Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

axiomthemes — Vulnerabilities & Security Advisories 98

Browse all 98 CVE security advisories affecting axiomthemes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Axiomthemes operates as a digital marketplace primarily distributing WordPress themes and plugins for web developers and business owners. Security audits reveal a concerning pattern of vulnerabilities, with approximately 85 Common Vulnerabilities and Exposures (CVEs) currently documented. The most prevalent issues involve Cross-Site Scripting (XSS) and Remote Code Execution (RCE), often stemming from insufficient input validation and sanitization within plugin code. Additionally, several incidents highlight broken access control mechanisms, allowing unauthorized privilege escalation for lower-level user roles. These flaws frequently enable attackers to inject malicious scripts or execute arbitrary commands on compromised servers. While the company provides standard support channels, the high volume of disclosed CVEs suggests inconsistent security review processes prior to product release. Users are advised to rigorously audit any installed components, as the historical data indicates a significant risk profile associated with their software ecosystem.

CVE ID Title CVSS Severity Published
CVE-2026-65581 WordPress AI ANN theme <= 1.29.0 - PHP Object Injection vulnerability — AI ANN CWE-502 9.8 Critical 2026-08-06
CVE-2026-65579 WordPress Agricola theme <= 1.21.0 - PHP Object Injection vulnerability — Agricola CWE-502 9.8 Critical 2026-08-06
CVE-2026-65571 WordPress 69 Clothing theme <= 1.2.11.1 - PHP Object Injection vulnerability — 69 Clothing CWE-502 9.8 Critical 2026-08-06
CVE-2026-65572 WordPress A.Williams theme <= 1.3.1 - PHP Object Injection vulnerability — A.Williams CWE-502 9.8 Critical 2026-08-06
CVE-2026-27377 WordPress QuickCal - Appointment Booking Calendar for WordPress plugin <= 1.0.16 - Broken Access Control vulnerability — QuickCal - Appointment Booking Calendar for WordPress CWE-862 6.7 Medium 2026-07-23
CVE-2026-57738 WordPress 777 theme <= 1.13.0 - PHP Object Injection vulnerability — 777 CWE-502 9.8 Critical 2026-07-13
CVE-2026-22326 WordPress Reprizo theme <= 1.0.8 - Local File Inclusion vulnerability — Reprizo CWE-98 8.1 High 2026-06-17
CVE-2026-22325 WordPress Promo theme <= 1.3.0 - Local File Inclusion vulnerability — Promo CWE-98 8.1 High 2026-06-17
CVE-2025-69369 WordPress Racquet theme <= 1.12.0 - Local File Inclusion vulnerability — Racquet CWE-98 8.1 High 2026-06-02
CVE-2025-58897 WordPress Fermentio theme <= 1.5.0 - Local File Inclusion vulnerability — Fermentio CWE-98 8.1 High 2026-06-02
CVE-2025-58707 WordPress Spin theme <= 1.8 - Local File Inclusion vulnerability — Spin CWE-98 8.1 High 2026-06-02
CVE-2025-58705 WordPress Crafti theme <= 1.12 - Local File Inclusion vulnerability — Crafti CWE-98 8.1 High 2026-06-02
CVE-2025-53440 WordPress Confidant theme <= 1.4 - Local File Inclusion vulnerability — Confidant CWE-98 8.1 High 2026-06-02
CVE-2026-22500 WordPress m2 | Construction and Tools Store theme <= 1.1.2 - PHP Object Injection vulnerability — m2 | Construction and Tools Store CWE-502 9.8 Critical 2026-03-25
CVE-2026-28129 WordPress Little Birdies theme <= 1.3.16 - Local File Inclusion vulnerability — Little Birdies CWE-98 8.1 High 2026-03-05
CVE-2026-28118 WordPress Welldone theme <= 2.4 - Local File Inclusion vulnerability — Welldone CWE-98 8.1 High 2026-03-05
CVE-2026-28119 WordPress Nirvana theme <= 2.6 - Local File Inclusion vulnerability — Nirvana CWE-98 8.1 High 2026-03-05
CVE-2026-28117 WordPress smart SEO theme <= 2.9 - Local File Inclusion vulnerability — smart SEO CWE-98 8.1 High 2026-03-05
CVE-2026-28079 WordPress Conquerors theme <= 1.2.13 - Local File Inclusion vulnerability — Conquerors CWE-98 8.1 High 2026-03-05
CVE-2026-28024 WordPress Helion theme <= 1.1.12 - Local File Inclusion vulnerability — Helion CWE-98 8.1 High 2026-03-05
CVE-2026-27326 WordPress AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme theme <= 1.2.5 - Local File Inclusion vulnerability — AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme CWE-98 8.1 High 2026-03-05
CVE-2026-27098 WordPress Au Pair Agency - Babysitting & Nanny Theme theme <= 1.2.2 - Deserialization of untrusted data vulnerability — Au Pair Agency - Babysitting & Nanny Theme CWE-502 8.1 High 2026-03-05
CVE-2026-22501 WordPress Mounthood theme <= 1.3.2 - PHP Object Injection vulnerability — Mounthood CWE-502 9.8 Critical 2026-03-05
CVE-2026-22475 WordPress Estate theme <= 1.3.4 - PHP Object Injection vulnerability — Estate CWE-502 9.8 Critical 2026-03-05
CVE-2026-22370 WordPress Marveland theme <= 1.3.0 - Local File Inclusion vulnerability — Marveland CWE-98 8.1 High 2026-02-20
CVE-2026-22368 WordPress Redy theme <= 1.0.2 - Local File Inclusion vulnerability — Redy CWE-98 8.1 High 2026-02-20
CVE-2026-22364 WordPress SevenTrees theme <=1.0.2 - Local File Inclusion vulnerability — SevenTrees CWE-98 8.1 High 2026-02-20
CVE-2026-22365 WordPress Soleng theme <= 1.0.5 - Local File Inclusion vulnerability — Soleng CWE-98 8.1 High 2026-02-20
CVE-2026-22366 WordPress Jude theme <= 1.3.0 - Local File Inclusion vulnerability — Jude CWE-98 8.1 High 2026-02-20
CVE-2026-22362 WordPress Photolia theme <= 1.0.3 - Local File Inclusion vulnerability — Photolia CWE-98 8.1 High 2026-02-20

This page lists every published CVE security advisory associated with axiomthemes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.