Nicdarkthemes develops WordPress themes focused on restaurant and food-service applications, including restaurant directory and reservation plugins. The durable signal centers on web-application input-handling weaknesses, specifically PHP remote file inclusion and cross-site scripting vulnerabilities, which recur across its food and reservation product lines. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nicdarkthemes over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1382HIGH The Restaurant Reservations plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the nd_rst_layout attribute of the nd_rst_searc | Mar 7, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-37223MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nicdark Restaurant Reservations allows Stored XSS.This issue affects Re | Jul 22, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nicdarkthemes.
Media articles that mention a CVE ID that affects a product developed by Nicdarkthemes — matched by CVE ID, not by vendor name.