Cththemes develops a focused line of WordPress theme and plugin products for booking and directory applications, including CityBook, EasyBook, TownHub, Balkon, and Monolit, that serve small-business and hospitality use cases. The vendor's vulnerabilities center on web-application input-handling issues, particularly cross-site scripting and authorization-bypass flaws arising from user-controlled parameters, which are characteristic of plugins that accept and render user input; the product line's public-facing nature and the availability of exploit tooling warrant active monitoring. Live severity, exploitation, and coverage details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cththemes over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-20210MEDIUM The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query. | Jan 13, 2020 | 6.1 | 30 | NO | YES |
CVE-2019-20209HIGH The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php t | Jan 13, 2020 | 7.5 | 24 | NO | NO |
CVE-2019-20212MEDIUM The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form. | Jan 13, 2020 | 6.1 | 22 | NO | NO |
CVE-2023-29236MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cththemes Outdoor theme <= 3.9.6 versions. | Apr 7, 2023 | 6.1 | 21 | NO | NO |
CVE-2019-20211MEDIUM The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longit | Jan 13, 2020 | 6.1 | 21 | NO | NO |
CVE-2023-25041MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cththemes Monolit theme <= 2.0.6 versions. | Apr 7, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-36502MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cththemes Balkon plugin <= 1.3.2 versions. | Jul 25, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-29430MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CTHthemes TheRoof theme <= 1.0.3 versions. | Jun 26, 2023 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cththemes.
Media articles that mention a CVE ID that affects a product developed by Cththemes — matched by CVE ID, not by vendor name.