Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

axiomthemes — Vulnerabilities & Security Advisories 98

Browse all 98 CVE security advisories affecting axiomthemes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Axiomthemes operates as a digital marketplace primarily distributing WordPress themes and plugins for web developers and business owners. Security audits reveal a concerning pattern of vulnerabilities, with approximately 85 Common Vulnerabilities and Exposures (CVEs) currently documented. The most prevalent issues involve Cross-Site Scripting (XSS) and Remote Code Execution (RCE), often stemming from insufficient input validation and sanitization within plugin code. Additionally, several incidents highlight broken access control mechanisms, allowing unauthorized privilege escalation for lower-level user roles. These flaws frequently enable attackers to inject malicious scripts or execute arbitrary commands on compromised servers. While the company provides standard support channels, the high volume of disclosed CVEs suggests inconsistent security review processes prior to product release. Users are advised to rigorously audit any installed components, as the historical data indicates a significant risk profile associated with their software ecosystem.

CVE ID Title CVSS Severity Published
CVE-2026-22362 WordPress Photolia theme <= 1.0.3 - Local File Inclusion vulnerability — Photolia CWE-98 8.1 High 2026-02-20
CVE-2026-22361 WordPress A-Mart theme <= 1.0.2 - Local File Inclusion vulnerability — A-Mart CWE-98 8.1 High 2026-02-20
CVE-2025-69409 WordPress PJ | Life & Business Coaching theme <= 3.0.0 - Local File Inclusion vulnerability — PJ | Life & Business Coaching CWE-98 8.1 High 2026-02-20
CVE-2025-50003 WordPress Amuli theme <= 2.3.0 - Local File Inclusion vulnerability — Amuli CWE-98 8.1 High 2026-01-22
CVE-2025-60065 WordPress Pinevale theme <= 1.0.14 - Local File Inclusion vulnerability — Pinevale CWE-98 8.1 High 2025-12-18
CVE-2025-60066 WordPress Katelyn theme <= 1.0.10 - Local File Inclusion vulnerability — Katelyn CWE-98 8.1 High 2025-12-18
CVE-2025-60064 WordPress Renewal theme <= 1.2.2 - Local File Inclusion vulnerability — Renewal CWE-98 8.1 High 2025-12-18
CVE-2025-60067 WordPress Giardino theme <= 1.1.10 - Local File Inclusion vulnerability — Giardino CWE-98 8.1 High 2025-12-18
CVE-2025-60063 WordPress Rosalinda theme <= 1.2.3 - Local File Inclusion vulnerability — Rosalinda CWE-98 8.1 High 2025-12-18
CVE-2025-60061 WordPress Kicker theme <= 2.2.0 - Local File Inclusion vulnerability — Kicker CWE-98 8.1 High 2025-12-18
CVE-2025-60060 WordPress Pubzinne theme <= 1.0.12 - Local File Inclusion vulnerability — Pubzinne CWE-98 8.1 High 2025-12-18
CVE-2025-60059 WordPress smart SEO theme <= 2.12 - Local File Inclusion vulnerability — smart SEO CWE-98 8.1 High 2025-12-18
CVE-2025-60050 WordPress Panda theme <= 1.21 - Local File Inclusion vulnerability — Panda CWE-98 8.1 High 2025-12-18
CVE-2025-60049 WordPress Soleil theme <= 1.17 - Local File Inclusion vulnerability — Soleil CWE-98 8.1 High 2025-12-18
CVE-2025-60048 WordPress Tripster theme <= 1.0.10 - Local File Inclusion vulnerability — Tripster CWE-98 8.1 High 2025-12-18
CVE-2025-60047 WordPress IPharm theme <= 1.2.3 - Local File Inclusion vulnerability — IPharm CWE-98 8.1 High 2025-12-18
CVE-2025-60046 WordPress HeartStar theme <= 1.0.14 - Local File Inclusion vulnerability — HeartStar CWE-98 8.1 High 2025-12-18
CVE-2025-58950 WordPress Lione theme <= 1.16 - Local File Inclusion vulnerability — Lione CWE-98 8.1 High 2025-12-18
CVE-2025-58946 WordPress Vocal theme <= 1.12 - Local File Inclusion vulnerability — Vocal CWE-98 8.1 High 2025-12-18
CVE-2025-58949 WordPress Spock theme <= 1.17 - Local File Inclusion vulnerability — Spock CWE-98 8.1 High 2025-12-18
CVE-2025-58945 WordPress EcoGrow theme <= 1.7 - Local File Inclusion vulnerability — EcoGrow CWE-98 8.1 High 2025-12-18
CVE-2025-58948 WordPress Aromatica theme <= 1.8 - Local File Inclusion vulnerability — Aromatica CWE-98 8.1 High 2025-12-18
CVE-2025-58947 WordPress Athos theme <= 1.9 - Local File Inclusion vulnerability — Athos CWE-98 8.1 High 2025-12-18
CVE-2025-58943 WordPress Agricola theme <= 1.1.0 - Local File Inclusion vulnerability — Agricola CWE-98 8.1 High 2025-12-18
CVE-2025-58944 WordPress Manufactory theme <= 1.4 - Local File Inclusion vulnerability — Manufactory CWE-98 8.1 High 2025-12-18
CVE-2025-58940 WordPress Basil theme <= 1.3.12 - Local File Inclusion vulnerability — Basil CWE-98 8.1 High 2025-12-18
CVE-2025-58941 WordPress Fabric theme <= 1.5.0 - Local File Inclusion vulnerability — Fabric CWE-98 8.1 High 2025-12-18
CVE-2025-58942 WordPress Dwell theme <= 1.7.0 - Local File Inclusion vulnerability — Dwell CWE-98 8.1 High 2025-12-18
CVE-2025-58937 WordPress Tacticool theme <= 1.0.13 - Local File Inclusion vulnerability — Tacticool CWE-98 8.1 High 2025-12-18
CVE-2025-58935 WordPress Lunna theme <= 1.15 - Local File Inclusion vulnerability — Lunna CWE-98 8.1 High 2025-12-18

This page lists every published CVE security advisory associated with axiomthemes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.