vciy

CVEs we hold for Themegoods

Records whose assigning authority named Themegoods as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-66652WordPress Grand Tour theme <= 5.5.1 - Cross Site Request Forgery (CSRF) vulnerabilityThemeGoods Grand Tour
CVE-2026-65487WordPress Photography theme <= 7.7.6 - Broken Access Control vulnerabilityThemeGoods Photography
CVE-2026-57770WordPress Grand Photography theme <= 5.7.8 - PHP Object Injection vulnerabilityThemeGoods Grand Photography
CVE-2026-57769WordPress Grand Photography theme <= 5.7.8 - Reflected Cross Site Scripting (XSS) vulnerabilityThemeGoods Grand Photography
CVE-2026-39635WordPress Grand Magazine theme <= 3.5.5 - Cross Site Request Forgery (CSRF) vulnerabilityThemeGoods Grand Magazine
CVE-2026-39634WordPress Grand Portfolio theme <= 3.3 - Cross Site Request Forgery (CSRF) vulnerabilityThemeGoods Grand Portfolio
CVE-2026-39633WordPress Grand Car Rental theme <= 3.6.9 - Cross Site Request Forgery (CSRF) vulnerabilityThemeGoods Grand Car Rental
CVE-2026-39632WordPress Grand Blog theme <= 3.1 - Cross Site Request Forgery (CSRF) vulnerabilityThemeGoods Grand Blog
CVE-2026-39603WordPress Grand Photography theme <= 5.7.8 - Cross Site Request Forgery (CSRF) vulnerabilityThemeGoods Grand Photography
CVE-2026-27367WordPress Musico theme < 3.4.5 - Cross Site Scripting (XSS) vulnerabilityThemeGoods Musico
CVE-2026-27358WordPress Architecturer theme < 3.9.5 - Cross Site Scripting (XSS) vulnerabilityThemeGoods Architecturer
CVE-2026-27353WordPress Grand News | Magazine Newspaper WordPress theme <= 3.4.3 - Reflected Cross Site Scripting (XSS) vulnerabilityThemeGoods Grand News
CVE-2026-27352WordPress Starto theme < 2.2.5 - Cross Site Scripting (XSS) vulnerabilityThemeGoods Starto
CVE-2026-27348WordPress Photography theme < 7.7.6 - Cross Site Scripting (XSS) vulnerabilityThemeGoods Photography
CVE-2026-27043WordPress Photography theme < 7.7.6 - Arbitrary File Upload vulnerabilityThemeGoods Photography
CVE-2026-24961WordPress Grand Blog theme < 3.1.5 - Server Side Request Forgery (SSRF) vulnerabilityThemeGoods Grand Blog
CVE-2026-24949WordPress PhotoMe theme <= 5.7.1 - Cross Site Scripting (XSS) vulnerabilityThemeGoods PhotoMe
CVE-2026-24943WordPress Grand Conference theme <= 5.3.4 - Reflected Cross Site Scripting (XSS) vulnerabilityThemeGoods Grand Conference
CVE-2026-24381WordPress PhotoMe theme < 5.7.2 - Server Side Request Forgery (SSRF) vulnerabilityThemeGoods PhotoMe
CVE-2026-23542WordPress Grand Restaurant theme <= 7.0.10 - PHP Object Injection vulnerabilityThemeGoods Grand Restaurant
CVE-2026-22417WordPress Grand Wedding theme < 3.1.11 - PHP Object Injection vulnerabilityThemeGoods Grand Wedding
CVE-2025-69370WordPress Capella theme <= 2.5.5 - PHP Object Injection vulnerabilityThemeGoods Capella
CVE-2025-69321WordPress Grand Spa theme <= 3.5.5 - Reflected Cross Site Scripting (XSS) vulnerabilityThemeGoods Grand Spa
CVE-2025-69320WordPress Grand Magazine theme <= 3.5.7 - Reflected Cross Site Scripting (XSS) vulnerabilityThemeGoods Grand Magazine
CVE-2025-69301WordPress PhotoMe theme <= 5.6.11 - PHP Object Injection vulnerabilityThemeGoods PhotoMe
CVE-2025-69152WordPress Artale | Wedding Photography WordPress theme <= 2.2.2 - Cross Site Scripting (XSS) vulnerabilityThemeGoods Artale | Wedding Photography WordPress
CVE-2025-69151WordPress Grand Car Rental theme <= 3.7 - Cross Site Scripting (XSS) vulnerabilityThemeGoods Grand Car Rental
