Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pencidesign

First CVE: Oct 10, 2022Active for: 4 yearsTotal CVEs: 17
36.1
VTI Score
Medium

Pencidesign develops the Soledad web application platform, a narrowly scoped product portfolio that serves design and content-management use cases. Vulnerabilities affecting the vendor skew toward serious outcomes, concentrating in application-layer input-handling and authorization weaknesses including cross-site scripting, SQL injection, missing authorization controls, CSRF, and untrusted deserialization that are characteristic of server-side web applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
3.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pencidesign over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 10, 2022
3 years ago
Most Recent CVE
Feb 19, 2026
155 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-8142HIGH
The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.6.7 via the 'header_layout' parameter. This makes it possible for auth
Aug 16, 20258.830NONO
CVE-2025-64188CRITICAL
Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affects Soledad: from n/a through <= 8.6.9.
Dec 18, 20259.829NONO
CVE-2023-49826CRITICAL
Deserialization of Untrusted Data vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, News
Dec 21, 20239.827NONO
CVE-2025-8105HIGH
The The Soledad theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.6.7. This is due to the software allowing users to execut
Aug 16, 20257.326NONO
CVE-2024-11289HIGH
The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.5.9 via several functions like penci_archive_more_post_ajax_func, penc
Dec 6, 20248.126NONO
CVE-2025-68066HIGH
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad soledad allows PHP Local File Inclusion
Dec 16, 20257.525NONO
CVE-2025-59588HIGH
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad soledad allows PHP Local File Inclusion
Sep 22, 20257.525NONO
CVE-2023-49825HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Th
Dec 20, 20238.123NONO
CVE-2025-59589MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Soledad soledad allows DOM-Based XSS.This issue affects Soledad: f
Sep 22, 20256.522NONO
CVE-2022-3209MEDIUM
The soledad WordPress theme before 8.2.5 does not sanitise the {id,datafilter[type],...} parameters in its penci_more_slist_post_ajax AJAX action, leading to a Reflected Cross-Site
Oct 10, 20226.122NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
47%
41%
12%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (82.4%)
High3 (17.6%)
Unknown0 (0.0%)
User Interaction
None11 (64.7%)
Unknown0 (0.0%)
Required6 (35.3%)
Privileges Required
Low9 (52.9%)
High0 (0.0%)
None8 (47.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pencidesign.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pencidesign — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pencidesign's Products

View all 3 CNAs →

Top CWEs