Apollotheme's vulnerability profile centers on its AP Pagebuilder product, a web-based page-construction tool where disclosures cluster around common web-application input-handling and access-control weaknesses including path traversal, cross-site scripting, and SQL injection. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Apollotheme over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-22897CRITICAL A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for PrestaShop allows unauthenticate | Aug 29, 2022 | 9.8 | 49 | NO | YES |
CVE-2024-6648HIGH Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_item_path' within the 'config' JS | May 8, 2025 | 7.5 | 23 | NO | NO |
CVE-2022-44897MEDIUM A cross-site scripting (XSS) vulnerability in ApolloTheme AP PageBuilder component through 2.4.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inj | Jan 31, 2023 | 6.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Apollotheme.
Media articles that mention a CVE ID that affects a product developed by Apollotheme — matched by CVE ID, not by vendor name.