Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Athemes

First CVE: Feb 29, 2024Active for: 2 yearsTotal CVEs: 9

Athemes develops WordPress plugins and extensions positioned for site builders and design professionals, with a modestly represented vulnerability footprint concentrated in products like Sydney Toolbox and Athemes Addons for Elementor. The recurring weakness classes affecting the vendor center on web application input handling and PHP file-inclusion flaws, which are characteristic of plugin-based server-side rendering in the WordPress ecosystem. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Athemes over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 29, 2024
2 years ago
Most Recent CVE
Apr 10, 2025
470 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-32158HIGH
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Syed Balkhi aThemes Addons for Elementor athemes-addons-for
Apr 10, 20258.824NONO
CVE-2024-2936MEDIUM
The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id attribute of widgets in all versions up to, and including, 1.26 due to insufficient
Mar 29, 20245.418NONO
CVE-2024-1447MEDIUM
The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aThemes Slider button element in all versions up to, and including, 1.25 due t
Feb 29, 20245.418NONO
CVE-2024-13547MEDIUM
The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions up to, and including, 1.0.12 due t
Feb 1, 20255.417NONO
CVE-2024-51675MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi aThemes Addons for Elementor athemes-addons-for-elementor-lite all
Nov 9, 20245.417NONO
CVE-2024-4036MEDIUM
The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the style parameter in all versions up to, and including, 1.30 due to insufficient input sa
May 2, 20245.417NONO
CVE-2024-3208MEDIUM
The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 1.28 due to in
Apr 9, 20245.417NONO
CVE-2025-22646MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi aThemes Addons for Elementor athemes-addons-for-elementor-lite all
Mar 27, 20255.416NONO
CVE-2024-4473MEDIUM
The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "aThemes: Portfolio" widget in all versions up to, and including, 1.31 due to insuffici
May 14, 20245.416NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
89%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (11.1%)
Unknown0 (0.0%)
Required8 (88.9%)
Privileges Required
Low9 (100.0%)
High0 (0.0%)
None0 (0.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Athemes.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Athemes — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Athemes's Products

View all 2 CNAs →

Top CWEs