CVE-2025-68538WordPress Craft | Coffee Shop Cafe Restaurant WordPress theme <= 2.3.6 - Reflected Cross Site Scripting (XSS)…ThemeGoods Craft
CVE-2025-68524WordPress Avante theme < 3.0.5 - Reflected Cross Site Scripting (XSS) vulnerabilityThemeGoods Avante
CVE-2025-68520WordPress DotLife theme < 4.9.5 - Reflected Cross Site Scripting (XSS) vulnerabilityThemeGoods DotLife
CVE-2025-68518WordPress Hoteller theme < 6.8.9 - Reflected Cross Site Scripting (XSS) vulnerabilityThemeGoods Hoteller
CVE-2025-68510WordPress Photography theme < 7.7.5 - Local File Inclusion vulnerabilityThemeGoods Photography
CVE-2025-67952WordPress Grand Tour theme < 5.6.2 - Cross Site Scripting (XSS) vulnerabilityThemeGoods Grand Tour
CVE-2025-67922WordPress Grand Restaurant theme < 7.0.9 - Cross Site Scripting (XSS) vulnerabilityThemeGoods Grand Restaurant
CVE-2025-64224WordPress Grand Conference Theme Custom Post Type plugin < 2.6.4 - Cross Site Scripting (XSS) vulnerabilityThemeGoods Grand Conference Theme Custom Post Type
CVE-2025-64217WordPress Photography theme <= 7.7.2 - Cross Site Scripting (XSS) vulnerabilityThemeGoods Photography
CVE-2025-63026WordPress Grand Restaurant Theme Elements for Elementor plugin <= 2.1.1 - Cross Site Scripting (XSS) vulnerabilityThemeGoods Grand Restaurant Theme Elements for Elementor
CVE-2025-60116WordPress Grand Conference Theme Custom Post Type plugin < 2.6.4 - Broken Access Control vulnerabilityThemeGoods Grand Conference Theme Custom Post Type
CVE-2025-53999WordPress Altair theme <= 5.2.2 - Broken Access Control vulnerabilityThemeGoods Altair
CVE-2025-47584WordPress Photography theme <= 7.5.2 - PHP Object Injection vulnerabilityThemeGoods Photography
CVE-2025-47579WordPress Photography Theme <= 7.7.2 - PHP Object Injection VulnerabilityThemeGoods Photography
CVE-2025-39485WordPress GrandTour theme <= 5.6 - PHP Object Injection vulnerabilityThemeGoods Grand Tour
CVE-2025-39354WordPress Grand Conference theme <= 5.3 - PHP Object Injection vulnerabilityThemeGoods Grand Conference
CVE-2025-39353WordPress Grand Restaurant WordPress theme <= 7.0 - Broken Access Control vulnerabilityThemeGoods Grand Restaurant
CVE-2025-39352WordPress Grand Restaurant WordPress theme <= 7.0 - Arbitrary Options Deletion vulnerabilityThemeGoods Grand Restaurant
CVE-2025-39351WordPress Grand Restaurant WordPress theme <= 7.0 - Cross Site Request Forgery (CSRF) vulnerabilityThemeGoods Grand Restaurant
CVE-2025-39348WordPress Grand Restaurant WordPress theme <= 7.0 - PHP Object Injection vulnerabilityThemeGoods Grand Restaurant
CVE-2025-32928WordPress Altair theme <= 5.2.2 - PHP Object Injection vulnerabilityThemeGoods Altair
CVE-2025-32926WordPress Grand Restaurant WordPress theme <= 7.0 - Path Traversal to PHP Object Injection vulnerabilityThemeGoods Grand Restaurant
CVE-2025-30964WordPress Photography theme < 7.7.6 - Server Side Request Forgery (SSRF) vulnerabilityThemeGoods Photography
CVE-2025-22702WordPress Photography Theme <= 7.7.2 - Broken Access Control VulnerabilityThemeGoods Photography
CVE-2025-15689WordPress Capella theme <= 2.5.5 - Privilege Escalation vulnerabilityThemeGoods Capella
CVE-2025-15688WordPress Capella theme <= 2.5.5 - SQL Injection vulnerabilityThemeGoods Capella
CVE-2024-12922Altair <= 5.2.4 - Unauthenticated Arbitrary Options Update via pp_import_currentThemeGoods Altair

54 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.