Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Axiomthemes — Vulnerabilities & Security Advisories 98

Browse all 98 CVE security advisories affecting Axiomthemes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Axiomthemes operates as a digital marketplace primarily distributing WordPress themes and plugins for web developers and business owners. Security audits reveal a concerning pattern of vulnerabilities, with approximately 85 Common Vulnerabilities and Exposures (CVEs) currently documented. The most prevalent issues involve Cross-Site Scripting (XSS) and Remote Code Execution (RCE), often stemming from insufficient input validation and sanitization within plugin code. Additionally, several incidents highlight broken access control mechanisms, allowing unauthorized privilege escalation for lower-level user roles. These flaws frequently enable attackers to inject malicious scripts or execute arbitrary commands on compromised servers. While the company provides standard support channels, the high volume of disclosed CVEs suggests inconsistent security review processes prior to product release. Users are advised to rigorously audit any installed components, as the historical data indicates a significant risk profile associated with their software ecosystem.

CVE IDTitleCVSSSeverityPublished
CVE-2026-22362 WordPress Photolia theme <= 1.0.3 - Local File Inclusion vulnerability — PhotoliaCWE-98 8.1 High2026-02-20
CVE-2026-22361 WordPress A-Mart theme <= 1.0.2 - Local File Inclusion vulnerability — A-MartCWE-98 8.1 High2026-02-20
CVE-2025-69409 WordPress PJ | Life & Business Coaching theme <= 3.0.0 - Local File Inclusion vulnerability — PJ | Life & Business CoachingCWE-98 8.1 High2026-02-20
CVE-2025-50003 WordPress Amuli theme <= 2.3.0 - Local File Inclusion vulnerability — AmuliCWE-98 8.1 High2026-01-22
CVE-2025-60065 WordPress Pinevale theme <= 1.0.14 - Local File Inclusion vulnerability — PinevaleCWE-98 8.1 High2025-12-18
CVE-2025-60066 WordPress Katelyn theme <= 1.0.10 - Local File Inclusion vulnerability — KatelynCWE-98 8.1 High2025-12-18
CVE-2025-60064 WordPress Renewal theme <= 1.2.2 - Local File Inclusion vulnerability — RenewalCWE-98 8.1 High2025-12-18
CVE-2025-60067 WordPress Giardino theme <= 1.1.10 - Local File Inclusion vulnerability — GiardinoCWE-98 8.1 High2025-12-18
CVE-2025-60063 WordPress Rosalinda theme <= 1.2.3 - Local File Inclusion vulnerability — RosalindaCWE-98 8.1 High2025-12-18
CVE-2025-60061 WordPress Kicker theme <= 2.2.0 - Local File Inclusion vulnerability — KickerCWE-98 8.1 High2025-12-18
CVE-2025-60060 WordPress Pubzinne theme <= 1.0.12 - Local File Inclusion vulnerability — PubzinneCWE-98 8.1 High2025-12-18
CVE-2025-60059 WordPress smart SEO theme <= 2.12 - Local File Inclusion vulnerability — smart SEOCWE-98 8.1 High2025-12-18
CVE-2025-60050 WordPress Panda theme <= 1.21 - Local File Inclusion vulnerability — PandaCWE-98 8.1 High2025-12-18
CVE-2025-60049 WordPress Soleil theme <= 1.17 - Local File Inclusion vulnerability — SoleilCWE-98 8.1 High2025-12-18
CVE-2025-60048 WordPress Tripster theme <= 1.0.10 - Local File Inclusion vulnerability — TripsterCWE-98 8.1 High2025-12-18
CVE-2025-60047 WordPress IPharm theme <= 1.2.3 - Local File Inclusion vulnerability — IPharmCWE-98 8.1 High2025-12-18
CVE-2025-60046 WordPress HeartStar theme <= 1.0.14 - Local File Inclusion vulnerability — HeartStarCWE-98 8.1 High2025-12-18
CVE-2025-58950 WordPress Lione theme <= 1.16 - Local File Inclusion vulnerability — LioneCWE-98 8.1 High2025-12-18
CVE-2025-58946 WordPress Vocal theme <= 1.12 - Local File Inclusion vulnerability — VocalCWE-98 8.1 High2025-12-18
CVE-2025-58949 WordPress Spock theme <= 1.17 - Local File Inclusion vulnerability — SpockCWE-98 8.1 High2025-12-18
CVE-2025-58945 WordPress EcoGrow theme <= 1.7 - Local File Inclusion vulnerability — EcoGrowCWE-98 8.1 High2025-12-18
CVE-2025-58948 WordPress Aromatica theme <= 1.8 - Local File Inclusion vulnerability — AromaticaCWE-98 8.1 High2025-12-18
CVE-2025-58947 WordPress Athos theme <= 1.9 - Local File Inclusion vulnerability — AthosCWE-98 8.1 High2025-12-18
CVE-2025-58943 WordPress Agricola theme <= 1.1.0 - Local File Inclusion vulnerability — AgricolaCWE-98 8.1 High2025-12-18
CVE-2025-58944 WordPress Manufactory theme <= 1.4 - Local File Inclusion vulnerability — ManufactoryCWE-98 8.1 High2025-12-18
CVE-2025-58940 WordPress Basil theme <= 1.3.12 - Local File Inclusion vulnerability — BasilCWE-98 8.1 High2025-12-18
CVE-2025-58941 WordPress Fabric theme <= 1.5.0 - Local File Inclusion vulnerability — FabricCWE-98 8.1 High2025-12-18
CVE-2025-58942 WordPress Dwell theme <= 1.7.0 - Local File Inclusion vulnerability — DwellCWE-98 8.1 High2025-12-18
CVE-2025-58937 WordPress Tacticool theme <= 1.0.13 - Local File Inclusion vulnerability — TacticoolCWE-98 8.1 High2025-12-18
CVE-2025-58935 WordPress Lunna theme <= 1.15 - Local File Inclusion vulnerability — LunnaCWE-98 8.1 High2025-12-18

This page lists every published CVE security advisory associated with Axiomthemes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.