Search Results (19 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-93944 2 Themerex Group, Wordpress-extensions 2 Camelia, Camelia 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Camelia camelia allows Object Injection.This issue affects Camelia: from n/a through 1.2.15.
CVE-2026-93943 2 Themerex Group, Wordpress-extensions 2 Convex, Convex 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a through 1.16.0.
CVE-2026-93942 2 Themerex Group, Wordpress-extensions 2 Dwell, Dwell 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Dwell dwell allows Object Injection.This issue affects Dwell: from n/a through 1.16.0.
CVE-2026-93941 2 Themerex Group, Wordpress-extensions 2 Edema, Edema 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2.
CVE-2026-93940 2 Themerex Group, Wordpress-extensions 2 Greeny, Greeny 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0.
CVE-2026-93938 2 Themerex Group, Wordpress-extensions 2 Hogwords, Hogwords 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7.
CVE-2026-93937 2 Themerex Group, Wordpress-extensions 2 Hygia, Hygia 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0.
CVE-2026-93936 2 Themerex Group, Wordpress-extensions 2 Ipharm, Ipharm 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a through 1.2.4.
CVE-2026-93935 2 Themerex Group, Wordpress-extensions 2 Let's Play, Let's Play 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Let's Play playhockey allows Object Injection.This issue affects Let's Play: from n/a through 1.1.15.
CVE-2026-93934 2 Themerex Group, Wordpress-extensions 2 Partiso, Partiso 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Partiso partiso allows Object Injection.This issue affects Partiso: from n/a through 1.1.13.
CVE-2026-93933 2 Themerex Group, Wordpress-extensions 2 Rosalinda, Rosalinda 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Rosalinda rosalinda allows Object Injection.This issue affects Rosalinda: from n/a through 1.2.4.
CVE-2026-93932 2 Themerex Group, Wordpress-extensions 2 Smart Casa, Smart Casa 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Smart Casa smart-casa allows Object Injection.This issue affects Smart Casa: from n/a through 1.0.12.
CVE-2026-93931 2 Themerex Group, Wordpress-extensions 2 Smash, Smash 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Smash smash allows Object Injection.This issue affects Smash: from n/a through 1.12.0.
CVE-2026-62046 2 Themerex Group, Wordpress-extensions 2 Gutentype, Gutentype 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gutentype allows Object Injection.This issue affects Gutentype: from n/a through 2.1.12.
CVE-2026-62045 2 Themerex Group, Wordpress-extensions 2 Booklovers, Booklovers 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers booklovers allows Object Injection.This issue affects Booklovers: from n/a through 2.13.0.
CVE-2026-57742 1 Themerex Group 1 Kids Planet 2026-10-11 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Group Kids Planet allows Reflected XSS. This issue affects Kids Planet: from n/a through 2.2.14.2.
CVE-2025-58924 2 Themerex Group, Wordpress 2 Geya, Wordpress 2026-06-23 8.1 High
Unauthenticated Local File Inclusion in Geya <= 1.15 versions.
CVE-2025-60085 2 Themerex Group, Wordpress 2 Learnify, Wordpress 2026-06-23 8.1 High
Unauthenticated Local File Inclusion in Learnify <= 1.15.0 versions.
CVE-2026-39529 2 Themerex Group, Wordpress 2 Elementra, Wordpress 2026-06-20 9.8 Critical
Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions.