Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

hogash — Vulnerabilities & Security Advisories 9

Browse all 9 CVE security advisories affecting hogash. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Hogash develops web applications and themes primarily for e-commerce and content management platforms. Historically, their products have been susceptible to multiple remote code execution (RCE) vulnerabilities, cross-site scripting (XSS), and privilege escalation flaws, with nine CVEs documented to date. These issues often stem from insufficient input validation and improper access controls. While no major public security incidents have been widely reported, the consistent pattern of vulnerabilities in their software suggests a need for improved security practices in their development lifecycle.

Found 4 results / 9 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2025-6988 Kallyas <= 4.23.0 - Authenticated (Contributor+) Stored Cross-Site Scripting — KALLYAS - Creative eCommerce Multi-Purpose WordPress Theme CWE-79 6.4 Medium 2025-11-01
CVE-2025-6990 Kallyas <= 4.24.0 - Authenticated (Contributor+) Remote Code Execution — KALLYAS - Creative eCommerce Multi-Purpose WordPress Theme CWE-94 8.8 High 2025-11-01
CVE-2025-6991 Kallyas <= 4.21.0 - Authenticated (Contributor+) Local File Inclusion — KALLYAS - Creative eCommerce Multi-Purpose WordPress Theme CWE-98 7.5 High 2025-07-26
CVE-2025-6989 Kallyas <= 4.21.0 - Authenticated (Contributor+) Arbitrary Folder Deletion — KALLYAS - Creative eCommerce Multi-Purpose WordPress Theme CWE-22 8.1 High 2025-07-26

This page lists every published CVE security advisory associated with hogash. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.