Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Themeum — Vulnerabilities & Security Advisories 126

Browse all 126 CVE security advisories affecting Themeum. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Themeum operates as a cloud-based platform facilitating the creation and deployment of virtual machines, primarily targeting developers and enterprises seeking streamlined infrastructure management. Security audits have identified eighty-four Common Vulnerabilities and Exposures (CVEs) associated with the platform, indicating a significant historical attack surface. The most prevalent vulnerability classes include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from inadequate input validation and improper access controls within its web interface and API endpoints. These defects have occasionally allowed unauthorized users to execute arbitrary commands or escalate their permissions to administrative levels, potentially compromising underlying virtual machine instances. While specific major public breaches remain limited in detailed public reporting, the high volume of disclosed CVEs suggests persistent challenges in securing the application layer. Continuous patching and rigorous code review processes are essential to mitigate these recurring risks and ensure the integrity of hosted environments.

CVE ID Title CVSS Severity Published
CVE-2026-18335 Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Unauthenticated Blind Server-Side Request Forgery via 'kirki_data' Parameter — Kirki – Freeform Page Builder, Website Builder & Customizer CWE-918 5.4 Medium 2026-09-24
CVE-2026-18439 Tutor LMS <= 4.0.7 - Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Quiz Question/Answer Modification and Deletion via 'payload' Parameter — Tutor LMS – eLearning and online course solution CWE-639 4.3 Medium 2026-09-22
CVE-2026-89081 Tutor LMS <= 4.0.8 - Reflected Cross-Site Scripting via 'back_url' and 'search' Parameters — Tutor LMS – eLearning and online course solution CWE-79 6.1 Medium 2026-09-19
CVE-2026-88944 Tutor LMS <= 4.0.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'lesson_id' Parameter — Tutor LMS – eLearning and online course solution CWE-862 4.3 Medium 2026-09-19
CVE-2026-89333 Tutor LMS <= 4.0.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'student_id' Parameter — Tutor LMS – eLearning and online course solution CWE-639 6.5 Medium 2026-09-19
CVE-2026-92465 WordPress WP Mega Menu plugin <= 1.4.2 - SQL Injection vulnerability — WP Mega Menu CWE-89 7.6 High 2026-09-16
CVE-2026-78175 Tutor LMS <= 4.0.7 - Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution — Tutor LMS – eLearning and online course solution CWE-502 8.8 High 2026-09-12
CVE-2026-17037 Kirki <= 6.2.0 - Unauthenticated Stored Cross-Site Scripting via 'comment' Parameter — Kirki – Freeform Page Builder, Website Builder & Customizer CWE-79 7.2 High 2026-09-11
CVE-2026-19945 WP Crowdfunding <= 2.2.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'first_name' Parameter — WP Crowdfunding CWE-79 6.4 Medium 2026-09-09
CVE-2026-19944 WP Crowdfunding <= 2.2.1 - Authenticated (Shop Manager+) SQL Injection via 'wpneo_reward' Post Meta — WP Crowdfunding CWE-89 4.9 Medium 2026-09-09
CVE-2026-16759 Tutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters — Tutor LMS – eLearning and online course solution CWE-74 6.5 Medium 2026-08-28
CVE-2026-66629 WordPress Kirki plugin <= 6.2.3 - Cross Site Scripting (XSS) vulnerability — Kirki CWE-79 7.1 High 2026-08-18
CVE-2026-18347 Kirki <= 6.1.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'context' Parameter — Kirki – Freeform Page Builder, Website Builder & Customizer CWE-862 4.3 Medium 2026-08-16
CVE-2026-17604 Kirki <= 6.1.1 - Authenticated (Editor+) Path Traversal to Arbitrary File Read via 'data' Parameter — Kirki – Freeform Page Builder, Website Builder & Customizer CWE-22 4.9 Medium 2026-08-16
CVE-2026-16974 Kirki - Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via post_meta Shortcode — Kirki – Freeform Page Builder, Website Builder & Customizer CWE-79 6.4 Medium 2026-08-11
CVE-2026-15601 Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary File Write (Zip Slip) — Kirki – Freeform Page Builder, Website Builder & Customizer CWE-22 4.9 Medium 2026-08-01
CVE-2026-15444 Tutor LMS <= 4.0.1 - Authenticated (Administrator+) SQL Injection via 'coupon_code' Parameter — Tutor LMS – eLearning and online course solution CWE-89 4.9 Medium 2026-07-28
CVE-2026-65436 WordPress Kirki plugin <= 6.0.13 - Arbitrary File Deletion vulnerability — Kirki CWE-22 6.8 Medium 2026-07-27
CVE-2026-13464 Kirki <= 6.0.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'context' Parameter — Kirki – Freeform Page Builder, Website Builder & Customizer CWE-639 5.3 Medium 2026-07-24
CVE-2026-65531 WordPress Qubely plugin <= 1.8.14 - Broken Access Control vulnerability — Qubely CWE-862 4.8 Medium 2026-07-23
CVE-2026-1372 Tutor LMS Elementor Addons <= 4.0.0 - Missing Authorization to Authenticated (Subscriber+) Tutor LMS and Elementor Plugin Activation — Tutor LMS Elementor Addons CWE-862 4.3 Medium 2026-07-21
CVE-2026-15457 Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' Parameter — Kirki – Freeform Page Builder, Website Builder & Customizer CWE-22 4.9 Medium 2026-07-17
CVE-2026-15022 Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array — Tutor LMS – eLearning and online course solution CWE-89 6.5 Medium 2026-07-16
CVE-2026-57726 WordPress Kirki plugin <= 6.0.12 - SQL Injection vulnerability — Kirki CWE-89 9.3 Critical 2026-07-13
CVE-2026-57694 WordPress Tutor LMS plugin <= 3.9.13 - Insecure Direct Object References (IDOR) vulnerability — Tutor LMS CWE-639 6.5 Medium 2026-07-13
CVE-2026-57725 WordPress Kirki plugin <= 6.0.11 - Cross Site Scripting (XSS) vulnerability — Kirki CWE-79 7.1 High 2026-07-13
CVE-2026-57724 WordPress Kirki plugin <= 6.0.12 - PHP Object Injection vulnerability — Kirki CWE-502 9.8 Critical 2026-07-13
CVE-2026-57727 WordPress Kirki plugin <= 6.0.13 - Broken Access Control vulnerability — Kirki CWE-862 7.5 High 2026-07-13
CVE-2026-57680 WordPress Kirki plugin <= 6.0.11 - Insecure Direct Object References (IDOR) vulnerability — Kirki CWE-639 6.5 Medium 2026-07-02
CVE-2026-12472 Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Arbitrary Email Content Injection (Mail Relay / Phishing) via 'emailBody' and 'emailSubject' Parameters — Kirki – Freeform Page Builder, Website Builder & Customizer CWE-862 5.3 Medium 2026-07-02

This page lists every published CVE security advisory associated with Themeum. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.