Thème WordPress
Vulnérabilités TheGem
Cette page rassemble les failles publiées pour TheGem, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de TheGem
8 fiches
TheGem <= 5.10.5 – Missing Authorization
The TheGem theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.10.5. This makes it possible for authenticated attackers, with subscriber-level access and above,…
*-5.10.5
5.10.5.1
26/09/2025
TheGem <= 5.10.5 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The TheGem theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.10.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above,…
*-5.10.5
5.10.5.1
03/09/2025
TheGem <= 5.10.3 – Authenticated (Subscriber+) Arbitrary File Upload
The TheGem theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the thegem_get_logo_url() function in all versions up to, and including, 5.10.3. This makes it possible for authenticated attackers, with Subscriber-level…
*-5.10.3
5.10.3.1
12/05/2025
TheGem <= 5.10.3 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Theme Options Update
The TheGem theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajaxApi() function in all versions up to, and including, 5.10.3. This makes it possible for authenticated attackers, with…
*-5.10.3
5.10.3.1
12/05/2025
TheGem <= 5.9.1 – Reflected Cross-Site Scripting
The TheGem theme for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions up to, and including, 5.9.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-5.9.1
5.9.2
26/12/2023
TheGem < 5.8.1.1 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The TheGem theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 5.8.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber-level permissions and above to inject…
[*, 5.8.1.1)
5.8.1.1
05/05/2023
TheGem < 5.8.1.1 – Improper Authentication
The TheGem theme for WordPress is vulnerable to improper authentication in versions up to 5.8.1.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unknown action.
[*, 5.8.1.1)
5.8.1.1
05/05/2023
TheGem < 5.8.1.1 – Missing Authorization
The TheGem theme for WordPress is vulnerable to unauthorized modification and retrieval of data due to a missing capability check on the ajaxApi() function called via an AJAX action in versions up to 5.8.1.1. This makes it possible…
[*, 5.8.1.1)
5.8.1.1
05/05/2023
Thèmes également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.