0.53cvss 8.1epss 0.00

    Missing Authorization vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8.

  • CVE-2024-33556HigMay 17, 2024
    risk 0.53cvss 8.2epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8.

  • CVE-2024-33563HigJun 9, 2024
    risk 0.49cvss 7.6epss 0.00

    Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8.

  • CVE-2024-33561HigJun 9, 2024
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8.

  • CVE-2024-33554HigApr 29, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core allows Reflected XSS.This issue affects XStore Core: from n/a through 5.3.5.

  • CVE-2024-33558MedApr 29, 2024
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.